Back to skill

Security audit

ClawHub - YouTube Downloader & Clipper

Security checks for vulnerabilities and agentic risk

Overview

This YouTube clipping skill is purpose-aligned, but it asks the agent to silently install packages and run generated Python code built from user inputs, which needs careful review before use.

Install only if you are comfortable with the agent downloading media into the working directory, modifying the Python environment, and running generated scripts. Prefer using this in a dedicated folder or sandbox, install reviewed and pinned dependencies yourself first, and avoid untrusted filenames or request text until the code-generation pattern is fixed.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
prompt.md:184
Finding

Automatic Installation of an Unpinned Third-Party Dependency

Content
View full analysis

Vulnerability Details

File Location: prompt.md:40-43, prompt.md:184-188
Related Documentation: SKILL.md:129-131, README.md:91-92, README.md:104-106
Vulnerability Type: Supply-chain exposure through unpinned and unattended package installation
Risk Level: Medium

Vulnerable Code

markdown
2. **Ensure yt-dlp Python module is available**
   - Check if yt-dlp is installed: `python3 -c "import yt_dlp" 2>/dev/null`
   - If not, auto-install: `pip install yt-dlp`
   - This is transparent to the user
bash
python3 -c "import yt_dlp" 2>/dev/null || pip install -q yt-dlp

Technical Analysis

The skill directs the Agent to install yt-dlp automatically when the module cannot be imported. The installation command does not pin a reviewed version, verify package hashes, use a lockfile, constrain the package index, or request explicit user approval.

Consequently, the code installed and subsequently imported can change independently of the reviewed skill. The effective source also depends on the runtime pip configuration, including configured indexes and mirrors. A compromised upstream release, package index, mirror, dependency, or local pip configuration could therefore cause attacker-controlled code to execute in the Agent's environment.

The quiet installation option and instruction that installation should be transparent to the user further reduce visibility into this security-sensitive environmental modification.

Attack Path

  1. A user invokes the skill on a system where the yt_dlp Python module is unavailable.
  2. The Agent executes the prescribed import check.
  3. The import check fails and triggers pip install -q yt-dlp.
  4. Pip resolves the unpinned package and transitive dependencies through the environment's configured package index.
  5. A compromised package release, dependency, mirror, or index response supplies malicious code.
  6. The package or its depende ...[truncated 768 chars]
Remediation
View remediation

Remediation Suggestions

  1. Remove transparent dependency installation from normal skill execution.
  2. Require explicit user approval before modifying the Python environment.
  3. Pin yt-dlp and every relevant dependency to reviewed versions.
  4. Verify packages using hashes, such as with a hash-locked requirements file and pip --require-hashes.
  5. Use python3 -m pip to ensure installation targets the intended interpreter.
  6. Install dependencies inside a dedicated, least-privileged virtual environment rather than the Agent's global or user environment.
  7. Restrict resolution to an approved package index or internally controlled artifact repository.
  8. Display the package version and source before installation instead of using quiet, transparent installation.
  9. Prefer a deployment process that installs and verifies dependencies before the skill is invoked.

T09 · Insecure Skill Coding Practices

Error
Location
prompt.md:45
Finding

Python Code Injection Through Direct Substitution of User-Controlled Values

Content
View full analysis

Vulnerability Details

File Location: prompt.md:45-48, prompt.md:56-60, prompt.md:89-92, prompt.md:121-124, prompt.md:147-149, prompt.md:190-197
Vulnerability Type: Code injection caused by constructing executable Python source from request values
Risk Level: High

Vulnerable Code

markdown
3. **Generate and execute Python code**
   - Create a Python script with the appropriate yt_dlp configuration
   - Execute the script to perform the download/clip
   - Show progress to the user
python
#!/usr/bin/env python3
import yt_dlp
import sys

url = 'YOUTUBE_URL'
start_time = 'START'  # e.g., '00:30'
end_time = 'END'      # e.g., '02:15'
output = 'OUTPUT_FILE'
quality = 'QUALITY'   # e.g., 720, 1080, or 'best'
markdown
2. **Create Python Script**
   - Use the Write tool to create a temporary Python script (e.g., `ytclip_temp.py`)
   - Replace placeholders with actual values from user's request

