Back to skill

Security audit

YouTube Watcher

Security checks for vulnerabilities and agentic risk

Overview

This is a disclosed YouTube transcript helper with some dependency and URL-scoping caveats, but no hidden persistence, credential access, destructive behavior, or exfiltration was found.

Install only if you are comfortable letting the agent run yt-dlp and make outbound network requests for video subtitles. Prefer using it with explicit, trusted YouTube URLs, and consider pinning/verifying yt-dlp or adding URL allowlisting before using it in sensitive network environments.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:11
Finding

Unpinned Third-Party Executable Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Warning
Location
scripts/get_transcript.py:40
Finding

Unrestricted URL Forwarding to a General-Purpose Network Downloader

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
Findings (5)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
91% confidence
Finding

The skill invokes a local Python script and depends on an external binary (yt-dlp), which implies shell execution and file access, but it does not declare any explicit tool scope such as permissions or allowed-tools. This weakens containment and reviewability because the runtime capabilities are broader than what is documented, increasing the chance of unintended command execution or file access through the skill path.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase summarize video is overly broad for a YouTube transcript skill and may cause the agent to invoke this skill for unrelated video-analysis requests. That can lead to inappropriate tool use, unnecessary external fetching, and user-intent confusion, especially when a request is not specifically about YouTube or transcripts.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The trigger phrase analyze video is ambiguous and much broader than the skill's actual function of fetching YouTube transcripts. In context, this mismatch is more dangerous because the skill has shell and file-read capabilities; broad activation criteria raise the likelihood of unnecessary or incorrect privileged execution.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/get_transcript.py (reported line 52)May include surrounding context.

python
]
        
        try:
            subprocess.run(cmd, cwd=temp_dir, check=True, capture_output=True)
        except subprocess.CalledProcessError as e:
            print(f"Error running yt-dlp: {e.stderr.decode()}", file=sys.stderr)
            sys.exit(1)

Natural-Language Policy Violations

Low
Category
Not specified by scanner
Confidence
95% confidence
Finding

The subprocess command hard-codes --sub-lang en, which constrains output to English regardless of user preference. This is a natural-language locale policy concern because the script does not offer opt-in, fallback behavior, or any documented reason for enforcing English only.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.