hyperframes-creative

Warn

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [DYNAMIC_EXECUTION]:
  • The scripts/package-loader.mjs script performs dynamic loading of Node.js modules from computed file paths. It uses the import() function to load packages that were installed at runtime into a temporary directory.
  • [EXTERNAL_DOWNLOADS]:
  • The scripts/package-loader.mjs script automates the installation of external NPM packages (specifically @hyperframes/producer, @hyperframes/core, and sharp) if they are missing from the environment.
  • [COMMAND_EXECUTION]:
  • The scripts/extract-audio-data.py script executes the ffmpeg command via subprocess.run to process audio files.
  • The scripts/package-loader.mjs script executes npm install via spawnSync to manage its dependencies.
  • Instructions in references/design-picker.md direct the agent to start a local background HTTP server using python3 -m http.server to serve the design picker interface.
  • [INDIRECT_PROMPT_INJECTION]:
  • Ingestion points: User-provided strings like headlines and sublines are ingested during the design picker workflow described in references/design-picker.md.
  • Boundary markers: Absent. The template templates/design-picker.html does not use delimiters or provide instructions to ignore commands within the user data.
  • Capability inventory: The skill can execute shell commands (scripts/package-loader.mjs, scripts/extract-audio-data.py) and perform network operations. The design picker UI uses innerHTML in templates/design-picker.html to render user-influenced content.
  • Sanitization: Absent. The implementation uses innerHTML to inject tokens like {{prompt_headline}} into the picker UI, creating a vulnerability where maliciously crafted input could execute arbitrary JavaScript.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 13, 2026, 03:57 PM
Security Audit — agent-trust-hub — hyperframes-creative