T08 · Insecure Dependencies
- Location
SKILL.md:11- Finding
Unpinned Third-Party Executable Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
This is a disclosed YouTube transcript helper with some dependency and URL-scoping caveats, but no hidden persistence, credential access, destructive behavior, or exfiltration was found.
Install only if you are comfortable letting the agent run yt-dlp and make outbound network requests for video subtitles. Prefer using it with explicit, trusted YouTube URLs, and consider pinning/verifying yt-dlp or adding URL allowlisting before using it in sensitive network environments.
SKILL.md:11Unpinned Third-Party Executable Dependency
scripts/get_transcript.py:40Unrestricted URL Forwarding to a General-Purpose Network Downloader
The skill invokes a local Python script and depends on an external binary (yt-dlp), which implies shell execution and file access, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens containment and reviewability because the runtime capabilities are broader than what is documented, increasing the chance of unintended command execution or file access through the skill path.
The trigger phrase summarize video is overly broad for a YouTube transcript skill and may cause the agent to invoke this skill for unrelated video-analysis requests. That can lead to inappropriate tool use, unnecessary external fetching, and user-intent confusion, especially when a request is not specifically about YouTube or transcripts.
The trigger phrase analyze video is ambiguous and much broader than the skill's actual function of fetching YouTube transcripts. In context, this mismatch is more dangerous because the skill has shell and file-read capabilities; broad activation criteria raise the likelihood of unnecessary or incorrect privileged execution.
subprocess module calls execute external commands. Without careful input validation, this enables command injection.
]
try:
subprocess.run(cmd, cwd=temp_dir, check=True, capture_output=True)
except subprocess.CalledProcessError as e:
print(f"Error running yt-dlp: {e.stderr.decode()}", file=sys.stderr)
sys.exit(1)
The subprocess command hard-codes --sub-lang en, which constrains output to English regardless of user preference. This is a natural-language locale policy concern because the script does not offer opt-in, fallback behavior, or any documented reason for enforcing English only.
No suspicious patterns detected.