Security audit
YouTube 数据助手 SocialDataX
Security checks for vulnerabilities and agentic risk
Overview
This skill is a disclosed, read-only YouTube research helper that uses a SocialDataX API key and npm CLI package to fetch public YouTube data.
Install only if you are comfortable using SocialDataX for YouTube data lookups and allowing the agent to run npx with your SOCIALDATAX_API_KEY. The artifact is read-only, but the npm package is fetched externally at runtime, so keep normal package-source trust expectations in mind.
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Static analysis
No suspicious patterns detected.
