Dataify Youtube Video By Url

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Dataify connector that submits YouTube URL collection tasks, with token use and external requests aligned to that purpose.

Install only if you intend to submit YouTube URL tasks through Dataify. Review the parameters before approving a run, use a Dataify token with appropriate scope, and be aware that the skill may be invoked from generic video collection wording because implicit invocation is enabled.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
87% confidence
Finding
The trigger description is overly broad, including generic phrases like video collection/scraping and troubleshooting, which can cause the skill to activate for ordinary user requests that did not clearly ask to use Dataify. Misrouting to a network-capable skill increases the chance of unintended external requests or prompting users for API tokens in contexts where that is not appropriate.

Vague Triggers

Medium
Confidence
95% confidence
Finding
The manifest sets allow_implicit_invocation to true, which allows the platform to trigger this skill without an explicit user request tied to the skill name. Because this skill performs an external action—submitting Dataify YouTube scraping/collection tasks by URL and potentially using configured API credentials—over-broad invocation increases the risk of unintended task submission, surprise external data processing, or abuse through prompt steering.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal