ai-smithery-kirbah-mcp-youtube
Do not install from this profile alone. High-impact signals or incomplete controls/evidence require manual review.
Source: https://github.com/kirbah/mcp-youtube
Registry: ai.smithery/kirbah-mcp-youtube 0.2.6
Registry: ai.smithery/kirbah-mcp-youtube 0.2.6
Connection signal
Do not install from this profile alone. High-impact signals or incomplete controls/evidence require manual review.
Observed tools
- None observed in this static profile.
Top findings
- Install risk pattern: curl_pipe_shell — install_nvm.sh:6
- References credential or secret pattern: DATABASE_URL — .gemini/settings.json:8
- Detected capability: environment_access — src/index.ts:31
Recommended controls
- Install in a sandbox before team or production use.
- Pin the exact package/repository version.
- Review install scripts, Dockerfile behavior, and dependency pins.
- Do not use production credentials during first install.
- Restrict filesystem, repository, cloud, and database scope.
- Require human approval for destructive actions.