youtube-clipper
Fail
Audited by Gen Agent Trust Hub on Jul 30, 2026
Risk Level: HIGHREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTIONDATA_EXFILTRATION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The documentation in
SKILL.md(and its translations) contains instructions for installing the Deno runtime using a piped curl-to-shell command (curl -fsSL https://deno.land/install.sh | sh). This is a dangerous pattern that executes remote code without verification. While targeting a well-known service, the execution method itself is inherently high-risk. - [EXTERNAL_DOWNLOADS]: The
downloader.pyscript executesyt-dlpwith the--remote-components ejs:githubflag. This configuration allows the tool to fetch and execute external JavaScript components from GitHub at runtime to handle changes in video platform obfuscation, introducing a vector for remote code execution. - [COMMAND_EXECUTION]: The skill makes extensive use of
subprocess.run()acrossdownloader.py,clip_extractor.py, andtranscriber.pyto invoke system tools likeffmpegandyt-dlp. While functional, the lack of strict input sanitization on variables like video URLs or file paths poses a risk of command injection. - [PROMPT_INJECTION]: The skill is highly susceptible to Indirect Prompt Injection.
- Ingestion points: The skill fetches video metadata (titles, descriptions) and subtitle text from external sources in
downloader.pyandtranscriber.py. - Boundary markers: Prompts in
chapter_analyzer.pyandsubtitle_translator.pyinterpolate untrusted subtitle content directly without using delimiters or instructions to ignore embedded commands. - Capability inventory: The system possesses the capability to execute shell commands (
subprocess.run), write to the local file system, and interact with the Gemini API. - Sanitization: No sanitization, escaping, or schema validation is applied to the externally sourced text before it is inserted into the AI's instructional prompt.
- [DATA_EXFILTRATION]: The
downloader.pyscript reads theYTDLP_COOKIESenvironment variable to access local cookie files. If an attacker can influence environment variables or point this path to sensitive system files, it could lead to the exposure of credentials or session tokens.
Recommendations
- HIGH: Downloads and executes remote code from: https://deno.land/install.sh - DO NOT USE without thorough review
- AI detected serious security threats
Audit Metadata