hyperframes-core
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill implements a multi-agent orchestration workflow where a 'Frame worker' agent receives instructions derived from project files like
STORYBOARD.mdandframe.md. - Ingestion points: The
scripts/lib/frame-packets-core.mjsscript readsSTORYBOARD.mdand other project assets to build 'Frame packets' for sub-agents. - Boundary markers: The system uses a structured role/packet format (e.g.,
_role.md) to provide context and constraints to sub-agents. - Capability inventory: Sub-agents (frame workers) have the capability to write HTML and Javascript files to the
compositions/frames/directory, which are subsequently assembled and rendered by the orchestrator. - Sanitization: The workflow lacks explicit sanitization or filtering for narrative content extracted from the storyboard before it is interpolated into the prompts for sub-agents.
- [DYNAMIC_EXECUTION]: The framework involves the generation and subsequent execution of scripts within HTML documents to drive animations.
- Evidence:
references/frame-worker-core.mdinstructs workers to author sub-compositions that include a GSAP timeline script registered globally. - Evidence:
references/sub-compositions.mdexplains how the runtime clones and executes these scripts during the render process. - This pattern constitutes script generation from templates for the intended purpose of animation rendering.
- [EXTERNAL_DOWNLOADS]: The framework and its documentation reference well-known third-party libraries via Content Delivery Networks (CDNs) for use in the generated HTML compositions.
- Evidence:
references/minimal-composition.mdandreferences/composition-patterns.mdreferencehttps://cdn.jsdelivr.net/npm/gsap@3.14.2/dist/gsap.min.js. - Evidence:
references/tailwind.mdreferences@tailwindcss/browser@4.2.4from a CDN. - These downloads target well-known services and are used for the intended purpose of rendering animations within the compositions.
- [COMMAND_EXECUTION]: The skill instructions and internal scripts utilize the
hyperframes-clitool and other local Node.js scripts to manage project lifecycle and rendering. - Evidence:
SKILL.mddescribes usage ofnpx hyperframes check,npx hyperframes preview, andnpx hyperframes render. - Evidence:
references/brief-contract.mdmentions executing a local scriptnode <MEDIA_DIR>/scripts/prefs.mjsto retrieve preferences. - These commands are standard operations for the framework's build and review process.
Audit Metadata