youtube-api

Pass

Audited by Gen Agent Trust Hub on Aug 6, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: No malicious patterns or vulnerabilities were detected. The skill is designed with a strong focus on developer security and best practices.- [CREDENTIALS_SAFE]: The skill provides explicit instructions and anti-pattern warnings to prevent the exposure of credentials. It mandates that client_secret.json and token.json be excluded from version control via .gitignore and uses the verify.sh script to audit for accidental inclusion of refresh tokens.- [COMMAND_EXECUTION]: The skill includes scripts/verify.sh, which is a defensive static analysis tool. It uses standard shell utilities to audit local source code for over-broad scopes, hardcoded tokens, and non-resumable upload implementations.- [EXTERNAL_DOWNLOADS]: All external references and dependencies are directed to official Google services and libraries, such as google-api-python-client, googleapis, and the developers.google.com domain. These are well-known and trusted sources.- [INDIRECT_PROMPT_INJECTION]: The skill ingests analytics data (e.g., video titles, traffic source names) from the YouTube API to create wiki logs. While this is an ingestion surface, the data is stored as static markdown and is not interpreted as instructions, posing a low risk profile typical of data-logging applications.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 6, 2026, 09:37 PM
Security Audit — agent-trust-hub — youtube-api