youtube-transcript

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly fetches transcripts from user-supplied YouTube URLs using yt-dlp (see SKILL.md Step 2 and the fetch-transcript.mjs script) and instructs the agent to read and act on the full transcript to produce summaries and takeaways (see SKILL.md "Step 4: Summarise"), so untrusted, user-generated third‑party content can directly influence agent behavior.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 03:33 AM