youtube-transcript
Fail
Audited by Gen Agent Trust Hub on Sep 28, 2026
Risk Level: HIGHPRIVILEGE_ESCALATIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [PRIVILEGE_ESCALATION]: The skill instructs the agent to run
sudo apt update && sudo apt install -y yt-dlpfor dependency installation on Linux systems, which requires administrative access. - [COMMAND_EXECUTION]: The skill executes multiple shell commands to process video data, including
yt-dlp,whisper,pip, andpython3. This heavy reliance on shell execution increases the attack surface for command injection. - [EXTERNAL_DOWNLOADS]: The skill downloads and installs software packages including
yt-dlpandopenai-whisperfrom public registries. OpenAI is recognized as a well-known source for the Whisper library. - [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted metadata from YouTube. Evidence chain:
- Ingestion points: Video titles are fetched via
yt-dlp --print "%(title)s"inSKILL.md. - Boundary markers: Absent when interpolating the title into shell commands.
- Capability inventory: Includes
Bashtool and fileWriteaccess. - Sanitization: Partial sanitization is performed using
trto replace some characters (like/,:,?), but it does not account for all potential shell metacharacters (e.g., backticks or dollar signs) that could be present in a malicious video title, creating a command injection vulnerability when creating the output file.
Recommendations
- AI detected serious security threats
Audit Metadata