hyperframes-cli

Warn

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The init command automatically fetches and updates AI coding skills from a remote GitHub repository. The instructions explicitly state that the --skip-skills flag is 'neutered' and the check/pull happens regardless of the user's intent, representing a forced remote update of the agent's instructional set.
  • [EXTERNAL_DOWNLOADS]: Several commands perform remote downloads outside of standard package managers:
  • npx hyperframes browser ensure downloads a pinned version of the Chrome browser.
  • npx hyperframes init pulls 'AI coding skills' from GitHub and a 'skills.sh' registry.
  • tts, transcribe, and remove-background commands may download machine learning models on first run.
  • [DATA_EXFILTRATION]: The npx hyperframes publish command uploads the project's source code (HTML and assets) to a public URL. If the project directory contains sensitive information (e.g., .env files, credentials, or private data), this command will exfiltrate that data to a public server.
  • [CREDENTIALS_UNSAFE]: The lambda suite of commands (deploy, render, etc.) interacts with sensitive AWS credential locations such as ~/.aws/credentials. While this is required for the stated functionality, it establishes a pattern of the skill accessing highly sensitive authentication tokens.
  • [INDIRECT_PROMPT_INJECTION]: The skill contains multiple surfaces for indirect prompt injection where untrusted external data is processed:
  • Ingestion points: The capture command fetches content from arbitrary URLs provided by the user or an attacker, and the validate command executes the composition in a headless Chrome instance.
  • Boundary markers: No explicit boundary markers or 'ignore embedded instructions' warnings are documented for the processing of captured HTML.
  • Capability inventory: The skill possesses significant capabilities including file writing, network operations (publish), and cloud deployment (lambda), which could be abused if an injected instruction is executed during the capture or validation phase.
  • Sanitization: There is no mention of sanitizing or escaping the HTML content captured from remote URLs before it is processed by the toolchain.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 15, 2026, 12:20 AM