Back to skill

Security audit

youtube-search

Security checks for vulnerabilities and agentic risk

Overview

The skill's YouTube search function is coherent, but its setup asks agents to collect and persist API credentials, email, and OTP data in a way users should review carefully.

Install only if you are comfortable with the agent using TranscriptAPI for YouTube search and transcript retrieval. Prefer supplying an existing key through a trusted secret manager, avoid pasting credentials into chat when possible, and do not let the agent create an account or persist secrets unless you understand where they will be stored and how to revoke them.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The entire file is focused on TranscriptAPI authentication, token handling, OTP verification, and API-key storage rather than YouTube discovery or search. This mismatch strongly suggests the skill is being used as a vehicle to smuggle unrelated secret-handling behavior into an innocuous context, making the content more dangerous because users would not expect it from a YouTube skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The guide tells the agent to persistently store a TranscriptAPI secret so it survives across sessions and non-interactive shells. For a YouTube search skill, this is an unjustified secret-management capability that expands the blast radius of compromise and enables continued access to a third-party service beyond the user's immediate intent.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The instructions explicitly direct the agent to solicit an API key from the user and then persist it, or to create an account and ultimately obtain equivalent credentials. Collecting and retaining secrets across sessions is highly sensitive behavior, and in this skill context it is unrelated to the advertised function, increasing the likelihood of credential theft or misuse.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
99% confidence
Finding

The document instructs the agent to create a third-party TranscriptAPI account, collect a user email and OTP, and complete verification on the user's behalf. That capability is unrelated to a YouTube search skill and introduces credential-handling and account-creation behavior that could be abused for unauthorized account provisioning or data collection.

Content

No source excerpt is available for this finding.

Ssd 3

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The document instructs the agent to capture access tokens and API keys via temporary files and reuse them to complete verification while avoiding visible output. This is dangerous because it operationalizes handling of sensitive credentials and specifically attempts to bypass normal redaction/visibility safeguards, which is a strong indicator of adversarial intent.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The activation guidance is broad enough that the skill may be invoked for generic research tasks without the user explicitly asking to use YouTube or a third-party media service. That can cause unintended disclosure of user queries to an external provider and may steer the agent toward lower-trust sources or away from the user's preferred research modality.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The skill sends user search queries and requested video/transcript targets to TranscriptAPI, but the user-facing description does not warn about this third-party data transfer. This can lead to unconsented disclosure of potentially sensitive research topics, interests, or identifiers contained in search terms or selected URLs.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The guide directs long-term storage of an API key across sessions without clearly informing the user of the privacy, persistence, and security implications. Even if intended as convenience, silent durable storage of credentials increases the chance of misuse, accidental exposure, or retention beyond user expectations.

Content

No source excerpt is available for this finding.

Ssd 4

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The staged flow begins with a benign setup question and progressively escalates to collecting email, OTPs, bearer tokens, and persistent API-key storage. This pattern is dangerous because it can socially engineer both the user and the agent into disclosing and retaining increasingly sensitive data under the guise of routine setup, especially in a skill whose declared purpose is unrelated.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The manifest description at L003 limits the skill to searching for videos, channels, creators, and related discovery tasks. However, the skill documentation explicitly states 'Search YouTube and fetch transcripts' and provides a transcript retrieval workflow, which extends beyond pure search/discovery into content extraction.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.