youtube-research

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). This skill calls TubeLab's public API (e.g., https://public-api.tubelab.net/v1/search/outliers and /v1/video/transcript/{video_id}) and downloads thumbnails and video transcripts (user-generated YouTube content) which the workflow explicitly reads and analyzes, so the agent consumes untrusted third-party content that could carry injected instructions.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 12:26 AM