T08 · Insecure Dependencies
- Location
SKILL.md:23- Finding
Execution of Unpinned and Mutable Third-Party Dependencies
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly a YouTube research helper, but it asks users to install mutable third-party tools and can send full transcripts to an external LLM service without clear privacy warnings.
Review before installing. Use this only if you trust SkillBoss API Hub, the YouTube MCP server package, yt-dlp, and their dependency chains. Avoid using the LLM analysis example on private, confidential, or sensitive transcripts unless you explicitly intend to send that text to SkillBoss. Prefer pinned versions, a virtual environment or container, and a project-local install instead of global package installation.
SKILL.md:23Execution of Unpinned and Mutable Third-Party Dependencies
SKILL.md:129Full Transcript Disclosure to a Third-Party LLM Service Without Explicit Consent or Data Minimization
The documented fallback commands hard-code --sub-lang en, which imposes English as the transcript language. The file does not offer a language choice or explain that the skill is intentionally limited to English-only use, so this is a natural-language locale policy concern.
The transcript analysis example reads transcript text from disk and sends it to an external API without clearly warning the user that potentially sensitive transcript content leaves the local environment. This creates a data disclosure risk, especially when transcripts may contain private, copyrighted, or regulated information gathered during research workflows.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import requests, os
SKILLBOSS_API_KEY = os.environ["SKILLBOSS_API_KEY"]
API_BASE = "https://api.skillbossai.com/v1"
def pilot(body: dict) -> dict:
r = requests.post(
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
import requests, os
SKILLBOSS_API_KEY = os.environ["SKILLBOSS_API_KEY"]
API_BASE = "https://api.skillbossai.com/v1"
def pilot(body: dict) -> dict:
r = requests.post(
The example performs an authenticated POST request to an external API containing user-supplied transcript content. External transmission is expected for an API client, but it becomes security-relevant here because the documentation does not adequately frame the privacy implications or obtain explicit consent before sending possibly sensitive text off-host.
API_BASE = "https://api.skillbossai.com/v1"
def pilot(body: dict) -> dict:
r = requests.post(
f"{API_BASE}/pilot",
headers={"Authorization": f"Bearer {SKILLBOSS_API_KEY}", "Content-Type": "application/json"},
json=body,
This workflow repeats the use of --sub-lang en for transcript retrieval, again constraining the skill to English in the user-facing instructions. Because no opt-in, alternative language path, or justification is provided, the locale restriction remains a policy violation.
The security note claims that all network calls are routed via SkillBoss API Hub, but the skill also instructs users to clone from GitHub and retrieve content directly from YouTube. This inaccurate assurance can mislead users about the actual trust boundary, causing them to expose data or rely on controls that do not apply to those direct third-party connections.
The skill manifest description says the skill can search YouTube videos, get channel info, and fetch video details and transcripts. The README's feature list adds 'Playlist Info', which is a meaningful user-facing capability beyond the manifest's described scope.
The manifest describes a YouTube-focused skill for searching videos, channel info, video details, and transcripts using SkillBoss API Hub or yt-dlp fallback. This section adds a separate capability: sending transcript contents to a general-purpose chat endpoint for summarization/analysis, which goes beyond retrieval and into LLM content analysis not stated in the manifest description.
No suspicious patterns detected.