Back to skill

Security audit

YouTube I18n Language

Security checks across malware telemetry and agentic risk

Overview

This skill is a narrow YouTube language-listing helper, but users should handle the local YouTube OAuth files as sensitive secrets.

Install only if you trust the yutu CLI package and are comfortable granting it YouTube API access. Keep client_secret.json and youtube.token.json private, out of repositories and shared folders, and revoke or rotate the OAuth token if either file is exposed.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
94% confidence
Finding
The setup guide instructs users to create and store OAuth client secrets and access tokens locally, but it does not warn that these files contain sensitive credentials that can grant API access if exposed. In an agent/skill context, users may follow these steps in shared workspaces, repos, or synced directories, increasing the chance of accidental credential leakage.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.