T09 · Insecure Skill Coding Practices
- Location
scripts/get_transcript.py:40- Finding
Unrestricted User-Supplied URL Passed to a Network-Capable Downloader
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This skill has a coherent YouTube-transcript purpose, but it runs a broad network-capable downloader on user-supplied URLs without restricting them to YouTube.
Review this before installing if your agent runs with access to private networks or sensitive local context. Use it only for YouTube URLs, prefer a trusted pinned yt-dlp installation, and consider adding URL allowlisting before relying on it in higher-trust environments.
scripts/get_transcript.py:40Unrestricted User-Supplied URL Passed to a Network-Capable Downloader
SKILL.md:13Unpinned Third-Party Downloader Dependency
The skill invokes a local Python script and depends on an external binary (yt-dlp), which means it can read local files and execute shell-accessible tooling, yet it declares no explicit tool scope or permissions boundary. Without an allowlist, an agent framework may grant broader-than-necessary capabilities, increasing the chance of unintended command execution or file access if the skill is misused or modified.
The trigger phrases include generic terms like summarize video and analyze video, which can match many unrelated user requests and cause this skill to activate outside its intended YouTube-transcript context. Over-broad routing can expose shell/file-reading behavior more often than necessary and may lead the agent to fetch remote content or invoke local tooling when a simpler, safer response would suffice.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
]
try:
subprocess.run(cmd, cwd=temp_dir, check=True, capture_output=True)
except subprocess.CalledProcessError as e:
print(f"Error running yt-dlp: {e.stderr.decode()}", file=sys.stderr)
sys.exit(1)
No suspicious patterns detected.