hyperframes-animation
Warn
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: MEDIUMREMOTE_CODE_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill's auditing tool, "animation-map.mjs", dynamically installs required Node.js packages ("@hyperframes/producer", "@hyperframes/core") from the NPM registry at runtime. The installation logic in "scripts/package-loader.mjs" executes "npm install" and subsequently loads the downloaded modules into the process. The script fallback to "@latest" versions for these packages represents a supply chain risk.
- [DYNAMIC_EXECUTION]: The "scripts/package-loader.mjs" script restarts the Node.js process using "spawnSync" to include a temporary "node_modules" directory in the environment. This allows the skill to execute code that was not present at the time of initial execution.
- [INDIRECT_PROMPT_INJECTION]: The "animation-map.mjs" script acts as a surface for indirect prompt injection by extracting raw element identifiers, specifically "id" attributes, from user-provided HTML composition files and including them in an audit report. This report is intended for interpretation by an AI agent, and the lack of sanitization or boundary markers around these identifiers creates a surface where maliciously crafted HTML could be used to influence the agent's behavior.
- Ingestion points: "scripts/animation-map.mjs" reads content from a user-specified composition directory.
- Boundary markers: The audit report does not use delimiters or isolation warnings for extracted identifiers.
- Capability inventory: The skill executes JavaScript in a headless browser and has the ability to spawn system processes and write to the filesystem.
- Sanitization: The script collects raw element IDs from the DOM without validation or escaping.
- [COMMAND_EXECUTION]: The skill spawns subprocesses to execute system commands, such as "npm" for dependency management and "node" for process re-execution.
- [EXTERNAL_DOWNLOADS]: The skill performs network requests to the NPM registry to download required dependency packages during the bootstrap process.
Audit Metadata