Back to skill

Security audit

Dataify YouTube Video Post

Security checks across malware telemetry and agentic risk

Overview

This skill submits user-chosen YouTube collection jobs to Dataify using a Dataify API token, and its network/token behavior is disclosed and purpose-aligned.

Use this skill only if you intend to submit YouTube collection tasks to Dataify. Review the selected mode and parameters before running, and treat DATAIFY_API_TOKEN like a credential because it will be sent to Dataify for Builder requests.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (2)

Lp3

Medium
Category
MCP Least Privilege
Confidence
94% confidence
Finding
The skill instructs the agent to read a locally saved API token from the environment and submit network requests, but no explicit permission declaration or trust boundary is documented. Hidden access to environment secrets plus outbound network use increases the risk of unintended secret exposure, unauthorized API use, and makes review harder because the capability is implicit rather than declared.

Vague Triggers

Medium
Confidence
89% confidence
Finding
The skill enables implicit invocation while its activation scope is broad and based on many generic phrases like YouTube scraping, URLs, keywords, hashtags, and troubleshooting requests. This increases the chance the agent auto-selects and executes the skill in contexts the user did not explicitly intend, which can trigger external data-collection actions or task submission to Dataify without sufficiently clear confirmation.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.