Back to skill

Security audit

Youtube Watcher Tool Free

Security checks across malware telemetry and agentic risk

Overview

The skill is not malicious, but it needs review because it activates for unrelated SEO/ranking tasks and asks for shell/package-install use while its referenced transcript script is missing.

Install only if you intend to use it for user-supplied single YouTube video transcript extraction. Review or narrow the trigger wording before enabling automatic skill selection, and expect the packaged skill to fail unless the missing transcript script is supplied or the workflow is rewritten to call yt-dlp directly.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

High
Confidence
88% confidence
Finding
The trigger conditions are overly broad and mismatched to the skill's actual capabilities, instructing activation for SEO optimization, ranking, and traffic tasks unrelated to YouTube transcript extraction. In an agent ecosystem, this can cause the wrong skill to be invoked for unrelated requests, increasing the chance of unintended command execution, unnecessary network access to third-party URLs, or user confusion about what actions the agent will perform.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.