hyperframes-cli
Warn
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
- [REMOTE_CODE_EXECUTION]: The
initcommand automatically fetches and updates AI coding skills from a remote GitHub repository. The instructions explicitly state that the--skip-skillsflag is 'neutered' and the check/pull happens regardless of the user's intent, representing a forced remote update of the agent's instructional set. - [EXTERNAL_DOWNLOADS]: Several commands perform remote downloads outside of standard package managers:
npx hyperframes browser ensuredownloads a pinned version of the Chrome browser.npx hyperframes initpulls 'AI coding skills' from GitHub and a 'skills.sh' registry.tts,transcribe, andremove-backgroundcommands may download machine learning models on first run.- [DATA_EXFILTRATION]: The
npx hyperframes publishcommand uploads the project's source code (HTML and assets) to a public URL. If the project directory contains sensitive information (e.g.,.envfiles, credentials, or private data), this command will exfiltrate that data to a public server. - [CREDENTIALS_UNSAFE]: The
lambdasuite of commands (deploy, render, etc.) interacts with sensitive AWS credential locations such as~/.aws/credentials. While this is required for the stated functionality, it establishes a pattern of the skill accessing highly sensitive authentication tokens. - [INDIRECT_PROMPT_INJECTION]: The skill contains multiple surfaces for indirect prompt injection where untrusted external data is processed:
- Ingestion points: The
capturecommand fetches content from arbitrary URLs provided by the user or an attacker, and thevalidatecommand executes the composition in a headless Chrome instance. - Boundary markers: No explicit boundary markers or 'ignore embedded instructions' warnings are documented for the processing of captured HTML.
- Capability inventory: The skill possesses significant capabilities including file writing, network operations (
publish), and cloud deployment (lambda), which could be abused if an injected instruction is executed during the capture or validation phase. - Sanitization: There is no mention of sanitizing or escaping the HTML content captured from remote URLs before it is processed by the toolchain.
Audit Metadata