hyperframes-core

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill implements a multi-agent orchestration workflow where a 'Frame worker' agent receives instructions derived from project files like STORYBOARD.md and frame.md.
  • Ingestion points: The scripts/lib/frame-packets-core.mjs script reads STORYBOARD.md and other project assets to build 'Frame packets' for sub-agents.
  • Boundary markers: The system uses a structured role/packet format (e.g., _role.md) to provide context and constraints to sub-agents.
  • Capability inventory: Sub-agents (frame workers) have the capability to write HTML and Javascript files to the compositions/frames/ directory, which are subsequently assembled and rendered by the orchestrator.
  • Sanitization: The workflow lacks explicit sanitization or filtering for narrative content extracted from the storyboard before it is interpolated into the prompts for sub-agents.
  • [DYNAMIC_EXECUTION]: The framework involves the generation and subsequent execution of scripts within HTML documents to drive animations.
  • Evidence: references/frame-worker-core.md instructs workers to author sub-compositions that include a GSAP timeline script registered globally.
  • Evidence: references/sub-compositions.md explains how the runtime clones and executes these scripts during the render process.
  • This pattern constitutes script generation from templates for the intended purpose of animation rendering.
  • [EXTERNAL_DOWNLOADS]: The framework and its documentation reference well-known third-party libraries via Content Delivery Networks (CDNs) for use in the generated HTML compositions.
  • Evidence: references/minimal-composition.md and references/composition-patterns.md reference https://cdn.jsdelivr.net/npm/gsap@3.14.2/dist/gsap.min.js.
  • Evidence: references/tailwind.md references @tailwindcss/browser@4.2.4 from a CDN.
  • These downloads target well-known services and are used for the intended purpose of rendering animations within the compositions.
  • [COMMAND_EXECUTION]: The skill instructions and internal scripts utilize the hyperframes-cli tool and other local Node.js scripts to manage project lifecycle and rendering.
  • Evidence: SKILL.md describes usage of npx hyperframes check, npx hyperframes preview, and npx hyperframes render.
  • Evidence: references/brief-contract.md mentions executing a local script node <MEDIA_DIR>/scripts/prefs.mjs to retrieve preferences.
  • These commands are standard operations for the framework's build and review process.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:57 PM
Security Audit — agent-trust-hub — hyperframes-core