youtube-briefing
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes content from external sources which could contain malicious instructions designed to manipulate the agent's behavior.
- Ingestion points: The skill fetches data from a wide range of external YouTube channels, playlists, and podcast show pages identified in the Source Pool section of SKILL.md.
- Boundary markers: There are no instructions or delimiters defining how the agent should distinguish between the skill's instructions and potentially adversarial text within the external content.
- Capability inventory: The skill has the capability to write files to the local
notebook/directory and format links for Slack distribution. - Sanitization: The instructions do not specify any validation or sanitization routines for the external data before it is processed into the briefing.
- [DATA_EXFILTRATION]: The skill involves network operations to retrieve data from external platforms.
- Evidence: SKILL.md defines a comprehensive source pool of URLs targeting YouTube, simplecast, and official domains of well-known venture capital firms such as a16z, Sequoia, and Bessemer.
- Note: These network requests are directed at well-known services and trusted organizations for the legitimate purpose of content discovery and summarization.
Audit Metadata