ingest-yt-history

Warn

Audited by Gen Agent Trust Hub on Mar 17, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCREDENTIALS_UNSAFEPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill performs dynamic code loading which can be risky if the source paths are untrusted. Specifically, src/artist_profiles.py uses importlib.util to load enrich_taxonomy.py from a relative directory. Additionally, src/taxonomy.py and sanity/hmt_verifier.py modify the Python search path (sys.path) at runtime based on the MEMORY_ROOT environment variable to import the horus_music_taxonomy module.
  • [CREDENTIALS_UNSAFE]: The modules src/enrich.py and sanity/youtube_api.py are designed to load sensitive API keys from .env files located in the user's home directory or workspace. While common for local configuration, this pattern involves the automated reading of sensitive credential files.
  • [PROMPT_INJECTION]: The skill processes external data provided by the user in the form of YouTube watch history JSON files. Since the content of these files (such as video titles and channel names) is untrusted and later used to build a persona profile or synced to a memory service, it presents a surface for indirect prompt injection that could influence the agent's behavior during future interactions.
  • [DATA_EXFILTRATION]: The skill communicates with the well-known YouTube Data API (googleapis.com) to fetch video metadata. This is a legitimate operation for the skill's purpose, but it involves sending video identifiers to an external service.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 17, 2026, 06:35 AM
Security Audit — agent-trust-hub — ingest-yt-history