Back to skill

Security audit

YouTube Video Downloader

Security checks for vulnerabilities and agentic risk

Overview

This is a Markdown-only YouTube downloader skill that openly uses a third-party API, with no bundled executable code or hidden persistence found.

Before installing, understand that this skill depends on a third-party service at skill.lordest.cn. Your generated service API key and requested YouTube URLs will be sent there, and successful downloads may be served from an external storage URL. Use a dedicated, rotatable API key and review the provider's terms, privacy practices, pricing, and content-rights implications before use.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (3)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill instructs users to obtain an API key from, and send YouTube URLs to, a third-party service without clearly warning that both user-supplied content and credentials will be transmitted off-platform. This creates a privacy and trust risk because users may reasonably assume the action is local or first-party, and they are not given enough information to make an informed consent decision.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
88% confidence
Finding

The curl example explicitly transmits an Authorization bearer token and YouTube URL to a third-party API endpoint. Although this matches the skill's purpose, it remains a real security concern because it encourages users to send credentials and content identifiers externally, with no nearby warning about third-party handling, logging, or retention.

Content

Scanner excerpt · SKILL.md (reported line 120)May include surrounding context.

bash
# Download a video
curl -X POST https://skill.lordest.cn/api/v1/download \
  -H "Authorization: Bearer sk-yt-xxxxx" \
  -H "Content-Type: application/json" \
  -d '{"youtube_url": "https://youtube.com/watch?v=dQw4w9WgXcQ", "resolution": "720"}'

External Transmission

Medium
Category
Data Exfiltration
Confidence
89% confidence
Finding

The example code sends the user's API key and requested YouTube URL to an external domain, which is an external data transmission by design. In context this is expected functionality, but it is still security-relevant because secrets and user activity are shared with a third-party endpoint, so the danger comes from insufficient disclosure and trust boundaries rather than hidden code execution.

Content

Scanner excerpt · SKILL.md (reported line 135)May include surrounding context.

md
BASE_URL = "https://skill.lordest.cn"

# Download
resp = requests.post(
    f"{BASE_URL}/api/v1/download",
    headers={"Authorization": f"Bearer {API_KEY}"},
    json={"youtube_url": "https://youtube.com/watch?v=dQw4w9WgXcQ", "resolution": "720"}

Static analysis

No suspicious patterns detected.