hyperframes-creative
Warn
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [DYNAMIC_EXECUTION]:
- The
scripts/package-loader.mjsscript performs dynamic loading of Node.js modules from computed file paths. It uses theimport()function to load packages that were installed at runtime into a temporary directory. - [EXTERNAL_DOWNLOADS]:
- The
scripts/package-loader.mjsscript automates the installation of external NPM packages (specifically@hyperframes/producer,@hyperframes/core, andsharp) if they are missing from the environment. - [COMMAND_EXECUTION]:
- The
scripts/extract-audio-data.pyscript executes theffmpegcommand viasubprocess.runto process audio files. - The
scripts/package-loader.mjsscript executesnpm installviaspawnSyncto manage its dependencies. - Instructions in
references/design-picker.mddirect the agent to start a local background HTTP server usingpython3 -m http.serverto serve the design picker interface. - [INDIRECT_PROMPT_INJECTION]:
- Ingestion points: User-provided strings like headlines and sublines are ingested during the design picker workflow described in
references/design-picker.md. - Boundary markers: Absent. The template
templates/design-picker.htmldoes not use delimiters or provide instructions to ignore commands within the user data. - Capability inventory: The skill can execute shell commands (
scripts/package-loader.mjs,scripts/extract-audio-data.py) and perform network operations. The design picker UI usesinnerHTMLintemplates/design-picker.htmlto render user-influenced content. - Sanitization: Absent. The implementation uses
innerHTMLto inject tokens like{{prompt_headline}}into the picker UI, creating a vulnerability where maliciously crafted input could execute arbitrary JavaScript.
Audit Metadata