Back to skill

Security audit

transcriptapi

Security checks for vulnerabilities and agentic risk

Overview

The skill provides a coherent YouTube transcript/search integration, but its setup flow asks the agent to handle and persist sensitive credentials, email, OTP, and temporary auth files with weak user-control guidance.

Install only if you are comfortable letting the agent use TranscriptAPI for YouTube lookups and handle a TranscriptAPI key. Prefer creating the account yourself, entering OTPs directly on the provider site, and storing the API key in a dedicated secret manager rather than chat, shell profiles, or temporary files.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (9)

Vague Triggers

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill’s activation description is extremely broad and explicitly says to use it whenever YouTube 'is or could be relevant — even if not mentioned,' plus many generic research and summary scenarios. That can cause the agent to invoke this external-network skill for ordinary requests where the user did not intend third-party API use, increasing privacy exposure, unnecessary external calls, and the chance of unrelated context being sent off-platform.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instruction to ask the user to paste an API key and later share a one-time verification code causes the agent to solicit highly sensitive secrets directly in chat. In many agent systems, chat content and tool traces may be logged or retained, making this an unsafe channel for collecting credentials and MFA-style factors.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

This signup flow has the agent collect an email address, receive an OTP, obtain the resulting API key, and then persist that secret, creating an end-to-end sensitive-data handling pipeline inside the agent. Even if intended as convenience, the workflow centralizes multiple sensitive artifacts in one place and expands the blast radius of any logging, prompt leakage, file exposure, or operator error.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document explicitly recommends saving raw authentication responses to temporary files and extracting tokens and API keys from those files, which encourages local plaintext retention of sensitive credentials. Temporary files are often accessible to other processes, may persist longer than intended, and can be captured by backups, debug tooling, or crash artifacts.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The documentation explains how to call transcriptapi.com and what parameters to send, but it does not clearly warn that user queries, YouTube links/handles/IDs, and related research terms are transmitted to a third-party service. In combination with the broad activation guidance, users may unknowingly have their inputs sent externally, creating a transparency and privacy-consent risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The document explicitly tells the agent to determine how to persist an environment variable so the API key survives across sessions and non-interactive shells. Persistent secret storage by an agent without strict secret-management controls can expose credentials through shell profiles, config files, backups, logs, or other local users/processes.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The skill tells the agent to collect and persist API keys and auth tokens but does not require a clear warning or consent flow explaining that these secrets may be stored on disk or in persistent configuration. Users may unknowingly authorize long-term storage of highly sensitive credentials in locations with weaker protections than expected.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The guide instructs the agent to perform account registration and OTP-based verification on the user's behalf, which places the agent in the middle of an authentication flow and requires it to collect, relay, and process sensitive login artifacts. This increases the risk of credential interception, account takeover, and unsafe handling of authentication factors, especially in agent environments with logging, tool traces, or insecure temp-file usage.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The guide directs the agent to send the user's email address to an external service during account creation without first requiring a disclosure that the data will be transmitted to a third party. This creates a privacy and consent issue because personally identifiable information is shared externally as part of the agent workflow.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.