hyperframes-keyframes

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses npx hyperframes for diagnostics, which initiates package downloads from the npm registry. As npm is a well-known service and the package corresponds to the skill's stated purpose, this is a standard development operation.
  • [COMMAND_EXECUTION]: The instructions direct the agent to run various CLI commands (lint, check, keyframes, snapshot) using npx. These commands are contained within the scope of the animation workflow and are used for verification and snapshotting.
  • [INDIRECT_PROMPT_INJECTION]: The skill accepts user requests for visual motion and translates them into code. It provides safety guardrails through a "Contract" section and defined "Creator editing boundaries" to ensure subject identity preservation and seek-safe execution, reducing the likelihood of accidental obedience to malicious instructions in processed data.
  • Ingestion points: User prompts for animation recipes and creator requests (SKILL.md).
  • Boundary markers: "Contract" and "Creator editing boundary" sections provide explicit rules for motion and state management.
  • Capability inventory: Execution of npx commands for linting and snapshotting; generation of GSAP/CSS/Anime.js code.
  • Sanitization: Relies on structural rules and deterministic runtime requirements (e.g., synchronous builds, registration of timelines) rather than string sanitization.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — hyperframes-keyframes