Back to skill

Security audit

Yt Dlp Downloader

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it routinely tells the agent to use browser cookies and broad shell permissions without enough user control or warning.

Review this skill before installing. Use it only if you are comfortable with an agent running yt-dlp locally, writing downloads to disk, and possibly accessing browser cookies. Prefer anonymous downloads first, require explicit approval before any cookie-based command, avoid required_permissions ["all", "network"] when narrower permissions are available, and install dependencies from a trusted, pinned environment.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:16
Finding

Unpinned Installation and Automatic Upgrade of an Executable Dependency

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:37
Finding

Automatic Extraction of Browser Authentication Cookies for YouTube Downloads

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Error
Location
SKILL.md:124
Finding

Downloader Execution with Unrestricted Local and Network Permissions

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • YARA SignaturesMalware Match, Webshell Match, Cryptominer Match
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (7)

YARA rule 'info_stealer': Information stealer patterns (credential harvesting, browser data theft) [malware]

High
Category
YARA Match
Confidence
75% confidence
Finding

YARA rule matched a known malware signature (reverse shell, backdoor, ransomware, C2 framework, or info stealer).

Content

Scanner excerpt · SKILL.md (reported line 41)May include surrounding context.

text

If not installed, install them first:
```bash
pip install yt-dlp
brew install ffmpeg  # macOS

Quick Start

Basic Download (Best Quality)

bash
yt-dlp -P "~/Downloads/yt-dlp" "VIDEO_URL"

YouTube Download (Recommended - with cookies)

YouTube often blocks direct downloads with 403 errors. Always use browser cookies for YouTube:

bash
yt-dlp -P "~/Downloads/yt-dlp" --cookies-from-browser chrome "YOUTUBE_URL"

Supported browsers: chrome, firefox, safari, edge, brave, opera

Download with Custom Output Path

bash
yt-dlp -P "/path/to/save" -o "%(title)s.%(ext)s" "VIDEO_URL"

Common Tasks

1. Download Video (Default - Best Quality)

bash
yt-dlp -P "~/Downloads/yt-dlp" "VIDEO_URL"

2. Extract Audio Only (MP3)

bash
yt-dlp -P "~/Downloads/yt-dlp" -x --audio-format mp3 "VIDEO_URL"

3. Download with Subtitles

bash
yt-dlp -P "~/Downloads/yt-dlp" --write-subs --sub-langs all "VIDEO_URL"

4. Download

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The workflow combines command construction, automatic execution, broad shell permissions, and cookie-enabled download guidance into an end-to-end path that can expose sensitive browser session data during execution. In context, this is more dangerous because the skill is designed for direct agent action rather than merely informational guidance, so the risky behavior is operationalized.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill recommends browser cookie extraction but provides no user-facing warning that this accesses sensitive local browser data and may use authenticated sessions. Users could unknowingly authorize access to personal account state, private subscriptions, age-gated content, or other session-scoped resources.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

Repeated instructions to always use browser cookies for YouTube create a natural operational pattern where the agent accesses and transmits authenticated browser state as part of routine task fulfillment. This can expose private session context and potentially download content tied to the user's account without meaningful necessity or consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill explicitly instructs use of --cookies-from-browser, which causes the agent to access locally stored browser authentication material and supply it to an external downloader process. That exceeds the minimally necessary scope of a simple media-download skill and can expose private session data or authenticated account access to remote services or logs.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

The workflow tells the agent to execute downloads with Shell permissions ['all', 'network'], which is broader than needed for the stated purpose of downloading a file. Excessive execution scope increases the blast radius if the command is malformed, the URL is adversarial, or the skill is later extended with unsafe inputs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The workflow directs automatic shell execution with broad permissions and no user warning about system-impacting behavior such as network access, file writes, and possible use of sensitive local data. This deprives the user of informed consent for actions beyond simple text assistance.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.