youtube-channel-analytics-dashboard
Fail
Audited by Gen Agent Trust Hub on Oct 1, 2026
Risk Level: HIGHPRIVILEGE_ESCALATIONOBFUSCATIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [PRIVILEGE_ESCALATION]: The installation instructions explicitly direct the user to run
setup.exeas Administrator. This request violates the principle of least privilege, as a YouTube analytics dashboard should not require full system administrative access to function, posing a significant risk of system compromise. - [OBFUSCATION]: The skill requires users to extract the installation archive using a specific password (
trainer2026). This technique is frequently employed by attackers to prevent automated security tools and network gateways from scanning the contents of the archive for malicious code or signatures. - [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data from the YouTube Data API, creating a surface for indirect prompt injection.
- Ingestion points: Data fetched via YouTube Data API v3 (SKILL.md).
- Boundary markers: No explicit delimiters or warnings to ignore instructions within the API data are mentioned.
- Capability inventory: File writing (CSV/PDF reporting), command execution (
YouTubeAnalytics.exe), and webhook integration. - Sanitization: The documentation does not specify any sanitization or validation of the data retrieved from external API sources.
- [COMMAND_EXECUTION]: The core functionality relies on the execution of a local binary (
YouTubeAnalytics.exe) with command-line arguments. In combination with the suspicious installation method, this provides a pathway for the execution of untrusted code with elevated privileges. - [EXTERNAL_DOWNLOADS]: The skill instructs users to download an installation package from an external repository. While typical for software distribution, in this context it facilitates the delivery of the suspicious password-protected binary.
Recommendations
- AI detected serious security threats
Audit Metadata