upload-video
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill invokes local CLI tools and Python scripts (
cli.py,script_srt.py,git,gh) to automate YouTube channel authentication and video uploads. These operations are transparently described and directly support the skill's primary functionality. - [INDIRECT_PROMPT_INJECTION]: The skill ingests data from project files like
upload.jsonandindex.htmlto generate video metadata and caption tracks. While these files represent an external data ingestion surface, the skill treats the content as data for the YouTube API rather than executable instructions, and the processing logic inscript_srt.pyis restricted to specific regex-based parsing. - [EXTERNAL_DOWNLOADS]: The skill performs a status check on a user-created privacy policy hosted on GitHub Pages using
curl. This network operation targets a well-known service and is a functional requirement for the YouTube API OAuth consent process. - [SAFE]: The skill demonstrates security consciousness by instructing the user to set restrictive file permissions on sensitive OAuth token files and ensuring they are excluded from version control systems. It correctly handles the sensitive OAuth setup by advising the user to perform interactive steps and maintaining local storage for credentials.
Audit Metadata