Back to skill

Security audit

Youtube Script

Security checks for vulnerabilities and agentic risk

Overview

This skill appears to be a local YouTube-content logging tool, but it is marketed as a content-generation toolkit and stores/export users' raw drafts in ways that deserve review before installing.

Review this before installing if you may paste unpublished scripts, client work, schedules, marketing plans, or secrets. It keeps local plaintext history and can export everything it has stored; use it only if that retention is intended, and consider tightening file permissions or avoiding sensitive input until deletion, retention, and safer export behavior are added.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:6
Finding

Stored Content May Be Readable by Other Local Users

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh:6-8
Vulnerability Type: Insecure file permissions for locally stored user content
Risk Level: Medium

bash
DATA_DIR="${HOME}/.local/share/youtube-script"
mkdir -p "$DATA_DIR"

_log() { echo "$(date '+%m-%d %H:%M') $1: $2" >> "$DATA_DIR/history.log"; }

Content handlers also append the complete user-supplied input to operation-specific log files. For example, the draft handler at scripts/script.sh:141-153 contains:

bash
draft)
    shift
    if [ $# -eq 0 ]; then
        echo "Recent draft entries:"
        tail -20 "$DATA_DIR/draft.log" 2>/dev/null || echo "  No entries yet. Use: youtube-script draft <input>"
    else
        local input="$*"
        local ts=$(date '+%Y-%m-%d %H:%M')
        echo "$ts|$input" >> "$DATA_DIR/draft.log"
        local total=$(wc -l < "$DATA_DIR/draft.log")
        echo "  [Youtube Script] draft: $input"
        echo "  Saved. Total draft entries: $total"
        _log "draft" "$input"
    fi
    ;;

Technical Analysis

The script creates its data directory and log files without setting a restrictive umask or explicitly applying secure permission modes. Their effective permissions therefore depend on the invoking process's environment.

With a common umask of 022, mkdir can create the directory as mode 0755, while shell redirection can create log files as mode 0644. Other local users may consequently be able to traverse the directory and read unpublished scripts, schedules, translations, headlines, and activity records.

The same input is written both to an operation-specific file and to history.log, increasing the number of locations from which content could be disclosed. This is particularly relevant because the Skill accepts arbitrary user-authored content that may contain confidential business or publication information.

Attack Path

  1. A user invokes a co ...[truncated 1208 chars]
Remediation
View remediation

Remediation Suggestions

  • Set a restrictive process mask before creating any data:
    bash
    umask 077
    
  • Create and verify the data directory with owner-only access:
    bash
    mkdir -p -- "$DATA_DIR"
    chmod 700 -- "$DATA_DIR"
    
  • Create log and export files with mode 0600, and validate that existing files are regular files owned by the current user before appending to them.
  • Avoid duplicating complete user content in history.log. Store only minimal metadata, such as the operation type and timestamp.
  • Provide a migration step that changes existing directories to mode 0700 and existing data files to mode 0600.
  • Document that supplied content is persisted locally and provide a secure deletion or history-clearing command.

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/script.sh:54
Finding

Unescaped Export Fields Permit JSON Corruption and CSV Formula Injection

Content
View full analysis

Vulnerability Details

File Location: scripts/script.sh:54-82
Vulnerability Type: Improper output encoding in JSON and CSV exports
Risk Level: Medium

bash
_export() {
    local fmt="${1:-json}"
    local out="$DATA_DIR/export.$fmt"
    case "$fmt" in
        json)
            echo "[" > "$out"
            local first=1
            for f in "$DATA_DIR"/*.log; do
                [ -f "$f" ] || continue
                local name=$(basename "$f" .log)
                while IFS='|' read -r ts val; do
                    [ $first -eq 1 ] && first=0 || echo "," >> "$out"
                    printf '  {"type":"%s","time":"%s","value":"%s"}' "$name" "$ts" "$val" >> "$out"
                done < "$f"
            done
            echo "" >> "$out"
            echo "]" >> "$out"
            ;;
        csv)
            echo "type,time,value" > "$out"
            for f in "$DATA_DIR"/*.log; do
                [ -f "$f" ] || continue
                local name=$(basename "$f" .log)
                while IFS='|' read -r ts val; do
                    echo "$name,$ts,$val" >> "$out"
                done < "$f"
            done
            ;;

Technical Analysis

User-controlled log values are interpolated directly into structured output without format-specific encoding.

