Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Pub Youtube

v1.0.0

Fetch and read transcripts from YouTube videos for summarization and content extraction. And also 50+ models for image generation, video generation, text-to-...

0· 176·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
high confidence
!
Purpose & Capability
The skill is named and described as a YouTube transcript fetcher plus model aggregator, but SKILL.md contains only generic docs/examples for the SkillBoss API (api.heybossai.com) and many model IDs — there are no concrete instructions for fetching YouTube transcripts (no YouTube API, no youtube-dl, no scraping instructions). The requested environment variable (SKILLBOSS_API_KEY) fits the SkillBoss usage but does not by itself justify the 'YouTube' purpose.
!
Instruction Scope
Runtime instructions direct calls to SkillBoss endpoints and model-run examples (chat, image, video, tts, stt) and show how to post audio/base64, download image/video URLs, etc. They do not instruct the agent how to locate or fetch YouTube video transcripts or which service will do that. Because the SKILL.md is the operative runtime behavior, the absence of YouTube-specific steps is a substantive scope mismatch.
Install Mechanism
No install spec and no code files that would write executables to disk — the skill is instruction-only, which minimizes installation risk.
Credentials
The skill requests a single credential (SKILLBOSS_API_KEY), which is proportionate if the skill's functionality is delivered by the documented SkillBoss API. However, for a claimed YouTube-transcript feature you'd expect either a YouTube API key or explicit documentation explaining how SkillBoss will obtain transcripts. The absence of any YouTube credential or explanation is a gap worth clarifying.
Persistence & Privilege
always is false and the skill is user-invocable; it does not request permanent/privileged presence or modifications to other skills or system config.
What to consider before installing
This skill appears to be a generic client for a third-party service (api.heybossai.com) rather than a focused 'YouTube transcript fetcher'. Before installing or supplying SKILLBOSS_API_KEY, ask the publisher: (1) exactly how transcripts are obtained (does SkillBoss scrape YouTube or require your YouTube API key?), (2) what the SKILLBOSS_API_KEY scope and provider reputation are, and (3) whether any video/audio content you send will be stored or shared by SkillBoss. If you can't verify those answers, avoid providing credentials or restrict them to a limited/sandbox key. Because the SKILL.md lacks YouTube-specific instructions, treat this as incomplete/incoherent until the developer clarifies the transcript flow.

Like a lobster shell, security has layers — review code before you run it.

latestvk977wjg5kgy11j1v60p41erve182szhg

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Runtime requirements

EnvSKILLBOSS_API_KEY
Primary envSKILLBOSS_API_KEY

Comments