youtube-researcher

Pass

Audited by Gen Agent Trust Hub on Jul 11, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill exhibits an attack surface for indirect prompt injection by ingesting untrusted data from an external source and providing the agent with capabilities that could be influenced by that data.
  • Ingestion points: The skill directs the agent to navigate to YouTube search results and take snapshots of the page content (SKILL.md).
  • Boundary markers: There are no defined delimiters or specific instructions to treat the external page content as untrusted or to ignore instructions embedded within video titles or descriptions.
  • Capability inventory: The agent is granted the ability to write to the local file system (docs/youtube-research.md) based on the external data gathered.
  • Sanitization: The skill explicitly instructs the agent to report exactly what is read from the page without mentions of filtering or sanitizing the content for malicious directives.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 11, 2026, 10:31 AM
Security Audit — agent-trust-hub — youtube-researcher