hyperframes-video

Pass

Audited by Gen Agent Trust Hub on May 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill executes local commands such as git, gh, and npx (specifically the HyperFrames CLI) to retrieve project data and perform video rendering tasks. These operations are directly related to the skill's primary function and project-specific workflows.
  • [EXTERNAL_DOWNLOADS]: The skill uses standard package managers (npm, pnpm, yarn, bun) to install the shiki library as a development dependency for code highlighting within the video compositions.
  • [DATA_EXPOSURE]: The skill scans local repository files (e.g., tailwind.config.js, package.json, app/layout.tsx) to auto-detect branding assets such as logos, colors, and fonts. It includes a dedicated phase (Phase 1.5) to scan for sensitive content (credentials, security patches, or unreleased roadmap items) before processing input data to ensure they are not accidentally included in the video.
  • [PROMPT_INJECTION]: The skill processes untrusted external data from sources like GitHub PRs, blog posts, and changelogs. While this presents an indirect prompt injection surface, the skill implements defensive measures including a sensitive content scan and a grounding step (Phase 3.2b) that verifies synthesized code against the actual codebase's public API.
Audit Metadata
Risk Level
SAFE
Analyzed
May 11, 2026, 10:14 AM
Security Audit — agent-trust-hub — hyperframes-video