upload-video

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill invokes local CLI tools and Python scripts (cli.py, script_srt.py, git, gh) to automate YouTube channel authentication and video uploads. These operations are transparently described and directly support the skill's primary functionality.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests data from project files like upload.json and index.html to generate video metadata and caption tracks. While these files represent an external data ingestion surface, the skill treats the content as data for the YouTube API rather than executable instructions, and the processing logic in script_srt.py is restricted to specific regex-based parsing.
  • [EXTERNAL_DOWNLOADS]: The skill performs a status check on a user-created privacy policy hosted on GitHub Pages using curl. This network operation targets a well-known service and is a functional requirement for the YouTube API OAuth consent process.
  • [SAFE]: The skill demonstrates security consciousness by instructing the user to set restrictive file permissions on sensitive OAuth token files and ensuring they are excluded from version control systems. It correctly handles the sensitive OAuth setup by advising the user to perform interactive steps and maintaining local storage for credentials.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 08:19 PM
Security Audit — agent-trust-hub — upload-video