youtube-clipper

Fail

Audited by Gen Agent Trust Hub on Jul 30, 2026

Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The documentation in SKILL.md (and its translations) contains instructions for installing the Deno runtime using a piped curl-to-shell command (curl -fsSL https://deno.land/install.sh | sh). This is a dangerous pattern that executes remote code without verification. While targeting a well-known service, the execution method itself is inherently high-risk.
  • [EXTERNAL_DOWNLOADS]: The downloader.py script executes yt-dlp with the --remote-components ejs:github flag. This configuration allows the tool to fetch and execute external JavaScript components from GitHub at runtime to handle changes in video platform obfuscation, introducing a vector for remote code execution.
  • [COMMAND_EXECUTION]: The skill makes extensive use of subprocess.run() across downloader.py, clip_extractor.py, and transcriber.py to invoke system tools like ffmpeg and yt-dlp. While functional, the lack of strict input sanitization on variables like video URLs or file paths poses a risk of command injection.
  • [PROMPT_INJECTION]: The skill is highly susceptible to Indirect Prompt Injection.
  • Ingestion points: The skill fetches video metadata (titles, descriptions) and subtitle text from external sources in downloader.py and transcriber.py.
  • Boundary markers: Prompts in chapter_analyzer.py and subtitle_translator.py interpolate untrusted subtitle content directly without using delimiters or instructions to ignore embedded commands.
  • Capability inventory: The system possesses the capability to execute shell commands (subprocess.run), write to the local file system, and interact with the Gemini API.
  • Sanitization: No sanitization, escaping, or schema validation is applied to the externally sourced text before it is inserted into the AI's instructional prompt.
  • [DATA_EXFILTRATION]: The downloader.py script reads the YTDLP_COOKIES environment variable to access local cookie files. If an attacker can influence environment variables or point this path to sensitive system files, it could lead to the exposure of credentials or session tokens.
Recommendations
  • HIGH: Downloads and executes remote code from: https://deno.land/install.sh - DO NOT USE without thorough review
  • AI detected serious security threats
Audit Metadata
Risk Level
HIGH
Analyzed
Jul 30, 2026, 08:27 PM
Security Audit — agent-trust-hub — youtube-clipper