youtube-transcript

Pass

Audited by Gen Agent Trust Hub on Aug 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external data from YouTube transcripts, creating a surface for indirect prompt injection. \n
  • Ingestion points: Transcripts are fetched via the agentbody_youtube_transcript and youtube_web_v2_video_captions tools as described in SKILL.md. \n
  • Boundary markers: The instructions do not define delimiters or specific safety guidelines to isolate fetched transcript content from the agent's instruction context. \n
  • Capability inventory: The skill is limited to read-only research operations through the SandBase gateway. No capabilities for file writing, system command execution, or network exfiltration are present in the skill manifest. \n
  • Sanitization: The skill does not implement sanitization or validation of the ingested transcript content. \n- [NO_CODE]: The skill does not ship with any executable scripts, binaries, or source code files.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 27, 2026, 11:31 PM
Security Audit — agent-trust-hub — youtube-transcript