Back to skill

Security audit

YouTube Analytics

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly performs YouTube analytics as advertised, but its exported storage helpers can access local JSON files outside the intended results folder.

Review before installing. Use it only if you are comfortable storing YouTube queries and analytics results locally, keep the API key limited to YouTube Data API use, and avoid exposing the storage helpers to untrusted prompts or callers until path containment and opt-in persistence are improved.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/src/core/storage.ts:62
Finding

Unrestricted Filesystem Access Through Exported Storage Functions

Content
View full analysis
( data: T, category: string, operation: string, name?: string ): string { const settings = getSettings(); const categoryDir = join(settings.resultsDir, category); // Ensure category directory exists if (!existsSync(categoryDir)) { mkdirSync(categoryDir, { recursive: true }); } // Build filename - use name if provided, otherwise operation with timestamp let filename: string; if (name) { const sanitizedName = sanitizeFilename(name).substring(0, 50); filename = `${sanitizedName}.json`; } else { const timestamp = getTimestamp(); const sanitizedOperation = sanitizeFilename(operation); filename = `${timestamp}__${sanitizedOperation}.json`; } const filepath = join(categoryDir, filename); // Build wrapped result const result: SavedResult = { metadata: { savedAt: new Date().toISOString(), category, operation, ...(name && { name }), }, data, }; // Write to file writeFileSync(filepath, JSON.stringify(result, null, 2), 'utf-8'); return filepath; } ``` ```typescript export function loadResult(filepath: string): SavedResult | null { if (!existsSync(filepath)) { return null; } try { const content = readFileSync(filepath, 'utf-8'); return JSON.parse(content) as SavedResult; } catch { return null; } } ``` ```typescript export function listResults(category: string, limit?: number): string[] { const settings = getSettings(); const categoryDir = join(settings.resultsDir, category); if (!existsSync(categoryDir)) { return []; } co ...[truncated 3766 chars]
Remediation
View remediation
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (21)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

Yes, this is a mismatch based on the supplied code chunk. The description claims a YouTube analytics toolkit with multiple analysis capabilities and API usage, but the actual code shown is only a setup script that installs npm dependencies. While setup scripts can be a supporting implementation detail, this chunk by itself does not implement or evidence the declared YouTube analysis behavior. Its primary observed purpose is environment setup, which is materially different from the declared functional purpose.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: brace-expansion==2.0.2 — 4 advisory(ies): CVE-2026-13149 (brace-expansion: DoS via exponential-time expansion of consecutive non-expanding); CVE-2026-33750 (brace-expansion: Zero-step sequence causes process hang and memory exhaustion); CVE-2026-14257 (brace-expansion: DoS via unbounded expansion length causing an out-of-memory pro) +1 more

High
Category
Supply Chain
Confidence
84% confidence
Finding

brace-expansion 2.0.2 is flagged with multiple DoS-style advisories involving pathological brace patterns that can trigger excessive CPU or memory use. In this lockfile it is only a transitive dependency of minimatch/glob and there is no evidence in this file that untrusted users can directly supply glob patterns, so the risk is real but contextually limited rather than critical.

Content

No source excerpt is available for this finding.

Possible Typosquatting: 'gaxios' resembles popular package 'axios'

High
Category
Supply Chain
Confidence
70% confidence
Finding

Package name closely resembles a popular package, suggesting possible typosquatting. Attackers publish malicious packages with similar names to trick developers into installing them.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: minimatch==9.0.5 — 3 advisory(ies): CVE-2026-27904 (minimatch ReDoS: nested *() extglobs generate catastrophically backtracking regu); CVE-2026-26996 (minimatch has a ReDoS via repeated wildcards with non-matching literal in patter); CVE-2026-27903 (minimatch has ReDoS: matchOne() combinatorial backtracking via multiple non-adja)

High
Category
Supply Chain
Confidence
87% confidence
Finding

minimatch 9.0.5 is associated with ReDoS/backtracking issues when processing attacker-controlled complex glob patterns. The package is present transitively for tooling and filesystem matching, and while that makes exploitation less obvious in this YouTube analytics skill, any future use of untrusted patterns could still permit CPU exhaustion.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
60% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · scripts/src/config/settings.ts (reported line 8)May include surrounding context.

ts
import { config } from 'dotenv';
import { join } from 'path';

// Load .env file from current working directory
config();

/**

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
85% confidence
Finding

The skill uses environment-based secrets (YOUTUBE_API_KEY) and describes executable code paths, but it declares no explicit tool scope or permissions boundary. That can lead to over-broad runtime capabilities and unclear secret-handling expectations, increasing the chance that the skill accesses environment data without appropriate restriction or review.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

