youtube-shorts

Warn

Audited by Gen Agent Trust Hub on Jun 22, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONCREDENTIALS_UNSAFEPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill runs shell commands to navigate to a specific local directory (/Users/gaebalai/Workspace2/youtube-bgm-auto) and execute a Python script (shorts.py).
  • [DATA_EXFILTRATION]: The skill performs network operations to upload generated videos to YouTube, which involves transmitting data to external APIs.
  • [CREDENTIALS_UNSAFE]: The skill references and performs preflight validation on sensitive local OAuth files and API keys used for YouTube authentication.
  • [PROMPT_INJECTION]: The skill presents an indirect prompt injection surface by ingesting untrusted data (user requests and Pixabay image metadata) and processing it with powerful capabilities (shell execution, network access) without explicit boundary markers or sanitization logic in the audited instructions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Jun 22, 2026, 12:02 AM
Security Audit — agent-trust-hub — youtube-shorts