youtube-processor
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data (YouTube transcripts) and interpolates it into a prompt for summarization, creating a surface for potential instruction injection.
- Ingestion points: Video transcripts are retrieved from external YouTube URLs via
tools/get_transcript.py,tools/youtube_core.py, and the FastAPI endpoint inapi/main.py. - Boundary markers: In
tools/youtube_core.py, the transcript content is appended to the system instructions using simple newlines (\n\nTranscript:\n{transcript}) rather than robust delimiters or explicit warnings for the AI to ignore instructions embedded within the transcript text. - Capability inventory: The skill possesses capabilities for
Bashexecution (to run the extractor),WebFetch(to communicate with the transcript API), andWrite(to save the final notes to the local Obsidian vault). - Sanitization: No sanitization, filtering, or validation is performed on the transcript text before it is processed by the AI model.
Audit Metadata