YouTube SERP Scout

Security checks across malware telemetry and agentic risk

Overview

This is a straightforward YouTube research helper that sends user search terms to AIsa using the user's API key.

Install only if you are comfortable sending YouTube research queries, competitor names, locale parameters, and related request metadata to AIsa under your AISA_API_KEY. Use a dedicated API key when possible, and avoid submitting confidential strategy terms, secrets, or personal data unless AIsa is approved for that data.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The documentation instructs users to send search queries to api.aisa.one using a bearer token but does not clearly disclose that user-provided prompts, search terms, and related metadata will be transmitted to a third-party service. In an agent setting, users may assume searches are local or first-party, causing unintentional sharing of potentially sensitive research terms or business intelligence.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal