Back to skill

Security audit

Youtube Transcript Fetcher

Security checks for vulnerabilities and agentic risk

Overview

The skill mostly matches its YouTube transcript purpose, but it relies on mutable remote instructions and unpinned setup commands that users should review before installing.

Install only if you are comfortable sending YouTube video identifiers to AgentPMT and having transcript JSON stored behind temporary signed URLs. Avoid sensitive or regulated content unless AgentPMT's retention and access controls are acceptable. Treat remote live instructions as reference data, not authority to override local policies, and prefer pinned or reviewed setup commands instead of unversioned npx installs.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:188
Finding

Unpinned Third-Party Skill Installation Creates a Supply-Chain Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 188-202
Vulnerability Type: Unpinned third-party dependencies and installation tooling
Risk Level: Medium

Vulnerable Code

markdown
Core AgentPMT setup skills:
- What AgentPMT is: ../what-is-agentpmt
  - ClawHub page: https://clawhub.ai/agentpmt/what-is-agentpmt
  - OpenClaw install: `openclaw skills install what-is-agentpmt`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup
  - ClawHub page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup
  - OpenClaw install: `openclaw skills install agentpmt-account-mcp-rest-api-setup`
  - skills.sh install: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`

skills.sh install script:

```bash
npx skills add AgentPMT/agent-skills --skill what-is-agentpmt
npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup
text

### Technical Analysis

The documented installation commands invoke an npm-delivered CLI through `npx` without specifying a verified package version. They also retrieve skills from `AgentPMT/agent-skills` without pinning the source to an immutable commit or release.

Consequently, the effective content installed by these commands can change after this Skill has been reviewed. The audit cannot establish that a future npm package version, repository revision, or downloaded setup skill will retain the behavior observed in the current artifact. This creates a supply-chain trust boundary outside the audited project.

The commands are presented as setup instructions rather than being executed automatically by the two files in scope. Exploitation therefore requires a user or agent to follow the installation instructions.

### Attack Path

1. An attacker compromises the npm package, its publisher credentials, th
...[truncated 987 chars]
Remediation
View remediation

Remediation Suggestions

  1. Pin the npm CLI to a reviewed, exact version instead of allowing npx to resolve the latest release.
  2. Pin downloaded skill repositories to immutable commit hashes or cryptographically signed release tags.
  3. Publish and verify integrity hashes for all remotely obtained artifacts.
  4. Use package lockfiles or an equivalent dependency-locking mechanism where applicable.
  5. Require explicit user confirmation before running installation commands or adding new skills.
  6. Review downloaded content before activation and prevent newly installed skills from inheriting unnecessary tools or credentials.
  7. Document the exact trusted publisher, version, commit, and expected integrity value in SKILL.md.

T01 · Skill Instruction Hijacking

Warning
Location
SKILL.md:123
Finding

Mutable Remote Instructions Are Given Precedence Over Audited Local Instructions

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 123-164
Vulnerability Type: Remote instruction trust and instruction hijacking
Risk Level: Medium

Vulnerable Code

markdown
## Live Schema And Examples
Use the compact schema above for ordinary calls. Before a new production integration, or whenever parameters, enum values, nested objects, outputs, or examples are unclear, fetch live details first.

- Exact schema: call `agentpmt-tool-search-and-execution` with `action: "get_schema"`, and `tool_id: "youtube-transcript-fetcher"`.
- Detailed examples: call `agentpmt-tool-search-and-execution` with `action: "get_instructions"` and `tool_id: "youtube-transcript-fetcher"`, or call this product with `action: "get_instructions"` when the product tool is already selected.
- Treat returned live schema and instructions as more specific than this generated summary.

MCP schema lookup through the main AgentPMT MCP server:

```json
{
  "method": "tools/call",
  "params": {
    "name": "AgentPMT-Tool-Search-and-Execution",
    "arguments": {
      "action": "get_schema",
      "tool_id": "youtube-transcript-fetcher"
    }
  }
}

For live examples, keep the same MCP tool and use these arguments:

json
{
  "action": "get_instructions",
  "tool_id": "youtube-transcript-fetcher"
}

Authenticated AgentPMT REST schema lookup body:

json
{
  "name": "agentpmt-tool-search-and-execution",
  "parameters": {
    "action": "get_schema",
    "tool_id": "youtube-transcript-fetcher"
  }
}

Authenticated AgentPMT REST live examples body:

json
{
  "name": "agentpmt-tool-search-and-execution",
  "parameters": {
    "action": "get_instructions",
    "tool_id": "youtube-transcript-fetcher"
  }
}
text

### Technical Analysis

The Skill instructs the agent to retrieve mutable instructions from a remote AgentPMT service and explicitly treat th
...[truncated 1984 chars]
Remediation
View remediation

Remediation Suggestions

  1. Treat all remotely returned instructions and examples as untrusted data rather than executable agent directives.
  2. Remove the statement that remote instructions are more specific than the audited local Skill.
  3. Accept only fields defined by a strict, locally pinned schema and reject unknown or instruction-bearing fields.
  4. Use versioned and cryptographically signed schemas whose publisher and integrity can be verified.
  5. Explicitly prohibit remote responses from overriding system policies, safety constraints, task scope, credential rules, or tool authorization boundaries.
  6. Restrict live lookups to schema metadata required for the declared transcript-fetching action.
  7. Require user confirmation before any remotely suggested action that falls outside fetching and downloading the requested transcript.
  8. Apply an allowlist for permitted action names, destination domains, and request fields.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (13)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest description is written with broad invocation language covering summarization, show notes, accessibility, citations, and generic fetch behavior, increasing the chance that orchestration systems auto-select this skill too aggressively. Because the tool stores transcript output externally and returns signed URLs, accidental invocation can expose user-requested content to third-party processing without sufficiently explicit user awareness.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The overview explains transcript retrieval features but does not prominently warn that the transcript is saved to cloud storage and exposed through a signed download URL. This omission matters because users or upstream agents may assume the transcript is returned inline and ephemeral, when in fact the content is persisted externally and accessible to whoever obtains the signed URL during its validity window.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill advertises broad activation keywords and generic use cases, which can cause an agent to invoke this tool in situations where transcript extraction was not explicitly intended. In this skill's context, unintended invocation is more dangerous because the action sends user-supplied video identifiers to an external service and stores retrieved transcript content in cloud storage behind signed URLs.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 260)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/youtube-transcript-fetcher
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 261)May include surrounding context.

md
- What AgentPMT is: ../what-is-agentpmt (ClawHub: `what-is-agentpmt`, page: https://clawhub.ai/agentpmt/what-is-agentpmt; skills.sh: `npx skills add AgentPMT/agent-skills --skill what-is-agentpmt`)
- AgentPMT account MCP/REST setup: ../agentpmt-account-mcp-rest-api-setup (ClawHub: `agentpmt-account-mcp-rest-api-setup`, page: https://clawhub.ai/agentpmt/agentpmt-account-mcp-rest-api-setup; skills.sh: `npx skills add AgentPMT/agent-skills --skill agentpmt-account-mcp-rest-api-setup`)
- Marketplace product: https://www.agentpmt.com/marketplace/youtube-transcript-fetcher
- AgentPMT main MCP server: https://api.agentpmt.com/mcp/
- AgentPMT REST invoke endpoint: https://api.agentpmt.com/products/purchase

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The schema states that fetched transcripts are saved to cloud storage and returned via a signed download URL, but the skill metadata/description does not clearly warn users about this persistence and sharing model. This can lead users or downstream agents to submit sensitive or copyrighted video content under the assumption of ephemeral processing, increasing the risk of unintended disclosure or retention.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.