Back to skill

Security audit

youtube-video-api-skill

Security checks for vulnerabilities and agentic risk

Overview

The skill performs the advertised YouTube data extraction through BrowserAct, but it asks users to provide an API key through the agent conversation if the environment variable is missing.

Review before installing. Use this only if you are comfortable sending the target YouTube channel URL and selected video type to BrowserAct. Do not paste your BrowserAct API key into the agent conversation; configure it through BROWSERACT_API_KEY or a protected secret mechanism instead, and rotate any key previously shared in chat.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Warning
Location
SKILL.md:26
Finding

API Key Disclosure Through Agent Conversation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:26-29 and scripts/youtube_video_api.py:87-90
Vulnerability Type: Unsafe credential handling and potential plaintext secret exposure
Risk Level: Medium

Vulnerable Code and Instructions

SKILL.md:26-29:

markdown
Before running, you must check the `BROWSERACT_API_KEY` environment variable. If it is not set, do not take any other actions first. You should request and wait for the user to provide it collaboratively.
**The Agent must inform the user at this time**:
> "Since you have not configured the BrowserAct API Key yet, please go to the [BrowserAct Console](https://www.browseract.com/reception/integrations) first to get your Key."

scripts/youtube_video_api.py:87-90:

python
print("\n[!] ERROR: BrowserAct API Key is missing.", flush=True)
print("Please follow these steps:", flush=True)
print("1. Go to: https://www.browseract.com/reception/integrations", flush=True)
print("2. Copy your API Key.", flush=True)
print("3. Provide it to me or set it as an environment variable (BROWSERACT_API_KEY).", flush=True)

Technical Analysis

The Skill explicitly instructs the Agent to request and wait for the user to provide a BrowserAct API key. The script repeats that the key may be provided “to me.” This encourages users to submit a reusable authentication secret through an Agent conversation.

Secrets entered into a conversation may be retained in chat transcripts, telemetry, debugging traces, orchestration logs, or other records accessible to parties who do not require the credential. Conversational submission is unnecessary because the script already supports reading the key from the BROWSERACT_API_KEY environment variable.

The script subsequently transmits the key as a Bearer token to the fixed HTTPS endpoint https://api.browseract.com/v2/workflow. Sending the credential to BrowserAct is consistent with the declared API-backed func ...[truncated 1625 chars]

Remediation
View remediation

Remediation Suggestions

  1. Remove all instructions asking users to provide API keys directly to the Agent or through chat.
  2. Require the key to be configured locally through BROWSERACT_API_KEY, an approved secret manager, or the execution platform's protected secret-injection facility.
  3. Replace the current guidance with an explicit warning such as: “Do not paste the API key into this conversation. Configure it as the BROWSERACT_API_KEY secret in your execution environment.”
  4. Change the script message at scripts/youtube_video_api.py:90 so that it only recommends protected environment or secret-manager configuration.
  5. Ensure conversation logs, command output, exceptions, and telemetry never include the credential or the complete Authorization header.
  6. Use a narrowly scoped API key when BrowserAct supports scoped credentials, and apply quota or spending limits where available.
  7. Rotate any key that has previously been submitted through a conversation or stored in an untrusted log.
  8. Consider validating that the environment variable is present without printing its value, then pass it only in the HTTPS authorization header as the script currently does.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
92% confidence
Finding

The skill declares access to environment variables and implicitly uses an external API, but it does not define an explicit tool scope or permissions boundary. That makes the skill's runtime capabilities less transparent to the agent and user, increasing the risk of unintended secret access or outbound requests without clear policy constraints.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The description instructs the agent to proactively apply the skill across a wide range of loosely related research, monitoring, and analytics requests. This broad trigger language can cause the skill to run without a clearly bounded user intent, leading to unnecessary external API calls and unintended disclosure of user-provided targets or research activity to a third party.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill does not clearly warn users that the provided YouTube channel URL and request parameters are transmitted to BrowserAct, a third-party external API. This weakens informed consent and can expose user interests, competitor-monitoring targets, or operational research data to an outside service without an explicit disclosure step.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/youtube_video_api.py (reported line 15)May include surrounding context.

python
# API Configuration
TEMPLATE_ID = "82163578680973165"
API_BASE_URL = "https://api.browseract.com/v2/workflow"

def run_youtube_video_task(api_key, channel_url, video_type="Popular"):
    headers = {"Authorization": f"Bearer {api_key}"}

External Transmission

Medium
Category
Data Exfiltration
Confidence
80% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · scripts/youtube_video_api.py (reported line 30)May include surrounding context.

python
# 1. Start Task
    print(f"Start Task", flush=True)
    try:
        res = requests.post(f"{API_BASE_URL}/run-task-by-template", json=payload, headers=headers).json()
    except Exception as e:
        print(f"Error: Connection to API failed - {e}", flush=True)
        return None

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

This code reads a sensitive credential from the BROWSERACT_API_KEY environment variable. While the script prints usage and error messages, it does not disclose that it will access a credential from the environment or provide any warning about secure handling of that secret.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.