ingest-youtube

Pass

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Uses the subprocess module to call yt-dlp for extracting video metadata and downloading audio streams required for Whisper transcription. This is restricted to legitimate YouTube processing.
  • [COMMAND_EXECUTION]: Executes nvidia-smi via subprocess in the supervisor module to provide real-time GPU utilization and memory metrics during local transcription jobs.
  • [EXTERNAL_DOWNLOADS]: Downloads audio files from YouTube to local temporary storage to facilitate transcription for videos where captions are unavailable.
  • [EXTERNAL_DOWNLOADS]: Fetches data from external services including the YouTube Transcript API and the OpenAI Whisper API.
  • [PROMPT_INJECTION]: Displays a surface for indirect prompt injection. Since the skill ingests and processes transcripts from untrusted external videos, malicious instructions embedded in captions could potentially influence agent behavior if subsequently stored in and retrieved from the memory system.
  • [SAFE]: Implements secure configuration management by utilizing environment variables for proxy credentials (IPRoyal) and API keys (OpenAI), avoiding hardcoded secrets.
  • [SAFE]: The scheduled task registration feature in persona_monitor.py uses an internal scheduler skill for automated updates, which is a documented and intended architectural pattern.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — ingest-youtube