Back to skill

Security audit

Youtube Knowledge Extractor

Security checks for vulnerabilities and agentic risk

Overview

This skill downloads YouTube metadata, captions, video, and frames for analysis, which matches its stated purpose, though users should expect network use, temporary files, and an unpinned dependency.

Install only if you are comfortable with the agent contacting YouTube, downloading video and caption data, and storing temporary analysis files. Prefer running it in a normal unprivileged account, clean up temp files after use, and be cautious with the optional browser-cookie workflow because it can expose logged-in session access to yt-dlp.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:20
Finding

Unpinned Third-Party Dependency

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 20–25
Vulnerability Type: Unpinned package dependency
Risk Level: Medium

Vulnerable Code

yaml
install:
  - kind: uv
    package: yt-dlp
    bins: [yt-dlp]

Technical Analysis

The skill instructs the package manager to install yt-dlp without specifying a reviewed version, lockfile, integrity hash, or signature-verification mechanism. Consequently, installation resolves whichever release the configured package source serves at that time.

This creates a supply-chain risk because the installed code can change after the skill has been audited. Exploitation would require compromise of the package, its maintainer account, the package repository, or the package-resolution channel. There is no evidence that the current yt-dlp package is malicious; the finding concerns the absence of reproducible and integrity-verified dependency resolution.

Attack Path

  1. An attacker compromises the upstream package, maintainer account, repository, or dependency-delivery channel.
  2. The attacker publishes or serves a malicious yt-dlp release.
  3. A user installs the skill's requirements.
  4. Because no version or hash is specified, the installer resolves the attacker-controlled release.
  5. Malicious package code executes during installation or later when the skill invokes yt-dlp.

Impact Assessment

Successful exploitation could execute arbitrary code with the privileges of the account installing or running the skill. Potential scope includes access to that account's readable files, environment variables, network credentials, and generated video-analysis data. If installation is performed by a privileged account, the impact could extend to system-wide resources available to that account.

The skill itself does not request privilege escalation, establish persistence, or demonstrate malicious package behavior. Actual impact depends on an upstr ...[truncated 92 chars]

Remediation
View remediation

Remediation Suggestions

  1. Pin yt-dlp to a specifically reviewed version rather than resolving the latest available release.
  2. Use a lockfile that records exact transitive dependency versions.
  3. Require cryptographic hashes for downloaded distributions where supported.
  4. Retrieve packages only from an explicitly configured, trusted package index.
  5. Update dependencies through a controlled process that includes security review and automated vulnerability scanning.
  6. Perform installation and execution as an unprivileged user in a sandbox with restricted filesystem and network access.
  7. Document the approved version and integrity information so installations are reproducible.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (4)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The trigger condition is broad enough that the skill may activate for almost any YouTube URL shared in a general analysis context, causing unintended execution. Because this skill performs network access, downloads remote content, and writes local files, accidental activation increases privacy, consent, and resource-usage risk even without explicit user intent to invoke heavy processing.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill makes outbound requests to third-party services using yt-dlp and curl to fetch metadata, subtitle URLs, transcripts, and video content, but this behavior is not surfaced as a user warning. Unannounced network activity can disclose user-supplied URLs, IP address, user-agent details, and access patterns to external platforms, which is a meaningful privacy and consent issue.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs the agent to create a temporary working directory and later download transcripts, video files, and extracted frames into it, but the description does not warn users that local storage will be used. This can expose sensitive viewing activity, consume disk space, and leave recoverable artifacts behind if cleanup fails or execution is interrupted.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
96% confidence
Finding

The instructions explicitly prioritize caption languages in a fixed order starting with English and German, which imposes a language preference without asking the user. This is a natural-language locale policy concern because the skill does not offer language choice or document why that preference is required.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.