youtube-data-mcp-server
v1.0.16YouTube MCP Server Implementation
10
Total
4
Critical
5
High
1
Medium
Findings
unknownEnvironment file access
Detected by automated pattern matching (rule DE-002) with medium confidence. May be a false positive.
11: }
12: // Default subtitle language setting
>>> 13: const defaultTranscriptLang = process.env.YOUTUBE_TRANSCRIPT_LANG || 'ko';
14: async function main() {
15: const videoManager = new VideoManagement();Report false positiveEnvironment file access
Detected by automated pattern matching (rule DE-002) with medium confidence. May be a false positive.
8: this.youtube = google.youtube({
9: version: 'v3',
>>> 10: auth: process.env.YOUTUBE_API_KEY
11: });
12: }Report false positiveEnvironment file access
Detected by automated pattern matching (rule DE-002) with medium confidence. May be a false positive.
58: const transcript = await getSubtitles({
59: videoID: videoId,
>>> 60: lang: lang || process.env.YOUTUBE_TRANSCRIPT_LANG || 'en'
61: });
62: return transcript;Report false positiveEnvironment file access
Detected by automated pattern matching (rule DE-002) with medium confidence. May be a false positive.
6: import { z } from "zod";
7: // Environment variable validation
>>> 8: if (!process.env.YOUTUBE_API_KEY) {
9: console.error('Error: YOUTUBE_API_KEY environment variable is not set.');
10: process.exit(1);Report false positiveDecoded base64 content: J�b�'���ӭ�즊�
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: ��B���zT�jج�',
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: J�b�'���ӭ�즊�
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: ��B���zT�jج�',
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveDecoded base64 content: ��B���zT�jج�',
Detected by automated pattern matching (rule DO-BAS) with medium confidence. May be a false positive.
Report false positiveHigh-entropy string (4.9 bits/char) — possible encoded payload
Detected by automated pattern matching (rule EN-001) with medium confidence. May be a false positive.
Report false positiveScan History
| Date | Risk | Findings | Files | Duration |
|---|---|---|---|---|
| Feb 25, 2026 | critical | 10 | 9 | 0.00s |
| Feb 23, 2026 | critical | 10 | 9 | 0.00s |
| Feb 22, 2026 | critical | 10 | 9 | 0.00s |