On one hand people tend to side with youtube-dl, because everybody claims they did nothing wrong. But it can be argued that the testsuite (and CI pipeline) is the responsibility of the person who implemented. And I agree with that point.
From youtube-dl's perspective, this is an unnecessary attack surface that can be easily removed. I mean, this was bound to happen at some point, don't kid yourself.
With a project so big, I think it is irresponsible to not care for its legality. I mean, they could have just prevented this with a supersimple fix.
0. Use only CC licensed content in testsuite. If necessary, open up your own youtube-dl-tests channel and upload a video of your dog or cat. It just takes less than an hour.
1. Implement a license check, required by all plugins. Default to proprietary if none given. If proprietary, provide a url to Terms Of Service.
2. Let the end user manually confirm that the license is XYZ once it is proprietary and not public domain or CC based. Do this with every download.
3. Introduce a CLI flag like "--agree-to-license" in order to skip that.
4. Document this under legal compliance in the readme, and state that youtube-dl does in good faith try to comply with legal requirements, but that the responsibility is the action of its users that it cannot influence.
Boom. Plausible deniability, and RIAA would have not a single basis for the case.
I mean, this would have been so easy to implement. I don't understand why this wasn't integrated.