Using npx tsx without pinning a specific version allows execution of whatever package version is resolved at runtime, which can change over time or be maliciously replaced upstream. This creates a supply-chain risk where unreviewed code may be downloaded and executed in the user's environment.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill states that all analysis results are automatically written to local disk, including summaries, without warning the user or requiring opt-in. Silent file creation can expose sensitive queries, channel/video targets, or derived analysis artifacts to other local users, backups, sync services, or later unintended disclosure.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation indicates that API calls save retrieved YouTube data to JSON by default, but it does not clearly warn users that routine read operations create persistent local files. This can cause unintentional retention of search queries, channel/video analytics, and other retrieved content, which is a security and privacy footgun in agent environments where file writes may be unexpected or broadly accessible.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The storage section explicitly documents functions that create and retrieve persisted JSON files but provides no warning about file creation, retention, or exposure risks. In an agent skill, silent persistence can leak operational history or collected third-party data to other tools, users, or later sessions if storage boundaries are weak.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The channel retrieval API persists fetched YouTube channel data to storage by default via saveResult(result, 'channels', 'channel', channelId), even though the function is primarily presented as a retrieval helper. Undeclared default persistence increases data retention and secondary exposure risk, especially if downstream users assume the call is read-only or if stored results are later accessible to other components, users, or logs.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The bulk channel lookup function also stores fetched results by default with saveResult(results, 'channels', 'multiple_channels'), creating hidden persistence for potentially larger datasets. In the context of an analytics skill, this broadens collection and retention beyond immediate user-request fulfillment and can amplify privacy, compliance, and unauthorized access risks if the storage layer is shared or insufficiently protected.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The function persists search results by default whenever callers do not explicitly disable saving. Search queries and returned metadata can reveal user interests, investigations, or sensitive research topics, so silent retention creates a privacy and data-governance risk if storage is later accessed, logged, or shared unexpectedly. In an analytics skill, users may reasonably expect live API lookups, not automatic local persistence.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

Channel searches are also saved automatically unless the caller opts out, which can silently retain search terms and associated channel metadata. While this is not code execution or privilege escalation, it is a legitimate privacy issue because analytics searches may expose competitive research, audience profiling, or other sensitive business intent without user awareness.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill persists API responses and metadata to local JSON files by default, which creates a data-at-rest surface that a read-only analytics tool may not need. Even if the YouTube data is largely public, saved results can include user queries, channel/video selections, operational metadata, and potentially derived or enriched data that becomes locally recoverable by other processes or users on the host.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module exposes filesystem read and listing helpers for previously saved results, expanding the skill from pure API access into local data access. While these functions appear scoped to the configured results directory, they still enable retrieval of persisted artifacts and accept a direct filepath in loadResult, which increases the chance of unintended local file access if higher layers pass untrusted paths.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: qs==6.14.1 — 3 advisory(ies): CVE-2026-82417 (qs: Denial of Service via Attacker Controlled isBuffer); CVE-2026-8723 (qs has a remotely triggerable DoS: qs.stringify crashes with TypeError on null/u); CVE-2026-2391 (qs's arrayLimit bypass in comma parsing allows denial of service)

Low
Category
Supply Chain
Confidence
72% confidence
Finding

qs 6.14.1 has reported denial-of-service issues tied to crafted input during query-string parsing/stringifying. Here it arrives through googleapis-common, and in this skill context it is likely used for API request construction rather than direct parsing of attacker-controlled payloads, so the issue appears genuine but low impact in practice.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · scripts/package.json (reported line 6)May include surrounding context.

json
"version": "1.0.0",
  "type": "module",
  "dependencies": {
    "dotenv": "^16.4.7",
    "googleapis": "^170.0.0",
    "tsx": "^4.19.2",
    "typescript": "^5.7.2"

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · scripts/package.json (reported line 7)May include surrounding context.

json
"type": "module",
  "dependencies": {
    "dotenv": "^16.4.7",
    "googleapis": "^170.0.0",
    "tsx": "^4.19.2",
    "typescript": "^5.7.2"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · scripts/package.json (reported line 8)May include surrounding context.

json
"dependencies": {
    "dotenv": "^16.4.7",
    "googleapis": "^170.0.0",
    "tsx": "^4.19.2",
    "typescript": "^5.7.2"
  },
  "engines": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · scripts/package.json (reported line 9)May include surrounding context.

json
"dotenv": "^16.4.7",
    "googleapis": "^170.0.0",
    "tsx": "^4.19.2",
    "typescript": "^5.7.2"
  },
  "engines": {
    "node": ">=18.0.0"

Static analysis

No suspicious patterns detected.