youtube-to-markdown
Pass
Audited by Gen Agent Trust Hub on Sep 25, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from external sources (YouTube video descriptions, transcripts, and chapters) which is then passed to AI subagents for summarization and formatting. This data could contain hidden instructions intended to override subagent behavior.
- Ingestion points: Transcripts and metadata are extracted in
extract_data.pyandextract_transcript.pyand subsequently read into the context for subagents inSKILL.mdSteps 4, 5, 6, 7, and 8. - Boundary markers: The prompts used for subagents lack explicit delimiters (like XML tags or block markers) to separate the data from the instructions, increasing the risk of the model confusing data for commands.
- Capability inventory: Subagents are granted access to the
Writetool to save results to the local filesystem. - Sanitization: There is no evidence of filtering or sanitizing the extracted transcript content before it is interpolated into subagent prompts.
- [COMMAND_EXECUTION]: The skill's architecture relies on executing external system commands via
subprocess.runwithin several Python scripts (extract_data.py,extract_transcript.py,extract_transcript_whisper.py). It specifically calls tools likeyt-dlpandwhisperusing user-supplied inputs such as YouTube URLs. While the use of argument lists instead of shell strings mitigates common shell injection vulnerabilities, it remains a primary vector for potential exploitation if the external tools themselves have vulnerabilities.
Audit Metadata