T09 · Insecure Skill Coding Practices
- Location
scripts/yt_transcript.py:435- Finding
Dormant Undisclosed Third-Party Requests and Provider-Controlled URL Fetching
- Content
View full analysis
tuple[str, str, list[dict[str, Any]]]: """Last-resort fallback via a third-party transcript provider.""" api = "https://yt-to-text.com/api/v1/Subtitles" body = json.dumps({"video_id": video_id}).encode("utf-8") headers = { "User-Agent": "Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120 Safari/537.36", "Accept": "application/json", "Content-Type": "application/json", "x-source": "tubetranscript", "x-app-version": "1.0", } req = urllib.request.Request(api, data=body, headers=headers, method="POST") try: with urllib.request.urlopen(req, timeout=30) as resp: raw = resp.read().decode("utf-8", errors="ignore") except urllib.error.HTTPError as e: msg = e.read().decode("utf-8", errors="ignore") raise TranscriptError(f"Third-party fallback (yt-to-text) HTTP {e.code}: {msg[:200]}") except urllib.error.URLError as e: raise TranscriptError(f"Third-party fallback (yt-to-text) failed: {e}") ``` ```python def _thirdparty_downsub(video_id: str) -> tuple[str, str, list[dict[str, Any]]]: """Third-party fallback using DownSub backends.""" try: from Crypto.Cipher import AES # type: ignore from Crypto.Protocol.KDF import EVP_BytesToKey # type: ignore from Crypto.Random import get_random_bytes # type: ignore except Exception as e: raise TranscriptError( "DownSub fallback requires pycryptodome (Crypto). Install: pip install pycryptodome" ) def _b64e(b: bytes) -> str: return base64.b64encode(b).decode("ascii") def _b64url(s: str) -> str: return s.replace("+ ...[truncated 5596 chars]- Remediation
View remediation
