hyperframes-audio

Warn

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]: The script scripts/carve.mjs dynamically loads Node.js modules from the target project's local node_modules directory using import() on computed paths. This behavior, facilitated by the loadCore function, allows for the execution of code from the file system based on input arguments.
  • [COMMAND_EXECUTION]: The decode function in scripts/carve.mjs uses execFileSync to run the ffmpeg system binary. This enables the skill to execute external processes with arguments derived from the provided composition HTML.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and parses HTML files and media assets to generate audio processing configurations. While it escapes attributes when writing back to the HTML file, the reliance on external project files for determining processing logic introduces an attack surface where malicious input content could influence agent-driven file modifications.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — hyperframes-audio