general-video

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONINDIRECT_PROMPT_INJECTIONCREDENTIALS_UNSAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses npx and node to run various scripts and tools, including npx hyperframes for project management and local scripts like frame-packets.mjs for processing. These are vendor-provided resources.
  • [EXTERNAL_DOWNLOADS]: The skill frequently invokes npx hyperframes, which triggers the download and execution of the hyperframes package from the npm registry.
  • [REMOTE_CODE_EXECUTION]: The command npx hyperframes skills update general-video is used to update the skill, which executes remote code from the package registry at runtime. This is part of the vendor's standard maintenance flow.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external, user-controlled files which could contain malicious instructions.
  • Ingestion points: Content is read from BRIEF.md, STORYBOARD.md, and Figma URLs.
  • Boundary markers: There are no explicit delimiters or instructions provided to the agent to treat this data as untrusted or to ignore embedded commands.
  • Capability inventory: The agent has access to shell execution (npx, node) and file system writing.
  • Sanitization: No sanitization of the markdown input is specified before it is processed or passed to sub-agents.
  • [CREDENTIALS_UNSAFE]: The agent is instructed to run npx hyperframes auth status and relay the output verbatim. This poses a potential risk of exposing authentication tokens or session details if the tool's status output includes sensitive information.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:57 PM
Security Audit — agent-trust-hub — general-video