Back to skill

Security audit

YouTube Channel Section

Security checks across malware telemetry and agentic risk

Overview

This is a coherent YouTube channel-section helper, but users should handle OAuth files carefully and confirm IDs before deleting sections.

Install this only if you trust the yutu CLI and intend to manage YouTube channel sections. Keep client_secret.json and youtube.token.json private, do not commit or share them, and list sections first so you can confirm the exact IDs before running any delete command.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Medium
Confidence
92% confidence
Finding
This documentation exposes a destructive delete command without any warning about irreversible effects, ownership verification, dry-run alternatives, or confirmation practices. In an agent skill context, users or downstream automation may execute the command directly, increasing the chance of accidental deletion of channel sections or misuse against the wrong resources.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal