ingest-youtube

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted external data (YouTube transcripts) and integrates it into the user's Obsidian vault.
  • Ingestion points: The skill ingests a user-provided YouTube URL via $ARGUMENTS and subsequently processes summary and transcript files generated by the youtube-summary tool (as seen in the Workflow section of SKILL.md).
  • Boundary markers: There are no explicit boundary markers or instructions to ignore embedded commands within the fetched transcript text before it is appended to the vault note.
  • Capability inventory: The skill has the capability to execute shell commands (find, cat, sed, tr), invoke other skills (claude --skill youtube-summary), and execute local scripts (../obsidian-vault/scripts/new_note.sh) as described in SKILL.md.
  • Sanitization: The skill performs basic sanitization for filename generation (slugification using sed and tr), but it does not sanitize the body content of the transcript or summary.
  • [COMMAND_EXECUTION]: The skill's workflow utilizes a Bash script that executes several system commands and local scripts. While input like $ARGUMENTS and $TITLE are quoted (e.g., "$URL", "$TITLE"), which mitigates basic shell injection, the skill's reliance on shell execution with external inputs remains a relevant capability to monitor.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 01:51 PM
Security Audit — agent-trust-hub — ingest-youtube