Back to skill

Security audit

YouTube Media Downloader

Security checks for vulnerabilities and agentic risk

Overview

The skill does what it claims, but it automatically downloads and runs third-party executable tools without verification or clear user approval.

Review this before installing. The skill is not showing exfiltration, destructive actions, or privilege escalation, but it can automatically install and run yt-dlp and ffmpeg binaries from third-party GitHub release URLs. Prefer using it only after installing those dependencies yourself from trusted sources, or require the publisher to pin versions, verify checksums or signatures, and ask before downloading executables.

Vulnerability Patterns
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Findings (2)

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/download_media.sh:78
Finding

Unverified Remote Executable Retrieval and Execution in Single-Media Downloader

Content
View full analysis
/dev/null; then if [ -f "$HOME/yt-dlp" ]; then YT_DLP="$HOME/yt-dlp" else echo "Installing yt-dlp to ~/yt-dlp..." curl -L https://github.com/yt-dlp/yt-dlp/releases/latest/download/yt-dlp -o "$HOME/yt-dlp" chmod +x "$HOME/yt-dlp" YT_DLP="$HOME/yt-dlp" fi else YT_DLP="yt-dlp" fi # Check if ffmpeg exists (needed for MP3 conversion) if ! command -v ffmpeg &> /dev/null; then if [ -f "$HOME/ffmpeg-portable/bin/ffmpeg" ]; then FFMPEG_PATH="$HOME/ffmpeg-portable/bin" echo "Using existing ffmpeg at $FFMPEG_PATH" else echo "Installing ffmpeg for audio conversion..." mkdir -p "$HOME/ffmpeg-portable" cd "$HOME/ffmpeg-portable" curl -L https://github.com/BtbN/FFmpeg-Builds/releases/download/latest/ffmpeg-master-latest-linux64-gpl.tar.xz -o ffmpeg.tar.xz tar -xf ffmpeg.tar.xz --strip-components=1 rm -f ffmpeg.tar.xz cd - > /dev/null FFMPEG_PATH="$HOME/ffmpeg-portable/bin" echo "ffmpeg installed to $FFMPEG_PATH" fi export PATH="$FFMPEG_PATH:$PATH" else echo "Using system ffmpeg" fi ``` The downloaded `yt-dlp` executable is subsequently invoked at `scripts/download_media.sh:135-141` or `scripts/download_media.sh:171-175`. FFmpeg is invoked indirectly by `yt-dlp` during audio extraction. ### Technical Analysis The script automatically downloads executable dependencies through mutable `latest` release URLs. It neither pins an immutable release version nor verifies a cryptographic checksum or publisher signature before making the downloaded `yt-dlp` file executable and running it. The FFmpeg archive is also downloaded from BtbN, a third ...[truncated 2386 chars]
Remediation
View remediation

