Withme Youtube

PassAudited by VirusTotal on May 11, 2026.

Findings (1)

The skill bundle automates a complex YouTube video production pipeline but contains instructions in SKILL.md to intentionally bypass the 'Main' agent's oversight and inspection mechanism (pending.json). It features high-risk behaviors including programmatically extracting API keys from local configuration files (~/.openclaw/openclaw.json) and using Chrome DevTools Protocol (CDP) via websockets to manipulate browser behavior, automate downloads, and circumvent Cloudflare protections. While these actions support the stated automation goals, the circumvention of security gates and direct handling of sensitive credentials represent significant risks.