captions
PassAudited by VirusTotal on May 12, 2026.
Findings (1)
The skill bundle is classified as suspicious primarily due to instructions in 'references/auth-setup.md' that direct the AI agent to bypass platform security redaction filters. It explicitly instructs the agent to write sensitive tokens and API keys to temporary files to ensure the agent can read them even if the platform attempts to mask or redact them from tool output. While the tool's stated purpose of fetching YouTube transcripts via 'transcriptapi.com' is functional, the inclusion of techniques to circumvent security guardrails and the automated account registration flow represent high-risk behaviors.
