youtube-processor

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (YouTube transcripts) and interpolates it into a prompt for summarization, creating a surface for potential instruction injection.
  • Ingestion points: Video transcripts are retrieved from external YouTube URLs via tools/get_transcript.py, tools/youtube_core.py, and the FastAPI endpoint in api/main.py.
  • Boundary markers: In tools/youtube_core.py, the transcript content is appended to the system instructions using simple newlines (\n\nTranscript:\n{transcript}) rather than robust delimiters or explicit warnings for the AI to ignore instructions embedded within the transcript text.
  • Capability inventory: The skill possesses capabilities for Bash execution (to run the extractor), WebFetch (to communicate with the transcript API), and Write (to save the final notes to the local Obsidian vault).
  • Sanitization: No sanitization, filtering, or validation is performed on the transcript text before it is processed by the AI model.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:03 AM
Security Audit — agent-trust-hub — youtube-processor