Back to skill

Security audit

YouTube

Security checks for vulnerabilities and agentic risk

Overview

This YouTube skill is a clearly documented Maton API integration with disclosed OAuth, write-operation, and automation risks guarded by user-approval instructions.

Before installing, understand that this skill can act on your connected YouTube account and can create persistent Maton automations if you approve them. Use the read/list flows first, confirm the exact account and resource before writes, and avoid raw API-key mode unless the CLI cannot be used.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

This markdown file includes a write example that sets "defaultLanguage": "en" in the playlist creation payload. Although the surrounding text notes that the value is illustrative, the example still defaults to a specific language/locale, which can conflict with the policy against forcing a language without user opt-in.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.