T08 · Insecure Dependencies
- Location
SKILL.md:16- Finding
Unpinned Installation and Automatic Upgrade of an Executable Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill does what it claims, but it routinely tells the agent to use browser cookies and broad shell permissions without enough user control or warning.
Review this skill before installing. Use it only if you are comfortable with an agent running yt-dlp locally, writing downloads to disk, and possibly accessing browser cookies. Prefer anonymous downloads first, require explicit approval before any cookie-based command, avoid required_permissions ["all", "network"] when narrower permissions are available, and install dependencies from a trusted, pinned environment.
SKILL.md:16Unpinned Installation and Automatic Upgrade of an Executable Dependency
SKILL.md:37Automatic Extraction of Browser Authentication Cookies for YouTube Downloads
SKILL.md:124Downloader Execution with Unrestricted Local and Network Permissions
YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).
If not installed, install them first:
```bash
pip install yt-dlp
brew install ffmpeg # macOS
yt-dlp -P "~/Downloads/yt-dlp" "VIDEO_URL"
YouTube often blocks direct downloads with 403 errors. Always use browser cookies for YouTube:
yt-dlp -P "~/Downloads/yt-dlp" --cookies-from-browser chrome "YOUTUBE_URL"
Supported browsers: chrome, firefox, safari, edge, brave, opera
yt-dlp -P "/path/to/save" -o "%(title)s.%(ext)s" "VIDEO_URL"
yt-dlp -P "~/Downloads/yt-dlp" "VIDEO_URL"
yt-dlp -P "~/Downloads/yt-dlp" -x --audio-format mp3 "VIDEO_URL"
yt-dlp -P "~/Downloads/yt-dlp" --write-subs --sub-langs all "VIDEO_URL"
The workflow combines command construction, automatic execution, broad shell permissions, and cookie-enabled download guidance into an end-to-end path that can expose sensitive browser session data during execution. In context, this is more dangerous because the skill is designed for direct agent action rather than merely informational guidance, so the risky behavior is operationalized.
The skill recommends browser cookie extraction but provides no user-facing warning that this accesses sensitive local browser data and may use authenticated sessions. Users could unknowingly authorize access to personal account state, private subscriptions, age-gated content, or other session-scoped resources.
Repeated instructions to always use browser cookies for YouTube create a natural operational pattern where the agent accesses and transmits authenticated browser state as part of routine task fulfillment. This can expose private session context and potentially download content tied to the user's account without meaningful necessity or consent.
The skill explicitly instructs use of --cookies-from-browser, which causes the agent to access locally stored browser authentication material and supply it to an external downloader process. That exceeds the minimally necessary scope of a simple media-download skill and can expose private session data or authenticated account access to remote services or logs.
The workflow tells the agent to execute downloads with Shell permissions ['all', 'network'], which is broader than needed for the stated purpose of downloading a file. Excessive execution scope increases the blast radius if the command is malformed, the URL is adversarial, or the skill is later extended with unsafe inputs.
The workflow directs automatic shell execution with broad permissions and no user warning about system-impacting behavior such as network access, file writes, and possible use of sensitive local data. This deprives the user of informed consent for actions beyond simple text assistance.
No suspicious patterns detected.