skills/unifapi-agent/skills/youtube/Gen Agent Trust Hub

youtube

Pass

Audited by Gen Agent Trust Hub on Jul 2, 2026

Risk Level: SAFE
Full Analysis
  • [PROMPT_INJECTION]: The skill provides the ability to ingest untrusted data from external sources, specifically YouTube comments and captions. Ingestion points: Operations youtube/videos/{video_id}/comments and youtube/videos/{video_id}/captions in SKILL.md retrieve user-generated content. Boundary markers: The instructions do not define specific delimiters or instructions to prevent the agent from obeying commands embedded in this external data. Capability inventory: The skill is strictly limited to read-only operations via the unifapi tool interface. Sanitization: No data sanitization or filtering logic is specified for the retrieved text content.
  • [EXTERNAL_DOWNLOADS]: The documentation references the vendor's own MCP server and provides setup instructions using the vendor's package registry. Evidence: References to https://mcp.unifapi.com and npx skills add unifapi-agent/agents in README.md. Context: These resources belong to the official vendor (unifapi-agent) and are required for the skill's core functionality.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 2, 2026, 10:29 AM
Security Audit — agent-trust-hub — youtube