youtube-transcript
Pass
Audited by Gen Agent Trust Hub on Aug 27, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes external data from YouTube transcripts, creating a surface for indirect prompt injection. \n
- Ingestion points: Transcripts are fetched via the
agentbody_youtube_transcriptandyoutube_web_v2_video_captionstools as described inSKILL.md. \n - Boundary markers: The instructions do not define delimiters or specific safety guidelines to isolate fetched transcript content from the agent's instruction context. \n
- Capability inventory: The skill is limited to read-only research operations through the SandBase gateway. No capabilities for file writing, system command execution, or network exfiltration are present in the skill manifest. \n
- Sanitization: The skill does not implement sanitization or validation of the ingested transcript content. \n- [NO_CODE]: The skill does not ship with any executable scripts, binaries, or source code files.
Audit Metadata