space-video-topic

Warn

Audited by Gen Agent Trust Hub on Aug 22, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONDATA_EXFILTRATIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to execute several shell commands involving yt-dlp and ffmpeg to download videos, extract audio, and handle file system operations within the 00_参考/ and 01_选题/ directories.
  • [DATA_EXPOSURE_AND_EXFILTRATION]: The skill explicitly instructs the agent to access the user's local browser data using the --cookies-from-browser chrome flag. This allows the agent to extract session cookies and authentication tokens from the local Chrome installation to bypass platform protections on Douyin. While used for the stated purpose of video downloading, accessing browser cookie stores represents a significant exposure of sensitive authentication data.
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill uses uvx yt-dlp@latest to dynamically fetch and execute the most recent version of yt-dlp from public registries at runtime. While yt-dlp is a well-known tool, executing unpinned, latest versions of external software introduces a dependency on the integrity of the external repository.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted external data by downloading videos and extracting transcripts/subtitles which are then analyzed by the agent to generate new content. This ingestion of arbitrary external text represents an indirect prompt injection surface.
  • Ingestion points: Video transcripts (00_参考/逐字稿.txt) and platform-provided subtitles.
  • Boundary markers: The skill does not provide specific instructions to the agent to ignore or delimit embedded instructions within the extracted transcripts.
  • Capability inventory: The skill has access to shell execution (yt-dlp, ffmpeg, uv), file system write access, and potential network access via the downloader tools.
  • Sanitization: There is no evidence of sanitization, filtering, or validation of the text extracted from external videos before it is processed by the agent.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 22, 2026, 04:53 AM