Back to skill

Security audit

YouTube API

Security checks across malware telemetry and agentic risk

Overview

This skill is not malware, but it exposes broad YouTube account-changing powers that are only partly disclosed and should be reviewed before installation.

Install only if you intend to let an agent prepare requests for a connected YouTube account with write, upload, moderation, and administration capabilities. Keep the MyBrandMetrics key scoped as narrowly as possible, require explicit confirmation for every upload/update/delete/moderation/live/branding/account-linking action, and avoid using this as a read-only YouTube analytics skill unless the high-impact endpoints are disabled or separated.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (15)

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The skill is described as a data-retrieval and analytics capability, but the catalog exposes broad write, delete, upload, moderation, and account-management operations across YouTube resources. This creates a dangerous mismatch between user/operator expectations and actual authority, increasing the chance that an agent invokes high-impact actions under the guise of a read-oriented skill.

Description-Behavior Mismatch

Medium
Confidence
96% confidence
Finding
The manifest frames playlist functionality as browsing, but the catalog also allows creating, modifying, and deleting playlists and playlist items. That mismatch can lead agents or users to unknowingly grant or use capabilities that alter account state rather than merely inspect it.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The manifest says the skill can list comments, but the catalog includes comment and comment-thread creation, editing, deletion, spam marking, and moderation status changes. In a social/community context, these operations can directly manipulate public communications and moderation outcomes, making the understatement especially risky.

Description-Behavior Mismatch

High
Confidence
98% confidence
Finding
The manifest says the skill can check live broadcasts, but the catalog permits creating, binding, transitioning, updating, and deleting live broadcasts as well as controlling live chat moderation. Because live operations affect active events and audience interaction in real time, the gap between stated and actual authority materially raises operational risk.

Context-Inappropriate Capability

High
Confidence
97% confidence
Finding
The catalog exposes subscriptions, ratings, abuse reporting, spam/moderation actions, uploads, and other account/community-management features that are not justified by the stated YouTube data and analytics purpose. This unnecessary expansion of privilege increases the blast radius of prompt mistakes, abuse, or compromised agent behavior.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
The manifest promises analytics querying, but the catalog also includes YouTube Analytics group and group-item create/update/delete operations. These mutation APIs are broader than necessary for reporting and can change analytics organization state, which is unjustified for a query-focused skill.

Context-Inappropriate Capability

Medium
Confidence
83% confidence
Finding
The presence of opaque or poorly justified capabilities such as test endpoints and video trainability lookup broadens the attack surface without clear alignment to the stated user purpose. While not inherently destructive on their own, undocumented or unexplained endpoints create uncertainty and may expose unintended behaviors or sensitive metadata.

Description-Behavior Mismatch

High
Confidence
96% confidence
Finding
The documented interface exposes a very broad set of write-capable and destructive operations far beyond a simple 'YouTube data needed' framing. That mismatch increases the chance an agent or user will invoke high-risk mutations such as deleting videos, changing moderation state, or altering channel assets under the assumption the skill is primarily read-oriented.

Context-Inappropriate Capability

Medium
Confidence
93% confidence
Finding
The skill includes moderation primitives such as banning users, deleting chat messages, and adding/removing moderators, which are materially different from ordinary data retrieval. In an agent setting, these actions can directly impact community management and can be abused to censor, lock out participants, or alter moderation state without sufficient expectation-setting.

Context-Inappropriate Capability

Medium
Confidence
94% confidence
Finding
Content publishing and branding mutation capabilities such as video upload, thumbnail changes, banner updates, and watermark management are inconsistent with a data/analytics-oriented description. This increases the risk of unauthorized publishing, brand defacement, or reputational damage if an agent is granted this skill under the assumption it is informational only.

Context-Inappropriate Capability

Medium
Confidence
91% confidence
Finding
Third-party account linking operations are outside the expected YouTube data and analytics use case and can create durable cross-account relationships. If misused, they could connect external commerce or platform accounts to channels, changing ownership or business integrations in ways that are hard to detect and reverse.

Vague Triggers

Medium
Confidence
94% confidence
Finding
The catalog lists destructive and high-impact operations alongside read-only ones without specifying invocation constraints, exclusions, or approval triggers. In an agent setting, that ambiguity is dangerous because the model may select a harmful method when a benign read operation was intended.

Missing User Warnings

Medium
Confidence
88% confidence
Finding
The documentation shows API key usage in curl commands without any warning about protecting secrets from shell history, terminal logs, process listings, or accidental copy/paste into shared environments. While the examples are instructional rather than malicious, they normalize direct secret handling in ways that can lead to credential disclosure and unauthorized API use.

Missing User Warnings

Medium
Confidence
82% confidence
Finding
The documentation exposes destructive DELETE operations for group items and groups without any warning, confirmation guidance, or mention of irreversible effects. In an agent setting, this increases the chance that an LLM or user invokes deletion actions casually or with incomplete understanding, causing unauthorized or unintended data removal.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The documentation presents many destructive and state-changing examples alongside benign reads without warnings about irreversible effects or required safeguards. In an agent workflow, that normalization increases the chance of accidental destructive calls because there is no friction, caution, or confirmation guidance around delete/update/insert operations.

VirusTotal

56/56 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.