skills/openclaw/gogcli/gog-youtube/Gen Agent Trust Hub

gog-youtube

Pass

Audited by Gen Agent Trust Hub on Aug 17, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill consists of documentation and configuration for a YouTube integration. It does not contain any executable scripts, remote downloads, or credential exposures.
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process data from YouTube, such as comments and video descriptions, which represents an attack surface for indirect prompt injection. However, the instructions explicitly recommend the use of the --wrap-untrusted flag when processing this content to mitigate the risk of the agent following embedded instructions.
  • Ingestion points: YouTube API outputs (comments, activities, search results).
  • Boundary markers: The instructions recommend using the --wrap-untrusted flag to delimit untrusted content.
  • Capability inventory: The skill uses the 'gog' CLI tool for read and write operations on YouTube.
  • Sanitization: The use of --wrap-untrusted is suggested as a standard sanitization/boundary practice.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 17, 2026, 02:43 PM
Security Audit — agent-trust-hub — gog-youtube