youtube-thumbnails

Pass

Audited by Gen Agent Trust Hub on Sep 21, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill's instructions and associated scripts follow safe practices for the intended use case of thumbnail optimization and experiment logging. No patterns of prompt injection, data exfiltration, or obfuscation were detected.
  • [COMMAND_EXECUTION]: The skill utilizes a local utility script, scripts/verify.sh, to ensure image files meet dimensions (1280x720) and size (under 2MB) constraints. The script is a read-only validator and uses standard system tools like sips or identify to inspect local files.
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a learning loop by reading and mining patterns from 02-DOCS/wiki/youtube/thumbnail-experiments.md. This ingestion of project-specific data is the primary mechanism for the skill's evidence-led design workflow and does not present a security risk in this implementation.
  • [EXTERNAL_DOWNLOADS]: The documentation references several external industry resources for thumbnail specifications and contrast rules (e.g., socialrails.com, thumbnailtest.com). These are provided as static informational sources for the agent and do not involve runtime code execution or the downloading of executable content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 21, 2026, 11:11 PM
Security Audit — agent-trust-hub — youtube-thumbnails