baoyu-youtube-transcript

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from YouTube (transcripts and descriptions) and provides it to an AI agent for structuring and speaker identification. This introduces a risk where a video author could embed malicious instructions in the transcript or description to influence the agent's behavior.
  • Ingestion points: scripts/youtube.ts fetches content from YouTube URLs using the InnerTube API and yt-dlp.
  • Boundary markers: The prompts/speaker-transcript.md provides a template for processing, but there are no explicit instructions to the AI to ignore embedded commands within the transcript content itself.
  • Capability inventory: The skill uses writeFileSync for local storage in scripts/storage.ts and scripts/main.ts, and executes shell commands via spawnSync in scripts/youtube.ts.
  • Sanitization: Implements htmlUnescape and stripTags in scripts/shared.ts to clean transcript text, though these do not prevent high-level prompt injection attacks.
  • [COMMAND_EXECUTION]: The script invokes external CLI tools (yt-dlp, uvx, or python3) to handle video processing and metadata extraction.
  • Evidence: scripts/youtube.ts contains the detectYtDlpCommand and fetchYtDlpInfo functions, which use child_process.spawnSync to execute system commands with specific flags.
  • [EXTERNAL_DOWNLOADS]: Fetches metadata, transcript snippets, and images from well-known YouTube domains and utilizes remote components via GitHub.
  • Evidence: scripts/youtube.ts makes fetch requests to youtube.com and i.ytimg.com. It also configures yt-dlp with the --remote-components ejs:github flag, which allows fetching additional extractors from a remote repository.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 06:59 AM
Security Audit — agent-trust-hub — baoyu-youtube-transcript