youtube-research
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from YouTube, including video comments and captions, which could contain malicious instructions designed to influence agent behavior.
- Ingestion points: Untrusted data enters the agent context through tools like
youtube_web_v2_video_comments,youtube_web_v2_video_comment_replies, andyoutube_web_v2_video_captions(referenced inSKILL.mdandreferences/sandbase-api-map.md). - Boundary markers: The instructions do not include specific delimiters or warnings for the agent to ignore instructions embedded in the external content.
- Capability inventory: The skill uses
sandbase_call_toolto interact with the YouTube API and retrieve content (SKILL.md). - Sanitization: There is no mention of sanitizing or filtering the retrieved data before it is processed by the agent.
- [NO_CODE]: The skill consists exclusively of markdown documentation and instructions for using existing platform tools. It does not include any scripts, binaries, or dependency configuration files.
Audit Metadata