ingest-youtube
Pass
Audited by Gen Agent Trust Hub on May 18, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it ingests untrusted external data (YouTube transcripts) and integrates it into the user's Obsidian vault.
- Ingestion points: The skill ingests a user-provided YouTube URL via
$ARGUMENTSand subsequently processes summary and transcript files generated by theyoutube-summarytool (as seen in the Workflow section ofSKILL.md). - Boundary markers: There are no explicit boundary markers or instructions to ignore embedded commands within the fetched transcript text before it is appended to the vault note.
- Capability inventory: The skill has the capability to execute shell commands (
find,cat,sed,tr), invoke other skills (claude --skill youtube-summary), and execute local scripts (../obsidian-vault/scripts/new_note.sh) as described inSKILL.md. - Sanitization: The skill performs basic sanitization for filename generation (slugification using
sedandtr), but it does not sanitize the body content of the transcript or summary. - [COMMAND_EXECUTION]: The skill's workflow utilizes a Bash script that executes several system commands and local scripts. While input like
$ARGUMENTSand$TITLEare quoted (e.g.,"$URL","$TITLE"), which mitigates basic shell injection, the skill's reliance on shell execution with external inputs remains a relevant capability to monitor.
Audit Metadata