youtube-transcript-dossier

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted transcript data fetched from YouTube, which could contain malicious instructions designed to influence the agent's summarization. \n
  • Ingestion points: scripts/fetch_transcript.py fetches transcripts using the YouTube API. \n
  • Boundary markers: The skill instructions lack explicit delimiters to separate external transcript content from system instructions. \n
  • Capability inventory: The skill involves file creation (dossiers) and command execution (yt-dlp). \n
  • Sanitization: The script filters specific non-speech tags (e.g., [Music]) but does not perform general content sanitization on the transcript text. \n- [COMMAND_EXECUTION]: The script scripts/fetch_transcript.py invokes the yt-dlp utility via subprocess.run to retrieve video metadata. Command injection is mitigated by regex-based validation of the YouTube video ID. \n- [DYNAMIC_EXECUTION]: The testing utility scripts/test_skill.py uses importlib.util to dynamically load and execute functions from scripts/fetch_transcript.py during validation probes.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 10:51 AM
Security Audit — agent-trust-hub — youtube-transcript-dossier