Back to skill

Security audit

Pub Youtube

Security checks across malware telemetry and agentic risk

Overview

This is a broad SkillBoss API gateway with email, SMS, scraping, uploads, and paid model access, but it is packaged as a YouTube watcher and lacks clear safeguards for high-impact actions.

Install only if you intentionally want to give an agent broad SkillBoss API access, not just YouTube transcript help. Use a restricted or spending-limited API key if available, and require explicit confirmation before any email, SMS, OTP, scraping, document upload, audio upload, media generation, or other paid external action.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (16)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The manifest advertises a narrow YouTube transcript skill, but the body documents a general-purpose API gateway for chat, media generation, search, scraping, documents, email, and SMS. This scope mismatch can mislead reviewers and users into granting or invoking a skill with far broader data access and side-effect capabilities than expected.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
Outbound email capability is unrelated to the stated YouTube transcript purpose and enables direct third-party side effects. In a misleadingly scoped skill, this creates risk of spam, phishing, data leakage, or unauthorized communications initiated under false expectations.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
SMS/OTP features are unrelated to transcript reading and introduce sensitive third-party communication and identity-verification workflows. These can be abused for unsolicited messaging, account workflow interference, or collection/transmission of phone numbers and verification codes.

Context-Inappropriate Capability

Medium
Confidence
92% confidence
Finding
Image and video generation are materially outside the declared YouTube transcript-reader scope. While less directly dangerous than email/SMS, they broaden the skill into a multi-purpose remote execution surface and increase the chance of misuse, unexpected billing, or exfiltration of user prompts and media inputs.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
TTS, STT, and music generation exceed the stated transcript-reading purpose and can transmit sensitive audio or text content to external providers. This increases privacy and abuse risk, especially when users believe they are using a narrowly scoped summarization utility.

Context-Inappropriate Capability

Medium
Confidence
95% confidence
Finding
Web search, scraping, and document parsing are unrelated to the advertised purpose and significantly widen the kinds of user and third-party data that may be transmitted externally. This creates hidden privacy exposure and capability creep beyond what a user would reasonably expect from a YouTube transcript tool.

Scope Creep

High
Confidence
88% confidence
Finding
The documented behavior relies on networked API calls and side-effectful remote actions such as sending email and SMS, yet the declared allowed-tools are only Bash and Read. This mismatch undermines reviewability and can conceal the practical execution and risk profile of the skill from policy enforcement or human reviewers.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The documented capabilities materially exceed the declared purpose of a YouTube transcript summarization skill, expanding into general web search, scraping, and executive-interview retrieval. This kind of scope mismatch is dangerous because it can hide unexpected data-access and collection behavior from reviewers and users, undermining least privilege and informed consent.

Context-Inappropriate Capability

Medium
Confidence
96% confidence
Finding
LinkedIn, Amazon, broad web scraping, and CEO interview retrieval are not reasonably necessary for a YouTube watcher skill and introduce collection paths for unrelated third-party data. In this context, the mismatch makes the skill more dangerous because users may invoke it expecting transcript processing while it can access and aggregate broader external content, including potentially sensitive profile or corporate information.

Description-Behavior Mismatch

Medium
Confidence
95% confidence
Finding
The documented tool catalog exposes capabilities far beyond the stated purpose of fetching and reading YouTube transcripts, including outbound messaging, document parsing, embeddings, and presentation generation. This capability mismatch increases attack surface and creates a deceptive-permissions problem where the skill may be able to process data or communicate externally in ways users would not reasonably expect.

Context-Inappropriate Capability

Medium
Confidence
97% confidence
Finding
Email sending is unrelated to the stated transcript-reading function and enables unsolicited external communication, data exfiltration, phishing, or spam if invoked by a compromised or misused workflow. Because users would not expect a YouTube transcript skill to send email, this is especially risky from a trust and consent perspective.

Context-Inappropriate Capability

High
Confidence
98% confidence
Finding
SMS and OTP verification capabilities are particularly sensitive because they allow direct contact with phone numbers and interaction with authentication-related workflows. In a skill whose stated purpose is transcript processing, these features are unjustified and could be abused for spam, social engineering, privacy violations, or unauthorized verification flows.

Context-Inappropriate Capability

Medium
Confidence
90% confidence
Finding
Presentation generation is not inherently dangerous, but it is outside the declared YouTube transcript-reading scope and represents unnecessary capability expansion. Extra undeclared generation features can be chained with other tools to process or repackage data in ways users did not authorize or anticipate.

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The documentation describes email and SMS actions without warning that they contact third parties and process personal data such as phone numbers, recipients, subjects, and message bodies. Missing warnings increase the chance of accidental misuse and uninformed transmission of sensitive or regulated data.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The skill shows audio, document, search, and media inputs being sent to external APIs without clear privacy disclosures. Users may unknowingly submit sensitive recordings, documents, prompts, or search terms to third-party providers under the mistaken assumption of local-only transcript handling.

Missing User Warnings

Medium
Confidence
96% confidence
Finding
Listing email and SMS sending capabilities without user-facing warnings or safeguards obscures that the skill can initiate external communications with privacy, financial, and compliance consequences. This lack of disclosure makes accidental misuse and user deception more likely, especially given the mismatch with the stated transcript-focused purpose.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.