hyperframes-fx-x-post

Pass

Audited by Gen Agent Trust Hub on Aug 21, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTION
Full Analysis
  • [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill instructs the user or agent to execute npx hyperframes add x-post. This command downloads and executes code from the public npm registry to add the necessary components. While this is the intended installation mechanism, it introduces an external dependency executed at runtime.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data from X (Twitter) posts, such as profile info and post bodies, for rendering in a UI block. It lacks explicit boundary markers or sanitization procedures to prevent the agent from potentially interpreting instructions embedded in the social media content. Ingestion points include profile data, post body, and stats; the skill's capability involves creating an HTML composition; and no sanitization or delimiters are specified to isolate the external content.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 21, 2026, 06:41 PM
Security Audit — agent-trust-hub — hyperframes-fx-x-post