Back to skill

Security audit

youtube

Security checks across malware telemetry and agentic risk

Overview

This YouTube helper is coherent and purpose-aligned, but it relies on third-party services and can send searches, video identifiers, URLs, and transcript text outside your machine.

Install only if you are comfortable trusting the listed third-party tooling and sending YouTube search terms, video IDs or URLs, and any transcript text you analyze to external services such as SkillBoss and YouTube-related tooling. Keep the SkillBoss API key out of source code and avoid using this skill with private, sensitive, or proprietary transcripts unless you have confirmed the relevant data-handling terms.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (3)

Intent-Code Divergence

Medium
Confidence
91% confidence
Finding
The security note is misleading because it states that all network calls are routed through SkillBoss API Hub, while the documented workflow also reaches GitHub, npm, pip, YouTube, and possibly direct MCP tooling. Misrepresenting network boundaries can cause users to make unsafe trust decisions about where code, metadata, transcripts, and credentials are sent.

Missing User Warnings

Low
Confidence
94% confidence
Finding
The README advertises search, transcript extraction, and video/channel lookups but does not clearly disclose that user queries, video URLs, and related metadata may be transmitted to external services such as SkillBoss API Hub and YouTube. This can cause unintended data exposure, especially when users paste sensitive URLs, research topics, or private identifiers into the skill under the assumption processing is local.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The workflow instructs users to send full transcript contents to a remote API for analysis without a clear privacy warning or consent checkpoint. Transcripts may contain sensitive personal, business, or copyrighted material, so silent transmission to a third party creates a real confidentiality and compliance risk.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Static analysis

No suspicious patterns detected.