youtube-publishing-and-metadata

Pass

Audited by Gen Agent Trust Hub on Jul 18, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: The skill presents an attack surface for indirect prompt injection by processing untrusted data from external sources.
  • Ingestion points: According to the SKILL.md and references/scope-and-connections.md, the skill reads external content including brand-profile, goals-and-kpis, and the video source/script to generate its output.
  • Boundary markers: There are no instructions for the agent to use delimiters or specific warnings to ignore commands that might be embedded within the ingested external data.
  • Capability inventory: The skill has the capability to write and publish metadata (title, description, tags) and configuration settings (privacy, madeForKids) to YouTube via the WoopSocial integration tool.
  • Sanitization: No specific filtering or validation mechanisms are described to sanitize the content extracted from external inputs before it is incorporated into the publishing metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 18, 2026, 02:27 PM
Security Audit — agent-trust-hub — youtube-publishing-and-metadata