Back to skill

Security audit

Youtube Scrapper

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed YouTube scraping guide with proxy support; its main risk is that it handles proxy credentials and encourages anti-detection scraping, but there is no hidden code, persistence, or exfiltration in the artifact.

Before installing, treat proxy credentials as secrets and avoid committing them or pasting them into shared logs. Also confirm that your scraping use complies with YouTube's terms and applicable laws, especially because the skill explicitly describes anti-detection techniques and residential proxy use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
88% confidence
Finding
This markdown file instructs users to set `PROXY_USERNAME` and `PROXY_PASSWORD`, which are sensitive credentials, but it does not include any caution about secure storage, shell history exposure, or avoiding accidental disclosure. Under SQP-2 for markdown files, credential-handling behavior that can affect privacy or system integrity should be accompanied by a user warning.

Static analysis

No suspicious patterns detected.