3. **Execute Script**
```bash
python3 ytclip_temp.py
text

The same direct placeholder pattern is used by the audio clipping, full video download, and audio-only templates.

### Technical Analysis

The prescribed workflow tells the Agent to replace string placeholders in executable Python source with values obtained from the user's request and then run the generated file. The relevant values include the URL, start and end timestamps, output filename, and quality selection.

These values are placed inside single-quoted Python literals, but the skill does not prescribe escaping, structured serialization, or safe argument passing. A value containing a quote can terminate the intended literal and append Python statements.

For example, if a directly substituted output value were:

```text
'; __import__("os").system("id"); #

the generated statement would become equivalent to:

python
output = ''; __import__("os").system("id"); #'

The inje ...[truncated 1941 chars]

Remediation
View remediation

Remediation Suggestions

  1. Do not generate executable Python source by replacing placeholders with user-controlled text.
  2. Ship or create a fixed, reviewed downloader program whose source is independent of request values.
  3. Pass user values as command-line arguments and parse them with argparse, or pass them through a structured data file parsed with json.
  4. When launching a process, use an argument array rather than a shell command string.
  5. If source generation is unavoidable, serialize every inserted value with a correct mechanism such as repr() or json.dumps(); do not use manual quoting or replacement.
  6. Strictly allowlist supported YouTube hostnames and URL schemes.
  7. Validate timestamps using a complete parser and enforce that the end time is greater than the start time.
  8. Allowlist quality values and output formats rather than accepting arbitrary strings.
  9. Resolve output paths against an approved output directory and reject absolute paths, traversal components, symbolic-link escapes, and unexpected extensions.
  10. Create temporary files using secure operating-system APIs with unpredictable names and restrictive permissions, and remove them in a finally block.
  11. Run media processing in a sandbox with minimal filesystem and network access.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (9)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill causes network retrieval of remote YouTube content and saves output to the current working directory, but the description does not present this as a prominent operational warning. In an agent setting, insufficient disclosure increases the risk of unanticipated file creation, workspace pollution, overwriting user files, and execution in sensitive directories.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The notes say 'Pure Python solution - no binary dependencies, just Python' at L141, yet the technical details state 'ffmpeg (required for audio extraction, usually pre-installed)' at L153, and the clipping workflow lists 'ffmpeg precise cutting' as a fallback at L106. This is an active contradiction about required runtime behavior and installation assumptions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

Automatically installing dependencies via pip during normal skill use is a meaningful supply-chain and environment-modification risk, especially when not prominently disclosed. In agent-driven environments this can unexpectedly execute package installation logic, alter the runtime, pull unpinned third-party code from remote sources, and violate least-privilege or reproducibility expectations.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
70% confidence
Finding

Commands invoke sudo or root privileges. Verify this elevated access is necessary and justified.

Content

Scanner excerpt · install.sh (reported line 35)May include surrounding context.

sh
echo ""
    echo "Please install yt-dlp:"
    echo "  macOS:   brew install yt-dlp"
    echo "  Linux:   sudo apt install yt-dlp"
    echo "  Pip:     pip install yt-dlp"
fi

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The skill directs automatic installation of yt-dlp with pip without explicit user consent, which modifies the runtime environment and pulls executable code from an external package repository. In an agent setting, silent dependency installation increases supply-chain and integrity risk, especially if package sources, versions, or installation scope are not constrained.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The prompt repeatedly frames the skill as a 'Pure Python solution' with 'no binary dependencies except Python itself'. However, the audio templates use yt-dlp postprocessors with FFmpegExtractAudio and the notes explicitly acknowledge ffmpeg is required, which directly contradicts the earlier claim rather than merely omitting detail.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

This markdown file documents that the skill saves clips to the current directory, but it does not present that behavior as a user-facing warning or caution despite affecting the user's filesystem. Under the markdown criteria for missing user warnings, behaviors that affect user data or system state should be clearly disclosed as warnings, not just mentioned incidentally in workflow notes.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The workflow explicitly states 'Validate the URL format' before generating and executing code. None of the supplied Python templates or implementation steps include any validation logic; they pass the user-provided URL directly into yt_dlp for download. This is an intent-code divergence because the instructions describe a safeguard that is absent from the actual implementation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The documented workflow says the agent will write ytclip_temp.py, execute it, and remove it afterward. Because this performs filesystem writes and deletion, the markdown should disclose that behavior to the user rather than only describing it as an internal implementation detail.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.