wjs-uploading-video — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited wjs-uploading-video (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Push finished videos to YouTube. Defaults are tuned for this user's workflow (王建硕 channel, China network with local proxy, 1080p horizontal recordings from Riverside / multicam edits).
.mp4 files and wants them on YouTubefinal/ directory with multiple segments and an UPLOAD_META.mdDon't use for:
wjs-reframing-video first to produce the 9:16 cut, then upload that via this skill)~/.config/youtube/credentials.json must exist. See references/credentials-setup.md for the 5-minute setup if missing.pip3 install google-auth-oauthlib google-api-python-client requests (only google-auth + requests are strictly needed at upload time, but the OAuth-lib pulls them).~/.config/youtube/token.json. Subsequent runs reuse it silently.YouTube's resumable upload protocol issues a Location: URL after the metadata POST, then accepts the bytes in chunked PUT requests. The stock google-api-python-client runs this over httplib2, which under this user's local SOCKS+HTTP proxy stack throws [Errno 65] No route to host or socket.timeout on those follow-up PUTs and stalls indefinitely.
This skill bypasses httplib2: it does OAuth via google-auth, then drives the resumable upload manually with requests, passing the proxy explicitly. 8 MB chunks (not the stock 256 KB) — fewer round-trips through the proxy. Exponential-backoff retry on socket.timeout / ConnectionError / 5xx.
If you're tempted to "just call the YouTube API client directly," don't — it'll fail in this environment.
final/ directorypython3 ~/.claude/skills/wjs-uploading-video/scripts/upload_youtube.py \
--dir "/path/to/final" \
--meta "/path/to/final/UPLOAD_META.md"The script:
UPLOAD_META.md and pairs each ## NN · filename.mp4 block to a video file in --dir--results-file (default <dir>/.youtube_upload_results.json) — safe to re-run after failures--results-filepython3 ~/.claude/skills/wjs-uploading-video/scripts/upload_youtube.py \
--video /path/to/clip.mp4 \
--title "My Title" \
--description "Body text" \
--tags "tag1,tag2,tag3"| Flag | Default | Notes |
|---|---|---|
--privacy | public | private / unlisted / public |
--category | 28 | 28 = Science & Tech. 27 = Education. 24 = Entertainment. |
--made-for-kids | false | YouTube requires this declaration |
--playlist <ID> | none | Add each uploaded video to a playlist |
--publish-at <ISO8601> | none | Schedule publish (requires --privacy private) |
--credentials | ~/.config/youtube/credentials.json | OAuth client JSON |
--token | ~/.config/youtube/token.json | Cached OAuth token |
--chunk-mb | 8 | Smaller chunks if uploads keep failing mid-flight |
--dry-run | off | Parse meta + list what would upload, don't touch network |
The parser expects the user's standard structure:
## 01 · segment_01_no-bugs.mp4
**短标题**
代码没有错误,只有意图不一致
**视频描述**
AI 时代屎山的重新定义...
—— 王建硕 × 任鑫《...》第 1 集
#王建硕 #AI编程 #ClaudeCode
---Mapping:
## NN · <filename> → which video this block describes**短标题** (or **Title**) block → YouTube title, verbatim. Short titles work but consider that YouTube allows up to 100 chars — if you want a richer title with series name, write it that way in **短标题****视频描述** (or **Description**) block → YouTube description, verbatim, with the #tag hashtags retained at the bottom#word tokens in the 视频描述 → comma-separated YouTube tags (each # is stripped; the user's channel name 王建硕 is auto-prepended per global instructions)Filename in the heading must match an actual file in --dir. If a file exists but has no meta block, the script errors loudly — pass --allow-missing-meta to upload it with --title <basename> and empty description.
--privacy unlisted (link-only) or --privacy private (owner-only) when you want to review first--category per uploadIf you write description footers, signatures, or "subscribe to me" lines into a video's metadata, use 王建硕 (the user's channel name). Don't put a guest's name there — guests like 任鑫 belong inside the description body when they're the conversation partner, never in the channel-CTA slot.
| Symptom | Fix |
|---|---|
access_denied 403 on consent screen | Add user's Google account to the OAuth client's Test users list in Google Cloud Console |
[Errno 65] No route to host mid-upload | Almost always a proxy issue — verify curl --max-time 10 https://upload.googleapis.com/upload/youtube/v3/videos returns a 4xx (any 4xx = proxy reachable); if 000, the proxy is down |
| Upload stalls with no progress lines | The proxy is silently buffering. Lower --chunk-mb 4 or restart the proxy daemon |
quotaExceeded (API units) | YouTube Data API default quota is 10,000 units/day, each upload is 1,600 units — so ~6 uploads/day. Request a quota bump in Google Cloud Console, or split uploads across days |
429 rateLimitExceeded · Video Uploads per day | A DIFFERENT, separate limit from API units — YouTube's per-project daily video-upload count (anti-abuse, tied to project verification status; can be very low). When hit, every upload in the batch fails init session failed: 429, none succeed. It is NOT a proxy/auth problem and can't be worked around. It resets at midnight US Pacific Time (not your local midnight). Options: wait for the PT reset and re-run (the results file was cleared so all retry); or upload via the YouTube Studio web UI, which does NOT consume this API limit; or get the GCP project verified to raise the cap. Earlier uploads the same PT-day (even manual API ones) eat into this count. |
| Token refresh fails | Delete ~/.config/youtube/token.json and re-run; OAuth browser flow restarts |
--results-file (JSON: file, title, video id, URL)public by default — they're live the moment the upload completes. If the user wanted a review buffer, mention they can re-upload with --privacy unlisted (or flip back to unlisted in YouTube Studio)~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.