hyperframes-cli

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on executing various CLI tools for video processing and cloud management, including npx hyperframes, ffmpeg, docker, terraform, gcloud, and aws sam. All command usage is consistent with its stated purpose as a development and rendering utility.
  • [EXTERNAL_DOWNLOADS]: The tool performs legitimate downloads of essential components, such as a pinned version of Chromium for consistent rendering, machine learning models for on-device search and transcription, and project templates from the vendor's GitHub repositories. These operations target trusted or well-known services.
  • [CREDENTIALS_UNSAFE]: The skill manages cloud credentials for HeyGen (~/.heygen/credentials) and AWS (~/.aws/credentials) to facilitate cloud-based rendering. The documentation provides clear guidance on secure management and standard location of these secrets.
  • [DATA_EXFILTRATION]: While the skill includes a feedback mechanism that sends data to a public channel, it includes rigorous instructions for users to anonymize reproduction packets, redact personal identifiers/secrets, and use structural anatomies to prevent the exposure of sensitive composition data.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests external data through the capture command (URLs) and variable-driven rendering. It includes mitigation features such as schema validation (--strict-variables) and boundary markers in its auditing logic to handle untrusted input safely.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — hyperframes-cli