css-animations
Pass
Audited by Gen Agent Trust Hub on Aug 1, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs users to run
npx hyperframes lintandnpx hyperframes validate. These are standard command-line operations for validating CSS code within the HyperFrames ecosystem. - [EXTERNAL_DOWNLOADS]: The documentation includes passive links to official Mozilla Developer Network (MDN) pages. These are trusted technical references and do not involve programmatic data exfiltration or remote code execution.
- [PROMPT_INJECTION]: The file
skill-report.jsoncontains a pre-authored security audit stating the skill is safe and characterizing findings as false positives. This constitutes a self-referential injection attempt (Category 8e) designed to override independent security analysis. 1. Ingestion points: Metadata fields inskill-report.json. 2. Boundary markers: Absent. 3. Capability inventory: Security scanner processing of skill packages. 4. Sanitization: None.
Audit Metadata