youtube-transcript
Pass
Audited by Gen Agent Trust Hub on Oct 8, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDATA_EXFILTRATIONPERSISTENCE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external, untrusted data by fetching and analyzing YouTube video transcripts. This creates an attack surface for indirect prompt injection if a video's spoken content contains instructions designed to manipulate the agent.
- Ingestion points: The skill fetches transcript strings via the
scripts/fetch_transcript.shscript. - Boundary markers: The skill includes explicit instructions in
SKILL.mdtelling the agent to treat transcripts strictly as data and to ignore any instructions or commands found within them (e.g., requests to reveal system prompts or run tools). - Capability inventory: The skill has the ability to make network requests using
curland can modify persistent shell configuration files. - Sanitization: No automatic sanitization or filtering is applied to the transcript content; safety depends on the agent adhering to the instructions.
- [COMMAND_EXECUTION]: The skill utilizes several shell scripts in the
scripts/directory to perform network operations viacurl. - Evidence: All scripts use
set -euo pipefailand utilizecurlwith--data-urlencodefor parameters likechannel,q, andv. This practice correctly mitigates the risk of command injection from user-provided input strings. - [DATA_EXFILTRATION]: The skill features an automated API key generation flow that transmits the user's email address to the external service
getyoutubetranscript.com. - Evidence:
SKILL.mdcontains acurlcommand toPOSTan email to the signup endpoint. This is documented as a user-facing feature and the agent is strictly instructed to obtain explicit user consent before proceeding with this step. - [PERSISTENCE]: The skill instructions suggest saving the retrieved API key to the user's shell profile for use in future sessions.
- Evidence:
SKILL.mdmentions writing the key to a shell profile. This persistence mechanism is gated by a requirement for the agent to ask the user for confirmation before writing to any persistent file.
Audit Metadata