Back to skill

Security audit

Youtube Transcript Api

Security checks for vulnerabilities and agentic risk

Overview

This skill is a straightforward guide for using a third-party YouTube transcript API, with expected network/API-key use and no hidden execution or persistence.

Install only if you are comfortable sending YouTube video URLs or IDs and transcript options to youtubetranscript.dev with your API key. Prefer direct HTTPS examples for minimal dependency exposure, pin/review the npm SDK if you use it, and use ASR webhooks only with trusted HTTPS endpoints under your control.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:98
Finding

Unpinned Third-Party npm SDK Creates Supply-Chain Execution Risk

Content
View full analysis

Vulnerability Details

File Location: SKILL.md, lines 98-105
Vulnerability Type: Unpinned and unnecessary third-party dependency installation
Risk Level: Medium

Vulnerable Code

markdown
### Using the Node.js SDK

```bash
npm install youtube-audio-transcript-api
javascript
import { YouTubeTranscript } from "youtube-audio-transcript-api";
text

### Technical Analysis

The Skill instructs users to install `youtube-audio-transcript-api` from the npm registry without specifying an exact version, integrity hash, lockfile, or reviewed source revision. Consequently, the package content resolved when the command is run can differ from the content available when the Skill was audited.

An npm installation can execute package lifecycle scripts, including scripts supplied by transitive dependencies. If the package, its publishing account, or a dependency is compromised, installation may execute attacker-controlled code with the privileges of the user running npm.

This dependency is not required for the Skill's core functionality because `SKILL.md` already documents direct HTTPS requests to the transcript API. Recommending an additional executable dependency therefore expands the trusted computing base beyond the minimum privileges and components necessary.

There is no evidence in the reviewed project that the currently published package is malicious. The vulnerability is the unpinned, unverified installation process and the resulting mutable supply-chain exposure.

### Attack Path

1. An attacker compromises the npm publisher account, package repository, release pipeline, or one of the package's transitive dependencies.
2. The attacker publishes a malicious package version or dependency release containing a lifecycle script or malicious runtime code.
3. A user follows the Skill's unpinned `npm install youtube-audio-transcript-api` instruction.
4. npm resolves and downloads the attacker-controlled release.
5. Malicious lifecycle code ma
...[truncated 842 chars]
Remediation
View remediation

Remediation Suggestions

  1. Prefer the documented direct HTTPS integration and remove the optional SDK installation instruction where it is not necessary.
  2. If the SDK must be supported, pin it to an exact reviewed version rather than allowing npm to resolve the latest compatible release.
  3. Commit and enforce a lockfile with integrity metadata, and use npm ci in controlled environments.
  4. Verify the package publisher, source repository, release provenance, and dependency tree before recommending it.
  5. Enable dependency scanning and monitor the package and its transitive dependencies for ownership changes, advisories, and unexpected releases.
  6. Where compatible with the package, install with lifecycle scripts disabled, such as npm install --ignore-scripts, and document any resulting limitations.
  7. Run installation and SDK execution in a sandbox with minimal filesystem, environment-variable, credential, and network access.
  8. Avoid exposing the transcript API key through broadly inherited environment variables; provide it only to the process that requires it.
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (6)

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
API_KEY = "your_api_key"

response = requests.post(
    "https://youtubetranscript.dev/api/v2/transcribe",
    headers={
        "Authorization": f"Bearer {API_KEY}",

External Transmission

Medium
Category
Data Exfiltration
Confidence
70% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 69)May include surrounding context.

md
API_KEY = "your_api_key"

response = requests.post(
    "https://youtubetranscript.dev/api/v2/transcribe",
    headers={
        "Authorization": f"Bearer {API_KEY}",

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 86)May include surrounding context.

Basic Transcript Extraction (JavaScript/Node.js)

javascript
const response = await fetch("https://youtubetranscript.dev/api/v2/transcribe", {
  method: "POST",
  headers: {
    Authorization: `Bearer ${API_KEY}`,

External Transmission

Medium
Category
Data Exfiltration
Confidence
60% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · SKILL.md (reported line 128)May include surrounding context.

Basic Transcript Extraction (cURL)

bash
curl -X POST https://youtubetranscript.dev/api/v2/transcribe \
  -H "Authorization: Bearer YOUR_API_KEY" \
  -H "Content-Type: application/json" \
  -d '{"video": "dQw4w9WgXcQ"}'

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The ASR workflow documents use of a webhook_url for asynchronous delivery but does not warn that transcript content will be pushed to another external endpoint designated by the user. This increases data exposure risk because potentially sensitive transcript text may be delivered to an unintended, insecure, or attacker-controlled endpoint.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The skill explicitly instructs use of a third-party API for transcript extraction but does not clearly warn that YouTube video identifiers, requested transcript parameters, and authentication tokens will be sent off-platform. This is a real transparency/privacy issue because users may not realize their inputs are transmitted to an external service, though the transmitted data is generally limited to expected API request contents.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.