youtube-transcript-dossier
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted transcript data fetched from YouTube, which could contain malicious instructions designed to influence the agent's summarization. \n
- Ingestion points:
scripts/fetch_transcript.pyfetches transcripts using the YouTube API. \n - Boundary markers: The skill instructions lack explicit delimiters to separate external transcript content from system instructions. \n
- Capability inventory: The skill involves file creation (dossiers) and command execution (
yt-dlp). \n - Sanitization: The script filters specific non-speech tags (e.g., [Music]) but does not perform general content sanitization on the transcript text. \n- [COMMAND_EXECUTION]: The script
scripts/fetch_transcript.pyinvokes theyt-dlputility viasubprocess.runto retrieve video metadata. Command injection is mitigated by regex-based validation of the YouTube video ID. \n- [DYNAMIC_EXECUTION]: The testing utilityscripts/test_skill.pyusesimportlib.utilto dynamically load and execute functions fromscripts/fetch_transcript.pyduring validation probes.
Audit Metadata