YouTube To Blog

Security checks across malware telemetry and agentic risk

Overview

This is a plain instruction-only writing skill that fetches or uses a provided YouTube transcript to draft a blog post, with no hidden code or persistence found.

Install only if you are comfortable with your agent accessing YouTube caption data for URLs you provide. Invoke the skill explicitly, treat fetched transcripts as untrusted source material, and review generated posts for accuracy, copyright/usage rights, and accidental transcript artifacts before publishing.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The README exposes a very broad natural-language invocation pattern ('Use youtube-to-blog with this video/transcript') without clear trigger boundaries, parameter validation expectations, or exclusions. In agent environments, overly generic invocation phrasing can cause accidental or adversarial activation on untrusted content, making prompt-routing and downstream handling of arbitrary URLs or pasted transcript text less predictable.

VirusTotal

63/63 vendors flagged this skill as clean.

View on VirusTotal