youtube-transcript-cn
Pass
Audited by Gen Agent Trust Hub on Aug 21, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The script
scripts/get_transcript.pyautomatically installs theyoutube-transcript-apipackage from the public Python Package Index (PyPI) usingpipif the module is not found in the current environment. - [COMMAND_EXECUTION]: The script uses
subprocess.check_callto execute shell commands at runtime to handle the dynamic installation of dependencies. - [PROMPT_INJECTION]: The skill ingests transcripts fetched from YouTube, which is an external and untrusted source. This provides a surface for indirect prompt injection where instructions hidden in video subtitles could attempt to influence the agent's behavior.
- Ingestion points: Transcripts are fetched from external YouTube URLs via the API in
scripts/get_transcript.py. - Boundary markers: Absent. The skill does not use specific delimiters or instructions to isolate the external transcript content from the agent's operational logic.
- Capability inventory: The script has the ability to write output to arbitrary local file paths provided via arguments and output text directly to the agent's context.
- Sanitization: Absent. No filtering or validation is performed on the retrieved transcript text before processing.
Audit Metadata