T03 · Remote Payload Retrieval and Execution

Error
Location
scripts/batch_download.sh:93
Finding

Unverified Remote Executable Retrieval and Execution in Batch Downloader

Content
View full analysis
/dev/null; then if [ -f "$HOME/yt-dlp" ]; then YT_DLP="$HOME/yt-dlp" else echo "Installing yt-dlp to ~/yt-dlp..." curl -L https://github.com/yt-dlp/yt-dlp/releases/latest/download/yt-dlp -o "$HOME/yt-dlp" chmod +x "$HOME/yt-dlp" YT_DLP="$HOME/yt-dlp" fi else YT_DLP="yt-dlp" fi # Check if ffmpeg exists (needed for MP3 conversion) if ! command -v ffmpeg &> /dev/null; then if [ -f "$HOME/ffmpeg-portable/bin/ffmpeg" ]; then FFMPEG_PATH="$HOME/ffmpeg-portable/bin" echo "Using existing ffmpeg at $FFMPEG_PATH" else echo "Installing ffmpeg for audio conversion..." mkdir -p "$HOME/ffmpeg-portable" cd "$HOME/ffmpeg-portable" curl -L https://github.com/BtbN/FFmpeg-Builds/releases/download/latest/ffmpeg-master-latest-linux64-gpl.tar.xz -o ffmpeg.tar.xz tar -xf ffmpeg.tar.xz --strip-components=1 rm -f ffmpeg.tar.xz cd - > /dev/null FFMPEG_PATH="$HOME/ffmpeg-portable/bin" echo "ffmpeg installed to $FFMPEG_PATH" fi export PATH="$FFMPEG_PATH:$PATH" else echo "Using system ffmpeg" fi ``` The selected `yt-dlp` executable is subsequently invoked at `scripts/batch_download.sh:193` or `scripts/batch_download.sh:196`. FFmpeg is invoked indirectly when batch audio extraction requires conversion. ### Technical Analysis The batch downloader independently reproduces the same unsafe dependency-bootstrap process as the single-media downloader. It retrieves mutable `latest` artifacts, makes the `yt-dlp` payload executable, and extracts a third-party FFmpeg build without checksum or signature verification. Consequently, the effective code executed ...[truncated 1991 chars]
Remediation
View remediation
Vulnerability Patterns
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (10)

Tp4

High
Category
MCP Tool Poisoning
Confidence
95% confidence
Finding

The skill claims playlist and batch-download functionality while the detected behavior instead centers on fetching external tools from GitHub and relying on underlying downloader behavior that may not match the declared feature set. Undeclared network access to third-party hosts and misleading capability claims make it harder for users and policy systems to assess risk, especially when executable code is retrieved at runtime.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The skill claims playlist and batch-download functionality while the detected behavior instead centers on fetching external tools from GitHub and relying on underlying downloader behavior that may not match the declared feature set. Undeclared network access to third-party hosts and misleading capability claims make it harder for users and policy systems to assess risk, especially when executable code is retrieved at runtime.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The script downloads executables directly from remote URLs and then executes or places them in the execution path without integrity verification. Automatic remote installation of executable tooling is especially dangerous in a downloader skill because untrusted network retrieval of binaries can turn a simple media operation into arbitrary code execution and persistent compromise of the user's environment.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill advertises shell-driven behavior but does not declare any explicit tool scope or permissions, which weakens enforcement and transparency around what it is allowed to execute. In a skill that invokes scripts and performs downloads, missing scope boundaries increases the chance of unintended command execution or overbroad agent activation without user awareness.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description uses broad activation language for common media and downloader requests, which can cause the skill to trigger in situations broader than users expect. Overly broad invocation criteria are risky here because the skill performs shell operations and may install software, so accidental activation can lead to unanticipated system and network actions.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The markdown omits a clear warning that the skill auto-installs software and downloads portable binaries that modify the local environment. Lack of upfront disclosure undermines informed consent and increases the risk that users will unknowingly run untrusted executables or permit persistent system changes.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script automatically downloads and installs executable dependencies (yt-dlp and ffmpeg) into the user's home directory without integrity verification, signature checking, or explicit consent. This expands the skill from media downloading into software deployment, creating supply-chain and arbitrary code execution risk if the remote binaries or transport path are compromised.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
92% confidence
Finding

The downloader fetches a yt-dlp binary from GitHub Releases and marks it executable automatically. Even though yt-dlp is relevant to the skill's purpose, silently installing and executing a remote binary is dangerous because it trusts external content without validating provenance or integrity.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The script downloads and extracts an ffmpeg archive into the user's home directory, then prepends that path to PATH for subsequent execution. This introduces supply-chain risk and local execution of unverified code, and archive extraction adds further risk if the downloaded artifact is malicious or unexpected.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The script goes beyond downloading media by creating persistent directories under the user's home directory and installing yt-dlp and ffmpeg automatically. This expands the trust boundary from 'use existing tools to download media' to 'download and execute remote binaries', which is risky because compromised release assets, MITM in weaker environments, or unexpected binary behavior could lead to arbitrary code execution or persistent system changes.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.