Back to skill

Security audit

youtube-full

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent YouTube/TranscriptAPI integration, but its setup asks the agent to create or verify accounts and persist credentials broadly across future sessions.

Install only if you are comfortable letting the agent use TranscriptAPI for YouTube-related work and store a TranscriptAPI key for future sessions. Prefer creating the account yourself, providing the key through an approved secret mechanism, and asking the agent before sending sensitive research queries or private links to the service.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (6)

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The guide directs the agent to persistently store an API secret across sessions and shells, creating long-lived credential access in the agent environment. For a YouTube-focused skill, this is an unjustified expansion of privilege and increases the blast radius if the agent, runtime, logs, or related skills are compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill instructs the agent to perform third-party account registration, receive an email OTP from the user, and complete verification on the user's behalf. That is outside the declared YouTube research/transcript scope and grants the skill a credential-brokering capability that could be abused to create, verify, or bind external accounts without clear necessity or strong consent boundaries.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The invocation description is extremely broad ('use when YouTube is or could be relevant — even if not mentioned'), which can cause the agent to route many ordinary research prompts to this skill unnecessarily. That increases unnecessary third-party data exposure and the chance of external calls being made with user queries or identifiers when a local or less-privileged capability would have sufficed.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The skill instructs sending user-provided queries, video URLs, handles, and other identifiers to TranscriptAPI.com but does not prominently warn that this data leaves the agent environment and is shared with a third-party service. In combination with the broad routing language, users may have their research topics or linked content transmitted externally without clear notice or consent.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The instructions tell the agent to inspect runtime documentation, config files, and environment-secret mechanisms to determine how to persist credentials. This expands the skill into agent-environment reconnaissance and secret-management behavior beyond its stated function, which can expose internal configuration details or normalize overbroad access patterns.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The flow asks the user to provide sensitive data including an API key, email address, and OTP, then transmits and stores resulting credentials without a clear user-facing warning about sensitivity, retention, or storage implications. This weakens informed consent and raises the risk of users oversharing secrets into an agent workflow that may log or persist them.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.