Back to skill

Security audit

youtube-summary

Security checks for vulnerabilities and agentic risk

Overview

The skill appears purpose-built for YouTube summaries, but its default full mode can send transcript or audio-derived content to OpenAI and can use authenticated YouTube cookies without a separate per-run confirmation.

Install only if you are comfortable with YouTube transcript content, and possibly audio-derived content for captionless videos, being sent to OpenAI in full mode. Use simple/extract mode or set YOUTUBE2MD_CAPTIONS_ONLY=1 for sensitive videos, avoid raw cookie headers when possible, and prefer an unprivileged or vetted npm installation rather than sudo/global installs on shared or sensitive machines.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/run_youtube2md.sh:135
Finding

External Content Disclosure Is Enabled by Default in Full Mode

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:52
Finding

Globally Installed Third-Party Packages Create an Unverified Supply-Chain Execution Boundary

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Rogue AgentSelf-Modification, Session Persistence
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (17)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 100)May include surrounding context.

md
- `scripts/run_youtube2md.sh <url> full [output_md_path] [language] [model]`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 103)May include surrounding context.

md
- `scripts/run_youtube2md.sh <url> full [output_md_path] [language] [model]`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 108)May include surrounding context.

md
- `scripts/run_youtube2md.sh <url> full [output_md_path] [language] [model]`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 109)May include surrounding context.

md
- `scripts/run_youtube2md.sh <url> full [output_md_path] [language] [model]`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 112)May include surrounding context.

md
- `scripts/run_youtube2md.sh <url> full [output_md_path] [language] [model]`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 114)May include surrounding context.

md
- `scripts/run_youtube2md.sh <url> full [output_md_path] [language] [model]`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 116)May include surrounding context.

md
- `scripts/run_youtube2md.sh <url> full [output_md_path] [language] [model]`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 118)May include surrounding context.

md
- `scripts/run_youtube2md.sh <url> full [output_md_path] [language] [model]`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 186)May include surrounding context.

md
- `scripts/run_youtube2md.sh <url> full [output_md_path] [language] [model]`

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 182)May include surrounding context.

md
- Keep only source files (`SKILL.md`, `scripts/`, `references/`) in release artifacts.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill auto-activates on messages containing only YouTube URLs, which broadens invocation beyond explicit user intent. In agent environments, this can cause unprompted fetching and summarization of external content, potentially triggering network access, processing sensitive links, or sending transcript/audio-derived data to third-party providers without a clear confirmation step.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
80% confidence
Finding

The instruction says to always set YOUTUBE2MD_CAPTION_LANG when the language is known or inferable from the user's request, channel, or title/description. This imposes a language/locale decision automatically rather than offering the user a choice, which can violate language or locale policy expectations.

Content

No source excerpt is available for this finding.

Sudo/Root Execution

Medium
Category
Privilege Escalation
Confidence
71% confidence
Finding

The documentation recommends sudo npm i -g @openai/codex-sdk, which normalizes running package-manager installs as root. Even though it tells the skill not to self-escalate, encouraging users to execute network-fetched JavaScript package installation with elevated privileges increases supply-chain and host-compromise risk if the package, registry path, or dependency chain is malicious or tampered with.

Content

Scanner excerpt · references/troubleshooting.md (reported line 67)May include surrounding context.

md
Fix:
- `npm i -g @openai/codex-sdk`
- On Homebrew Node, `node_modules/@openai` is often root-owned, so this fails with `EACCES` (`syscall mkdir`). Ask the user to run `sudo npm i -g @openai/codex-sdk` themselves — never escalate privileges from the skill.
- Verify: the runner's pre-check now mirrors youtube2md's own `detectCodexChatGptLogin()`, so once it stops warning, full mode will really use Codex.
- Watch for `INFO: Codex (ChatGPT login) unavailable; full mode will use the billed OPENAI_API_KEY path` — that means an `auto` run is spending API credits, not the ChatGPT subscription.

Session Persistence

Medium
Category
Rogue Agent
Confidence
60% confidence
Finding

Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.

Content

Scanner excerpt · references/troubleshooting.md (reported line 95)May include surrounding context.

md
Explanation and options:
- Expected since youtube2md 1.2.0: the Summary is an orientation capped at 8 sentences (with a paired word ceiling), and the detail deliberately lives in `## Chapters`. Pass the output through as-is instead of expanding it.
- If the user wants more substance, the lever is chapter density: `YOUTUBE2MD_DETAIL=exhaustive`.
- If the user specifically wants a longer narrative overview, write it separately from the transcript; do not present it as youtube2md output.

### 7) Change the full-mode model

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

Line L52 directs the skill to write in Korean based on content language or request context, rather than explicitly offering the user a language/locale choice. This is a natural-language locale policy constraint that can override a user's preferred output language without opt-in.

Content

No source excerpt is available for this finding.

Excessive Permissions

Low
Category
Privilege Escalation
Confidence
80% confidence
Finding

Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.

Content

Scanner excerpt · references/troubleshooting.md (reported line 67)May include surrounding context.

md
Fix:
- `npm i -g @openai/codex-sdk`
- On Homebrew Node, `node_modules/@openai` is often root-owned, so this fails with `EACCES` (`syscall mkdir`). Ask the user to run `sudo npm i -g @openai/codex-sdk` themselves — never escalate privileges from the skill.
- Verify: the runner's pre-check now mirrors youtube2md's own `detectCodexChatGptLogin()`, so once it stops warning, full mode will really use Codex.
- Watch for `INFO: Codex (ChatGPT login) unavailable; full mode will use the billed OPENAI_API_KEY path` — that means an `auto` run is spending API credits, not the ChatGPT subscription.

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The example command hard-codes Korean as the output language in a way that could normalize a fixed language setting rather than user-selected locale behavior. Under the policy, locale/language should not be forced unless the user is given a choice or the constraint is explicitly justified.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.