For JSON exports, quotes, backslashes, tabs, carriage returns, and other control characters are not JSON-escaped. A value containing a double quote can terminate the intended string and inject additional JSON properties or records. Even where no malicious downstream behavior occurs, ordinary quoted or multiline content can produce invalid JSON.

For CSV exports, values are not enclosed in quotes and embedded quotes, commas, carriage returns, or newlines are not escaped according to CSV conventions. In addition, values beginning with spreadsheet formula indicators such as =, +, -, or @ are written unchan ...[truncated 2002 chars]

Remediation
View remediation

Remediation Suggestions

  • Generate JSON through a serializer that correctly escapes every field rather than constructing JSON with printf.
  • If an external JSON utility is not permitted, implement and thoroughly test escaping for quotation marks, backslashes, and all control characters.
  • Produce RFC 4180-compatible CSV by enclosing fields in double quotes and replacing every embedded double quote with two double quotes.
  • Neutralize spreadsheet formulas when exports are intended for spreadsheet use. Prefix fields beginning with =, +, -, @, tab, or carriage return with a safe text marker, and document this behavior.
  • Keep a separate strict CSV mode if preservation of exact raw data is necessary, and warn users not to open untrusted exports in formula-evaluating software.
  • Add tests covering commas, quotation marks, backslashes, pipes, multiline values, control characters, Unicode content, and formula-prefixed values.
  • Validate generated JSON with a standards-compliant parser and test CSV output with multiple compatible readers before release.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The manifest and description present this as a content-writing helper, but the documented behavior also includes persistent logging, export, search, scheduling, and activity tracking that materially change the data-handling and privacy profile of the skill. This mismatch can mislead users into providing sensitive draft content without realizing it will be retained and exportable, increasing risk of unintended disclosure even if no overtly malicious behavior is shown.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill explicitly states that all content operations are logged with timestamps, which means user-provided scripts, ideas, hooks, and related content may be retained by default. Because creative drafts can contain unpublished, proprietary, or sensitive material, default logging expands the exposure surface and can lead to accidental disclosure through later access, export, or local compromise.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented storage model keeps detailed per-command logs, a master history log, and export files under a local path, creating multiple plain-text copies of user content and activity. This broad retention makes sensitive drafts easier to enumerate, search, and exfiltrate by other local users, malware, backups, or accidental sharing, especially since export functionality further concentrates the data.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The manifest promises capabilities like script writing, title A/B testing, thumbnail copy, SEO optimization, hooks, and chapter markers. In practice, the script does not generate or transform content; it creates a local data directory, appends raw user input to per-command log files, and exports those logs in JSON/CSV/TXT formats. This is a broader logging/archive utility rather than the claimed content-writing functionality.

Content

No source excerpt is available for this finding.

Ssd 3

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The script stores all user inputs and exposes bulk search, recent-history, status, and export capabilities, making accumulated natural-language data easy to retrieve and exfiltrate if the local account or filesystem is accessed. In the context of a writing assistant, the stored text may contain unpublished content, business plans, client material, or secrets that users casually pasted into the tool.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The export function aggregates all historical log contents into JSON, CSV, or TXT files without warning that prior sensitive entries will be materialized into a portable file. This increases the chance of accidental sharing, backup propagation, or exposure of old data that users may not realize is being included.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

User-provided content is silently persisted to ~/.local/share/youtube-script/*.log with no clear consent, retention notice, or sensitivity warning. For a content-writing skill, users may paste drafts, unpublished titles, sponsorship notes, credentials, or other confidential text, creating an avoidable privacy and disclosure risk on shared or compromised systems.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The closest implemented feature is headline, which merely appends input to headline.log; there is no comparison, scoring, variant handling, or A/B evaluation. Likewise, no command or logic specifically handles thumbnail copy beyond generic text logging, so the advertised optimization capabilities are not reflected in code behavior.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
82% confidence
Finding

The manifest description begins in Chinese and presents the skill as Chinese-language by default, while the rest of the file is largely in English. This creates a language/locale policy concern because the skill does not explicitly offer users a language choice or explain why a Chinese default is required.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
92% confidence
Finding

A scheduling feature in a YouTube content skill would reasonably imply calendaring, publication timing, or at least structured plan management. Here, the schedule command simply writes the provided input to schedule.log and records it in history without performing any scheduling action or validation.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.