youtube-summary

Pass

Audited by Gen Agent Trust Hub on May 18, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses yt-dlp to fetch video metadata and subtitles. User input (the URL) is passed as an argument to the command. While command injection is a theoretical risk, the usage pattern is standard for this type of utility, and the skill follows best practices by using shell variables and sanitizing the video title for file system operations.
  • [EXTERNAL_DOWNLOADS]: The skill downloads subtitle files from YouTube servers via yt-dlp. This is the core functionality of the skill and targets a well-known service (YouTube/Google), which does not escalate the security risk.
  • [REMOTE_CODE_EXECUTION]: There is no remote code execution or dynamic execution of untrusted code. The Python script used for cleaning transcripts is included in the skill and runs locally on the downloaded text.
Audit Metadata
Risk Level
SAFE
Analyzed
May 18, 2026, 11:35 AM
Security Audit — agent-trust-hub — youtube-summary