youtube-api
Pass
Audited by Gen Agent Trust Hub on Aug 6, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or vulnerabilities were detected. The skill is designed with a strong focus on developer security and best practices.- [CREDENTIALS_SAFE]: The skill provides explicit instructions and anti-pattern warnings to prevent the exposure of credentials. It mandates that
client_secret.jsonandtoken.jsonbe excluded from version control via.gitignoreand uses theverify.shscript to audit for accidental inclusion of refresh tokens.- [COMMAND_EXECUTION]: The skill includesscripts/verify.sh, which is a defensive static analysis tool. It uses standard shell utilities to audit local source code for over-broad scopes, hardcoded tokens, and non-resumable upload implementations.- [EXTERNAL_DOWNLOADS]: All external references and dependencies are directed to official Google services and libraries, such asgoogle-api-python-client,googleapis, and thedevelopers.google.comdomain. These are well-known and trusted sources.- [INDIRECT_PROMPT_INJECTION]: The skill ingests analytics data (e.g., video titles, traffic source names) from the YouTube API to create wiki logs. While this is an ingestion surface, the data is stored as static markdown and is not interpreted as instructions, posing a low risk profile typical of data-logging applications.
Audit Metadata