youtube-research

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from YouTube, including video comments and captions, which could contain malicious instructions designed to influence agent behavior.
  • Ingestion points: Untrusted data enters the agent context through tools like youtube_web_v2_video_comments, youtube_web_v2_video_comment_replies, and youtube_web_v2_video_captions (referenced in SKILL.md and references/sandbase-api-map.md).
  • Boundary markers: The instructions do not include specific delimiters or warnings for the agent to ignore instructions embedded in the external content.
  • Capability inventory: The skill uses sandbase_call_tool to interact with the YouTube API and retrieve content (SKILL.md).
  • Sanitization: There is no mention of sanitizing or filtering the retrieved data before it is processed by the agent.
  • [NO_CODE]: The skill consists exclusively of markdown documentation and instructions for using existing platform tools. It does not include any scripts, binaries, or dependency configuration files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — youtube-research