Back to skill

Security audit

tube-summary

Security checks for vulnerabilities and agentic risk

Overview

This skill does what it says: it searches YouTube, downloads subtitle files, and summarizes them, with only ordinary dependency and local-file cautions.

Install dependencies in a dedicated virtual environment, consider pinning yt-dlp and requests, and run the subtitle download from a directory where creating temporary .vtt files is acceptable. The skill does contact YouTube and stores subtitle text locally for processing.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:52
Finding

Unpinned Third-Party Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:52
Vulnerability Type: Unpinned and unverified third-party dependency
Risk Level: Medium

Vulnerable Code

markdown
## Prerequisites

- `yt-dlp` (install: `pip install yt-dlp`)
- `requests` (for YouTube search fallback)
- Python 3.7+

Technical Analysis

The documented installation command retrieves the latest available yt-dlp package from the active pip package index without specifying a reviewed version, verifying cryptographic hashes, or using a locked dependency set. Package versions and their transitive dependencies can therefore change after the Skill has been audited.

Python package installation may execute package build or installation logic. Consequently, compromise of the configured package index, the upstream package, or a transitive dependency could turn this prerequisite command into a code-execution path. An unexpected future release could also introduce incompatible or vulnerable behavior.

No evidence was found that the project intentionally uses a typosquatted package or a known malicious dependency. The risk arises from mutable, unverified dependency resolution.

Attack Path

  1. An attacker compromises the upstream package, a transitive dependency, or the package source configured for pip.
  2. The attacker publishes a malicious version that remains eligible for unrestricted dependency resolution.
  3. A user follows the documented prerequisite and runs pip install yt-dlp.
  4. Pip downloads and installs the attacker-controlled artifact without a required version or hash check.
  5. Malicious build or installation logic executes with the privileges of the user running pip.
  6. The installed package may execute again when scripts/youtube-search.py invokes the yt-dlp executable.

Impact Assessment

Successful exploitation could provide arbitrary code execution with the privileges of the user performing the installati ...[truncated 560 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin yt-dlp and every other runtime dependency to reviewed versions in a dependency manifest.
  2. Generate and require cryptographic hashes for all resolved artifacts, for example:
    bash
    python3 -m pip install --require-hashes -r requirements.txt
    
  3. Use a lock-generation workflow that records and reviews transitive dependencies.
  4. Install dependencies inside a dedicated virtual environment rather than into a system Python environment.
  5. Explicitly configure and document the trusted package index; avoid untrusted extra indexes.
  6. Update dependencies through a controlled process that includes provenance checks, vulnerability scanning, and functional review.
  7. Add the imported beautifulsoup4 package to the locked dependency set if the web-scraping fallback remains supported.
Vulnerability Patterns
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/youtube-search.py (reported line 27)May include surrounding context.

python
'--dump-json',
            '--flat-playlist'
        ]
        result = subprocess.run(cmd, capture_output=True, text=True, timeout=30)
        
        if result.returncode == 0:
            videos = []

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The instructions tell the operator to run yt-dlp in a way that writes a subtitle file to local disk, but they do not clearly warn about this side effect before execution. This can lead to unintended local data creation, clutter, or storage of potentially sensitive/transient content in the current working directory, especially in automated or shared environments.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.