hyperframes-cli
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill relies on executing various CLI tools for video processing and cloud management, including
npx hyperframes,ffmpeg,docker,terraform,gcloud, andaws sam. All command usage is consistent with its stated purpose as a development and rendering utility. - [EXTERNAL_DOWNLOADS]: The tool performs legitimate downloads of essential components, such as a pinned version of Chromium for consistent rendering, machine learning models for on-device search and transcription, and project templates from the vendor's GitHub repositories. These operations target trusted or well-known services.
- [CREDENTIALS_UNSAFE]: The skill manages cloud credentials for HeyGen (
~/.heygen/credentials) and AWS (~/.aws/credentials) to facilitate cloud-based rendering. The documentation provides clear guidance on secure management and standard location of these secrets. - [DATA_EXFILTRATION]: While the skill includes a feedback mechanism that sends data to a public channel, it includes rigorous instructions for users to anonymize reproduction packets, redact personal identifiers/secrets, and use structural anatomies to prevent the exposure of sensitive composition data.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests external data through the
capturecommand (URLs) and variable-driven rendering. It includes mitigation features such as schema validation (--strict-variables) and boundary markers in its auditing logic to handle untrusted input safely.
Audit Metadata