Back to skill

Security audit

Youtube Watcher 1.0.0

Security checks for vulnerabilities and agentic risk

Overview

This skill has a coherent YouTube-transcript purpose, but it runs a broad network-capable downloader on user-supplied URLs without restricting them to YouTube.

Review this before installing if your agent runs with access to private networks or sensitive local context. Use it only for YouTube URLs, prefer a trusted pinned yt-dlp installation, and consider adding URL allowlisting before relying on it in higher-trust environments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/get_transcript.py:40
Finding

Unrestricted User-Supplied URL Passed to a Network-Capable Downloader

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
SKILL.md:13
Finding

Unpinned Third-Party Downloader Dependency

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (3)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes a local Python script and depends on an external binary (yt-dlp), which means it can read local files and execute shell-accessible tooling, yet it declares no explicit tool scope or permissions boundary. Without an allowlist, an agent framework may grant broader-than-necessary capabilities, increasing the chance of unintended command execution or file access if the skill is misused or modified.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The trigger phrases include generic terms like summarize video and analyze video, which can match many unrelated user requests and cause this skill to activate outside its intended YouTube-transcript context. Over-broad routing can expose shell/file-reading behavior more often than necessary and may lead the agent to fetch remote content or invoke local tooling when a simpler, safer response would suffice.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/get_transcript.py (reported line 52)May include surrounding context.

python
]
        
        try:
            subprocess.run(cmd, cwd=temp_dir, check=True, capture_output=True)
        except subprocess.CalledProcessError as e:
            print(f"Error running yt-dlp: {e.stderr.decode()}", file=sys.stderr)
            sys.exit(1)

Static analysis

No suspicious patterns detected.