Fetch web content in multiple formats - HTML, JSON, plain text, Markdown, readable articles, and YouTube transcripts
79
99%
Does it follow best practices?
Run evals on this skill
Adds up to 20 points to the overall score
View guide
Low
Low-risk findings worth noting
Low
Low-risk findings.
1 low severity finding. Worth noting, but not necessarily harmful.
The skill exposes the agent to untrusted, user-generated content from public third-party sources, creating a risk of indirect prompt injection. This includes browsing arbitrary URLs, reading social media posts or forum comments, and analyzing content from unknown websites.
The required workflow uses MCP web-fetch tools (e.g., `mcp__fetch__fetch_markdown` / `fetch_readable` / `fetch_txt`) to retrieve and convert arbitrary public web pages or transcripts into LLM-readable text at runtime, which is outsider-authored content.
youtube.com
domain · 3 sites
The plugin uses mcp__fetch__fetch_youtube_transcript to fetch YouTube video transcripts from youtube.com (or youtu.be) at runtime, ingesting outsider-authored transcript content.
SKILL.md
17
- Downloading YouTube video transcripts
SKILL.md
29
| `mcp__fetch__fetch_youtube_transcript` | YouTube video transcripts by video URL or ID |
SKILL.md
42
- **YouTube videos**: `fetch_youtube_transcript`