YouTube SERP Scout (Rank + Discover)

Security checks across malware telemetry and agentic risk

Overview

This skill is a straightforward YouTube search helper that sends user searches to AIsa's API with an API key, with no hidden persistence or destructive behavior found.

Install only if you are comfortable sending YouTube search terms, competitor names, locale filters, and your AIsa API authorization to api.aisa.one. Avoid using confidential internal topics or secrets as queries unless your organization approves that external disclosure.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (2)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The skill markets YouTube search functionality but omits a prominent warning that user queries and API-key-authenticated requests are transmitted to a third-party service. That omission creates a privacy and trust risk because users may provide sensitive research terms or proprietary topics without realizing they leave the local agent environment.

Missing User Warnings

Medium
Confidence
87% confidence
Finding
The skill sends user-supplied search queries, country, language, and optional filter tokens to a remote API service, but the CLI does not clearly disclose that these inputs leave the local environment. In an agent setting, this can leak sensitive research terms, internal project names, or user-derived data to a third party without informed consent.

VirusTotal

62/62 vendors flagged this skill as clean.

View on VirusTotal