Sadly, this is the moment where the terms of service that do permit such work would have been precisely what we need to counter the direction of the entire post. I hope you or someone are able to discover it and cite it here. (I couldn’t manage to find the terms from my device, but that’s likely more my device’s fault than any. I’ll try again later if I remember, but it might be too late for today’s comment.)
On this page (https://support.google.com/youtube/answer/2801964?hl=en) of the Community Guidelines they say you may not post “Instructional hacking and phishing [content]: Showing users how to bypass secure computer systems or steal user credentials and personal data.”
Interpret that how you will. It seems broad enough to include academic/security work.