ingest-yt-history
Warn
Audited by Gen Agent Trust Hub on Mar 17, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill performs dynamic code loading which can be risky if the source paths are untrusted. Specifically,
src/artist_profiles.pyusesimportlib.utilto loadenrich_taxonomy.pyfrom a relative directory. Additionally,src/taxonomy.pyandsanity/hmt_verifier.pymodify the Python search path (sys.path) at runtime based on theMEMORY_ROOTenvironment variable to import thehorus_music_taxonomymodule. - [CREDENTIALS_UNSAFE]: The modules
src/enrich.pyandsanity/youtube_api.pyare designed to load sensitive API keys from.envfiles located in the user's home directory or workspace. While common for local configuration, this pattern involves the automated reading of sensitive credential files. - [PROMPT_INJECTION]: The skill processes external data provided by the user in the form of YouTube watch history JSON files. Since the content of these files (such as video titles and channel names) is untrusted and later used to build a persona profile or synced to a memory service, it presents a surface for indirect prompt injection that could influence the agent's behavior during future interactions.
- [DATA_EXFILTRATION]: The skill communicates with the well-known YouTube Data API (
googleapis.com) to fetch video metadata. This is a legitimate operation for the skill's purpose, but it involves sending video identifiers to an external service.
Audit Metadata