Back to skill

Security audit

youtube

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly a YouTube research helper, but it asks users to install mutable third-party tools and can send full transcripts to an external LLM service without clear privacy warnings.

Review before installing. Use this only if you trust SkillBoss API Hub, the YouTube MCP server package, yt-dlp, and their dependency chains. Avoid using the LLM analysis example on private, confidential, or sensitive transcripts unless you explicitly intend to send that text to SkillBoss. Prefer pinned versions, a virtual environment or container, and a project-local install instead of global package installation.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:23
Finding

Execution of Unpinned and Mutable Third-Party Dependencies

Content
View full analysis
Remediation
View remediation

other

Warning
Location
SKILL.md:129
Finding

Full Transcript Disclosure to a Third-Party LLM Service Without Explicit Consent or Data Minimization

Content
View full analysis
dict: r = requests.post( f"{API_BASE}/pilot", headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"}, json=body, timeout=60, ) return r.json() # Analyze transcript content transcript_text = open("/tmp/VIDEO_ID.en.vtt").read() result = pilot({ "type": "chat", "inputs": { "messages": [ {"role": "user", "content": f"Summarize the key points from this transcript:\n\n{transcript_text}"} ] }, "prefer": "balanced" }) summary = result["result"]["choices"][0]["message"]["content"] print(summary) ``` ### Technical Analysis The documented workflow reads the complete transcript from local storage and places it into a request sent to `https://api.skillbossai.com/v1/pilot`. The bearer API key is also sent to that service as intended authentication. Remote LLM analysis is optional and is not required for the Skill’s core YouTube search, metadata retrieval, or transcript-extraction functionality. However, the workflow does not: - Require explicit user approval before transmitting transcript content. - Distinguish public transcripts from private, unlisted, confidential, or user-supplied material. - Redact personally identifiable or confidential information. - Minimize the transmitted content to only the portions required for analysis. - Explain the third party’s retention, logging, training, or deletion practices. - Offer a local analysis mode for sensitive material. The API request is visible in the documentation rather than concealed, and no evidence indicates that the key is trans ...[truncated 1608 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (9)

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The documented fallback commands hard-code --sub-lang en, which imposes English as the transcript language. The file does not offer a language choice or explain that the skill is intentionally limited to English-only use, so this is a natural-language locale policy concern.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The transcript analysis example reads transcript text from disk and sends it to an external API without clearly warning the user that potentially sensitive transcript content leaves the local environment. This creates a data disclosure risk, especially when transcripts may contain private, copyrighted, or regulated information gathered during research workflows.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 139)May include surrounding context.

md
import requests, os

SKILLBOSS_API_KEY = os.environ["SKILLBOSS_API_KEY"]
API_BASE = "https://api.skillbossai.com/v1"

def pilot(body: dict) -> dict:
    r = requests.post(

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 318)May include surrounding context.

md
import requests, os

SKILLBOSS_API_KEY = os.environ["SKILLBOSS_API_KEY"]
API_BASE = "https://api.skillbossai.com/v1"

def pilot(body: dict) -> dict:
    r = requests.post(

External Transmission

Medium
Category
Data Exfiltration
Confidence
96% confidence
Finding

The example performs an authenticated POST request to an external API containing user-supplied transcript content. External transmission is expected for an API client, but it becomes security-relevant here because the documentation does not adequately frame the privacy implications or obtain explicit consent before sending possibly sensitive text off-host.

Content

Scanner excerpt · SKILL.md (reported line 142)May include surrounding context.

md
API_BASE = "https://api.skillbossai.com/v1"

def pilot(body: dict) -> dict:
    r = requests.post(
        f"{API_BASE}/pilot",
        headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
        json=body,

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

This workflow repeats the use of --sub-lang en for transcript retrieval, again constraining the skill to English in the user-facing instructions. Because no opt-in, alternative language path, or justification is provided, the locale restriction remains a policy violation.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The security note claims that all network calls are routed via SkillBoss API Hub, but the skill also instructs users to clone from GitHub and retrieve content directly from YouTube. This inaccurate assurance can mislead users about the actual trust boundary, causing them to expose data or rely on controls that do not apply to those direct third-party connections.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The skill manifest description says the skill can search YouTube videos, get channel info, and fetch video details and transcripts. The README's feature list adds 'Playlist Info', which is a meaningful user-facing capability beyond the manifest's described scope.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The manifest describes a YouTube-focused skill for searching videos, channel info, video details, and transcripts using SkillBoss API Hub or yt-dlp fallback. This section adds a separate capability: sending transcript contents to a general-purpose chat endpoint for summarization/analysis, which goes beyond retrieval and into LLM content analysis not stated in the manifest description.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.