ingest-youtube
Pass
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Uses the
subprocessmodule to callyt-dlpfor extracting video metadata and downloading audio streams required for Whisper transcription. This is restricted to legitimate YouTube processing. - [COMMAND_EXECUTION]: Executes
nvidia-smivia subprocess in the supervisor module to provide real-time GPU utilization and memory metrics during local transcription jobs. - [EXTERNAL_DOWNLOADS]: Downloads audio files from YouTube to local temporary storage to facilitate transcription for videos where captions are unavailable.
- [EXTERNAL_DOWNLOADS]: Fetches data from external services including the YouTube Transcript API and the OpenAI Whisper API.
- [PROMPT_INJECTION]: Displays a surface for indirect prompt injection. Since the skill ingests and processes transcripts from untrusted external videos, malicious instructions embedded in captions could potentially influence agent behavior if subsequently stored in and retrieved from the memory system.
- [SAFE]: Implements secure configuration management by utilizing environment variables for proxy credentials (IPRoyal) and API keys (OpenAI), avoiding hardcoded secrets.
- [SAFE]: The scheduled task registration feature in
persona_monitor.pyuses an internal scheduler skill for automated updates, which is a documented and intended architectural pattern.
Audit Metadata