youtube-full

Pass

Audited by Gen Agent Trust Hub on Jul 9, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill is distributed through the author's repository at 'ZeroPointRepo/youtube-skills' and involves a remote installation process using the 'skills' CLI.
  • [DATA_EXFILTRATION]: The skill interacts with an external service, 'transcriptapi.com', to retrieve video metadata and transcripts. This requires sending identifiers such as video IDs and search queries to a third-party domain not on the standard whitelist.
  • [PROMPT_INJECTION]: The skill facilitates the ingestion of untrusted data from YouTube, creating a potential vector for indirect prompt injection.
  • Ingestion points: External content is brought into the agent context via the 'get_transcript' and 'search_youtube' operations.
  • Boundary markers: The documentation does not describe the use of markers or specific instructions to help the agent distinguish between its core instructions and the fetched transcript data.
  • Capability inventory: The skill is designed for use with powerful agents (e.g., Claude, Gemini) that have the ability to interact with the local system and external tools, which could be leveraged if an injection is successful.
  • Sanitization: No mention is made of sanitizing or filtering the fetched YouTube content before it is presented to the agent for processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 9, 2026, 09:08 PM
Security Audit — agent-trust-hub — youtube-full