youtube-clipper

Warn

Audited by Snyk on Feb 16, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill downloads arbitrary public YouTube videos and subtitles via scripts/download_video.py (user‑supplied URLs) and then exposes the full subtitle text and translation batches to the agent for AI analysis (scripts/analyze_subtitles.py, scripts/translate_subtitles.py, scripts/generate_summary.py), so the agent is explicitly expected to read and interpret untrusted, user-generated third‑party content.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 16, 2026, 12:42 AM