consume-youtube
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: No malicious patterns or security vulnerabilities were detected. The skill performs local data management tasks as described.\n- [DATA_EXFILTRATION]: The skill reads and writes data (transcripts, indices, and notes) within the user's home directory (~/.pi/consume-youtube/). All data access is localized, and there are no network operations detected that would result in data exfiltration.\n- [PROMPT_INJECTION]: The skill processes YouTube transcripts, which are untrusted external data. \n
- Ingestion points: Reads YouTube transcript JSON files via ingest_bridge.py and search.py from local storage.\n
- Boundary markers: Absent; transcripts are treated as literal text data for search and indexing.\n
- Capability inventory: Limited to file reading/writing and execution of local Python scripts through run.sh.\n
- Sanitization: Standard json.loads is used for parsing structured data; no further sanitization is applied to the transcript text itself as it is intended for search.\n- [COMMAND_EXECUTION]: The run.sh and sanity.sh scripts manage environment setup and dependency verification. These scripts are used for orchestrating local skill operations and do not execute external or user-provided strings.
Audit Metadata