baoyu-youtube-transcript
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted content from YouTube (transcripts and descriptions) and provides it to an AI agent for structuring and speaker identification. This introduces a risk where a video author could embed malicious instructions in the transcript or description to influence the agent's behavior.
- Ingestion points:
scripts/youtube.tsfetches content from YouTube URLs using the InnerTube API andyt-dlp. - Boundary markers: The
prompts/speaker-transcript.mdprovides a template for processing, but there are no explicit instructions to the AI to ignore embedded commands within the transcript content itself. - Capability inventory: The skill uses
writeFileSyncfor local storage inscripts/storage.tsandscripts/main.ts, and executes shell commands viaspawnSyncinscripts/youtube.ts. - Sanitization: Implements
htmlUnescapeandstripTagsinscripts/shared.tsto clean transcript text, though these do not prevent high-level prompt injection attacks. - [COMMAND_EXECUTION]: The script invokes external CLI tools (
yt-dlp,uvx, orpython3) to handle video processing and metadata extraction. - Evidence:
scripts/youtube.tscontains thedetectYtDlpCommandandfetchYtDlpInfofunctions, which usechild_process.spawnSyncto execute system commands with specific flags. - [EXTERNAL_DOWNLOADS]: Fetches metadata, transcript snippets, and images from well-known YouTube domains and utilizes remote components via GitHub.
- Evidence:
scripts/youtube.tsmakesfetchrequests toyoutube.comandi.ytimg.com. It also configuresyt-dlpwith the--remote-components ejs:githubflag, which allows fetching additional extractors from a remote repository.
Audit Metadata