youtube-packaging

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill defines a legitimate and well-structured process for YouTube SEO. It relies on local documentation and maintains a performance feedback loop within the project's documentation folder (02-DOCS).
  • [COMMAND_EXECUTION]: The skill provides a shell script (scripts/verify.sh) to validate the generated metadata. A detailed audit of this script confirms it is limited to read-only text processing using standard utilities like grep, sed, and awk. It contains no network activity, no credential access, and no dangerous system commands.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from channel logs and related ideation skills.
  • Ingestion points: Reads from 02-DOCS/wiki/youtube/ and accepts inputs from the youtube-ideation skill (SKILL.md).
  • Boundary markers: The instructions specify using structured artifacts and YAML frontmatter for log entries, but do not include explicit prompt delimiters for external content.
  • Capability inventory: The skill is capable of writing to the local documentation directory and executing its own verification script (SKILL.md).
  • Sanitization: No specific sanitization or filtering of input data is described.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — youtube-packaging