youtube-to-markdown

Pass

Audited by Gen Agent Trust Hub on Sep 25, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and processes untrusted data from external sources (YouTube video descriptions, transcripts, and chapters) which is then passed to AI subagents for summarization and formatting. This data could contain hidden instructions intended to override subagent behavior.
  • Ingestion points: Transcripts and metadata are extracted in extract_data.py and extract_transcript.py and subsequently read into the context for subagents in SKILL.md Steps 4, 5, 6, 7, and 8.
  • Boundary markers: The prompts used for subagents lack explicit delimiters (like XML tags or block markers) to separate the data from the instructions, increasing the risk of the model confusing data for commands.
  • Capability inventory: Subagents are granted access to the Write tool to save results to the local filesystem.
  • Sanitization: There is no evidence of filtering or sanitizing the extracted transcript content before it is interpolated into subagent prompts.
  • [COMMAND_EXECUTION]: The skill's architecture relies on executing external system commands via subprocess.run within several Python scripts (extract_data.py, extract_transcript.py, extract_transcript_whisper.py). It specifically calls tools like yt-dlp and whisper using user-supplied inputs such as YouTube URLs. While the use of argument lists instead of shell strings mitigates common shell injection vulnerabilities, it remains a primary vector for potential exploitation if the external tools themselves have vulnerabilities.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 25, 2026, 08:05 AM
Security Audit — agent-trust-hub — youtube-to-markdown