T09 · Insecure Skill Coding Practices
- Location
scripts/run_youtube2md.sh:135- Finding
External Content Disclosure Is Enabled by Default in Full Mode
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill appears purpose-built for YouTube summaries, but its default full mode can send transcript or audio-derived content to OpenAI and can use authenticated YouTube cookies without a separate per-run confirmation.
Install only if you are comfortable with YouTube transcript content, and possibly audio-derived content for captionless videos, being sent to OpenAI in full mode. Use simple/extract mode or set YOUTUBE2MD_CAPTIONS_ONLY=1 for sensitive videos, avoid raw cookie headers when possible, and prefer an unprivileged or vetted npm installation rather than sudo/global installs on shared or sensitive machines.
scripts/run_youtube2md.sh:135External Content Disclosure Is Enabled by Default in Full Mode
SKILL.md:52Globally Installed Third-Party Packages Create an Unverified Supply-Chain Execution Boundary
Referenced artifact was not completely inspected
- `scripts/run_youtube2md.sh <url> full [output_md_path] [language] [model]`
Referenced artifact was not completely inspected
- `scripts/run_youtube2md.sh <url> full [output_md_path] [language] [model]`
Referenced artifact was not completely inspected
- `scripts/run_youtube2md.sh <url> full [output_md_path] [language] [model]`
Referenced artifact was not completely inspected
- `scripts/run_youtube2md.sh <url> full [output_md_path] [language] [model]`
Referenced artifact was not completely inspected
- `scripts/run_youtube2md.sh <url> full [output_md_path] [language] [model]`
Referenced artifact was not completely inspected
- `scripts/run_youtube2md.sh <url> full [output_md_path] [language] [model]`
Referenced artifact was not completely inspected
- `scripts/run_youtube2md.sh <url> full [output_md_path] [language] [model]`
Referenced artifact was not completely inspected
- `scripts/run_youtube2md.sh <url> full [output_md_path] [language] [model]`
Referenced artifact was not completely inspected
- `scripts/run_youtube2md.sh <url> full [output_md_path] [language] [model]`
Referenced artifact was not completely inspected
- Keep only source files (`SKILL.md`, `scripts/`, `references/`) in release artifacts.
The skill auto-activates on messages containing only YouTube URLs, which broadens invocation beyond explicit user intent. In agent environments, this can cause unprompted fetching and summarization of external content, potentially triggering network access, processing sensitive links, or sending transcript/audio-derived data to third-party providers without a clear confirmation step.
The instruction says to always set YOUTUBE2MD_CAPTION_LANG when the language is known or inferable from the user's request, channel, or title/description. This imposes a language/locale decision automatically rather than offering the user a choice, which can violate language or locale policy expectations.
The documentation recommends sudo npm i -g @openai/codex-sdk, which normalizes running package-manager installs as root. Even though it tells the skill not to self-escalate, encouraging users to execute network-fetched JavaScript package installation with elevated privileges increases supply-chain and host-compromise risk if the package, registry path, or dependency chain is malicious or tampered with.
Fix:
- `npm i -g @openai/codex-sdk`
- On Homebrew Node, `node_modules/@openai` is often root-owned, so this fails with `EACCES` (`syscall mkdir`). Ask the user to run `sudo npm i -g @openai/codex-sdk` themselves — never escalate privileges from the skill.
- Verify: the runner's pre-check now mirrors youtube2md's own `detectCodexChatGptLogin()`, so once it stops warning, full mode will really use Codex.
- Watch for `INFO: Codex (ChatGPT login) unavailable; full mode will use the billed OPENAI_API_KEY path` — that means an `auto` run is spending API credits, not the ChatGPT subscription.
Skill establishes unauthorized persistence across sessions via cron jobs, startup scripts, or state files. Session persistence allows an attacker to maintain access beyond the current interaction.
Explanation and options:
- Expected since youtube2md 1.2.0: the Summary is an orientation capped at 8 sentences (with a paired word ceiling), and the detail deliberately lives in `## Chapters`. Pass the output through as-is instead of expanding it.
- If the user wants more substance, the lever is chapter density: `YOUTUBE2MD_DETAIL=exhaustive`.
- If the user specifically wants a longer narrative overview, write it separately from the transcript; do not present it as youtube2md output.
### 7) Change the full-mode model
Line L52 directs the skill to write in Korean based on content language or request context, rather than explicitly offering the user a language/locale choice. This is a natural-language locale policy constraint that can override a user's preferred output language without opt-in.
Skill requests more permissions than appear necessary for its stated functionality. Review if elevated access is justified.
Fix:
- `npm i -g @openai/codex-sdk`
- On Homebrew Node, `node_modules/@openai` is often root-owned, so this fails with `EACCES` (`syscall mkdir`). Ask the user to run `sudo npm i -g @openai/codex-sdk` themselves — never escalate privileges from the skill.
- Verify: the runner's pre-check now mirrors youtube2md's own `detectCodexChatGptLogin()`, so once it stops warning, full mode will really use Codex.
- Watch for `INFO: Codex (ChatGPT login) unavailable; full mode will use the billed OPENAI_API_KEY path` — that means an `auto` run is spending API credits, not the ChatGPT subscription.
The example command hard-codes Korean as the output language in a way that could normalize a fixed language setting rather than user-selected locale behavior. Under the policy, locale/language should not be forced unless the user is given a choice or the constraint is explicitly justified.
No suspicious patterns detected.