youtube-tools
Pass
Audited by Gen Agent Trust Hub on Jun 17, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill contains an explicit instruction to bypass its own constraints and structure if requested by the user. Under the 'When NOT to use' section, it states: 'User explicitly asks for raw output without skill discipline → respect override'. This provides a mechanism for users to circumvent the skill's defined behavioral guardrails.
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process untrusted data from an external source (YouTube) without adequate protection against embedded malicious instructions.
- Ingestion points: The
search_videostool retrieves video titles and descriptions from the YouTube Data API, which are then processed by the agent. - Boundary markers: The instructions do not define delimiters (e.g., XML tags or Markdown blocks) to separate untrusted external data from the agent's instructions, nor do they include warnings to ignore instructions embedded in the search results.
- Capability inventory: The skill has access to sensitive filesystem tools including
Glob,Grep, andRead, as specified in theallowed-toolsfrontmatter. - Sanitization: There is no mention of sanitizing or validating the content of the data returned by the API before processing or displaying it.
- [COMMAND_EXECUTION]: The workflow section contains unusual verification steps that suggest the agent might perform environmental checks or local operations unrelated to the primary YouTube task. Specifically, it includes 'verify: package installed + import succeeds' and 'verify: output file exists + no syntax error' following API-based tool calls.
Audit Metadata