youtube-transcript

Pass

Audited by Gen Agent Trust Hub on Oct 8, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONPERSISTENCE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, untrusted data by fetching and analyzing YouTube video transcripts. This creates an attack surface for indirect prompt injection if a video's spoken content contains instructions designed to manipulate the agent.
  • Ingestion points: The skill fetches transcript strings via the scripts/fetch_transcript.sh script.
  • Boundary markers: The skill includes explicit instructions in SKILL.md telling the agent to treat transcripts strictly as data and to ignore any instructions or commands found within them (e.g., requests to reveal system prompts or run tools).
  • Capability inventory: The skill has the ability to make network requests using curl and can modify persistent shell configuration files.
  • Sanitization: No automatic sanitization or filtering is applied to the transcript content; safety depends on the agent adhering to the instructions.
  • [COMMAND_EXECUTION]: The skill utilizes several shell scripts in the scripts/ directory to perform network operations via curl.
  • Evidence: All scripts use set -euo pipefail and utilize curl with --data-urlencode for parameters like channel, q, and v. This practice correctly mitigates the risk of command injection from user-provided input strings.
  • [DATA_EXFILTRATION]: The skill features an automated API key generation flow that transmits the user's email address to the external service getyoutubetranscript.com.
  • Evidence: SKILL.md contains a curl command to POST an email to the signup endpoint. This is documented as a user-facing feature and the agent is strictly instructed to obtain explicit user consent before proceeding with this step.
  • [PERSISTENCE]: The skill instructions suggest saving the retrieved API key to the user's shell profile for use in future sessions.
  • Evidence: SKILL.md mentions writing the key to a shell profile. This persistence mechanism is gated by a requirement for the agent to ask the user for confirmation before writing to any persistent file.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 8, 2026, 09:48 PM