Back to skill

Security audit

Video Transcript Downloader

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it exposes an unrestricted yt-dlp argument passthrough that can give an agent much broader local command authority than a normal video downloader needs.

Review this skill carefully before installing. It is suitable only if you trust users and prompts not to supply advanced yt-dlp options after `--`; a safer version would remove raw passthrough or replace it with a small allowlist for benign options like format selection and verbosity.

Vulnerability Patterns
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T09 · Insecure Skill Coding Practices

Error
Location
scripts/vtd.js:32
Finding

Unrestricted yt-dlp Argument Passthrough Enables Arbitrary Command Execution

Content
View full analysis
Remediation
View remediation
--remux-video --verbose ``` 5. Ensure fixed security arguments cannot be overridden by later user-supplied arguments. Construct the final `yt-dlp` argument list exclusively from validated fields. 6. If advanced passthrough must remain available for trusted interactive use, disable it by default in agent execution and require explicit human confirmation that displays the complete resulting argument list. 7. Add automated tests verifying that dangerous arguments are rejected across every command, including `transcript`, `download`, `audio`, `subs`, and `formats`. ]]>
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
87% confidence
Finding

The trigger phrases are broad enough to match common user requests such as downloading, saving, or getting transcripts, which can cause the skill to activate in more situations than intended. Over-broad activation increases the chance of unexpected network access, media retrieval, and local file operations without sufficiently specific user consent.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill instructs downloading video, audio, and subtitles to a local output directory but does not clearly warn that this writes files to disk. In an agent setting, undisclosed file creation can surprise users, clutter sensitive directories, or overwrite existing content depending on downstream script behavior.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.dangerous_exec, suspicious.env_credential_access

Shell command execution detected (child_process).

Critical
Code
suspicious.dangerous_exec
Location
scripts/vtd.js:77

Environment variable access combined with network send.

Critical
Code
suspicious.env_credential_access
Location
scripts/vtd.js:61