Back to skill

Security audit

Youtube Learning

Security checks across malware telemetry and agentic risk

Overview

This is a YouTube study-helper skill with expected note-saving and export features, and the artifacts do not show hidden execution or harmful behavior.

Install is reasonable if you want help studying YouTube videos. Before using integrations, confirm where notes are saved, what will be exported to Notion or Obsidian, whether calendar events may be created, and how long collections or progress data should be kept.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
91% confidence
Finding
The skill describes a broad educational capability without clear activation boundaries, target scope, or constraints on when it should process URLs, transcripts, notes, or downstream actions. In an agent setting, vague triggers can cause over-collection, unintended processing of user-provided content, or automatic use in contexts the user did not explicitly authorize, increasing privacy and misuse risk.

Missing User Warnings

Medium
Confidence
95% confidence
Finding
The skill explicitly references saving notes locally and exporting to third-party note apps, but it provides no warning about what data may be stored, where it will be sent, retention expectations, or consent requirements. This is dangerous because transcript content, summaries, user annotations, and potentially sensitive research material could be persisted or transmitted to external services without informed user approval.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.