T09 · Insecure Skill Coding Practices
- Location
extraction/youtubeTranscript.js:69- Finding
OS Command Injection Through the YouTube Transcript URL
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This web research skill matches its stated purpose, but unsafe URL handling and a YouTube transcript command bug could let it reach internal network resources or run local commands.
Review before installing. Use only in a sandboxed environment with restricted network egress and trusted callers until the publisher replaces shell execSync with argument-based execution, validates URLs and YouTube IDs, blocks private/internal destinations, adds time and size limits, removes committed debug output, and updates vulnerable dependencies.
extraction/youtubeTranscript.js:69OS Command Injection Through the YouTube Transcript URL
extraction/pageExtractor.js:4Server-Side Request Forgery in Page and Link Extraction
extraction/pdfExtractor.js:4Server-Side Request Forgery in PDF Extraction
extraction/pdfExtractor.js:4Unbounded Remote Content Download and Parsing Enables Denial of Service
extraction/youtubeTranscript.js:63Predictable Shared Subtitle File Creates Race and Symlink Risks
output.txt:96Committed Debug Transcript Discloses Operational Environment Data
No manifest is available, so there is no declared purpose that would justify granting a skill arbitrary subprocess execution. The observed behavior runs yt-dlp through the shell against user-controlled input, which is a materially broader capability than simple in-process data handling.
The lockfile pins axios 1.13.6, and the provided advisories include SSRF, prototype-pollution-assisted MITM/credential theft, and related request handling flaws. In a browser/web-fetching MCP skill, HTTP client behavior is security-relevant, so a vulnerable axios version materially increases risk if the skill fetches attacker-controlled URLs or honors proxy environment settings.
form-data 4.0.5 is reported vulnerable to CRLF injection through unescaped multipart field names/filenames. If the skill constructs multipart requests using attacker-influenced values, this can corrupt request structure or inject unintended headers/content toward upstream services.
undici 7.22.0 is flagged for multiple HTTP parsing and smuggling issues, including request/response smuggling and CRLF-related problems. Because cheerio depends on undici and this skill appears to perform network retrieval/parsing, these flaws can affect interactions with attacker-controlled endpoints or intermediaries.
The package manifest permits installation of axios 1.13.6, and the static analysis indicates that version has multiple known advisories including SSRF-related and prototype-pollution/MITM exploitation paths. In a skill described as a web-search or browsing MCP for agents, HTTP client behavior is security-critical because the component likely fetches attacker-controlled URLs and remote content, making known axios flaws materially more dangerous in context.
This skill explicitly provides web search, page fetching, PDF extraction, YouTube transcript retrieval, and automated research, but the description does not warn users that it will access external network resources and process untrusted third-party content. That omission can cause users or downstream agents to invoke the skill without understanding privacy, data exposure, or prompt-injection risks from remote content, which is especially relevant for a research-oriented MCP.
Both extractPage and extractLinks perform server-side HTTP requests directly to a caller-supplied URL with no validation, allowlist, or protocol restrictions. This creates an SSRF-style primitive that can be used to make the host access internal services, cloud metadata endpoints, or other unintended network targets; the scraping context increases risk because fetching arbitrary pages is the core behavior.
The function performs an HTTP request to a caller-supplied URL and downloads remote content, which can transmit user-provided data and interact with external systems. There is no confirmation prompt, logging, comment, or docstring disclosing this network behavior in the file.
The command forces transcript extraction to English via --sub-lang en, and the surrounding comment explicitly states 'only English'. This imposes a language choice without any indication of user selection, opt-in, or documented region-specific justification.
With no manifest available, the skill's stated purpose is unknown, so spawning a local binary is not justified by any declared intent. The code uses execSync to run yt-dlp, which is a materially more powerful capability than simple in-process text parsing and can have broader system effects.
The function interpolates a user-supplied URL directly into a shell command passed to execSync, which creates a command injection risk if quoting can be broken or shell metacharacters are interpreted unexpectedly. It also allows undisclosed network-capable subprocess execution against attacker-controlled input, increasing the blast radius to arbitrary command execution or unwanted outbound requests.
This text file contains executable Node.js commands that invoke execSync to run yt-dlp, which triggers shell execution and network access to YouTube. Although runtime warnings from yt-dlp are shown later, there is no user-facing comment, prompt, or explanatory note in the file itself disclosing that a shell command will contact an external service and process subtitle output.
The natural-language-facing behavior here constrains subtitle retrieval to English by specifying --sub-lang en, and the later invocation appears to do the same transcript operation for the user without offering a language choice. That creates a locale policy issue because the skill behavior fixes the language rather than letting the user choose or documenting a justified regional constraint.
follow-redirects 1.15.11 is flagged for leaking custom authentication headers across cross-domain redirects. In a tool that may retrieve remote resources, this can expose bearer tokens or API keys when an attacker controls a redirect target, especially because axios depends on this package.
mongoose 8.23.0 is flagged for prototype pollution in update casting via proto-prefixed properties. This is a real issue in environments that pass attacker-controlled update objects into Mongoose, though the skill’s declared top-level dependencies do not directly indicate active database use, so exploitability in this specific context is less certain.
uuid 9.0.1 is flagged for a missing bounds check in certain hash-based UUID variants when a caller supplies a buffer. This appears real, but impact is limited unless the application explicitly uses v3/v5/v6 APIs with attacker-controlled buffer arguments; no such usage is visible from the lockfile alone.
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"main": "index.js",
"type": "commonjs",
"dependencies": {
"axios": "^1.6.0",
"cheerio": "^1.0.0",
"natural": "^6.5.0",
"p-limit": "^4.0.0",
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"type": "commonjs",
"dependencies": {
"axios": "^1.6.0",
"cheerio": "^1.0.0",
"natural": "^6.5.0",
"p-limit": "^4.0.0",
"pdf-parse": "^1.1.1",
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"dependencies": {
"axios": "^1.6.0",
"cheerio": "^1.0.0",
"natural": "^6.5.0",
"p-limit": "^4.0.0",
"pdf-parse": "^1.1.1",
"youtube-transcript": "^1.2.1"
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"axios": "^1.6.0",
"cheerio": "^1.0.0",
"natural": "^6.5.0",
"p-limit": "^4.0.0",
"pdf-parse": "^1.1.1",
"youtube-transcript": "^1.2.1"
}
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"cheerio": "^1.0.0",
"natural": "^6.5.0",
"p-limit": "^4.0.0",
"pdf-parse": "^1.1.1",
"youtube-transcript": "^1.2.1"
}
}
Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.
"natural": "^6.5.0",
"p-limit": "^4.0.0",
"pdf-parse": "^1.1.1",
"youtube-transcript": "^1.2.1"
}
}
This code performs a network request using axios and sends request metadata, including a User-Agent header, but the file contains no comment, docstring, log, or prompt disclosing that outbound network access occurs. For code files, network calls that transmit user or system data should have some visible warning unless clearly covered by the skill's stated purpose, which is not evident in this file alone.
Detected: suspicious.dangerous_exec