YouTube SkillForge

Security checks across malware telemetry and agentic risk

Overview

This skill is transparent about turning YouTube transcripts into local reusable skill files and its disclosed storage, MCP, and install behavior fit that purpose.

Before installing, make sure you trust the external npm package and yt-dlp installation source. Generated video-derived skills will persist locally and may influence future agent recall, so review saved skills before relying on them.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal