hyperframes-keyframes
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses
npx hyperframesfor diagnostics, which initiates package downloads from the npm registry. As npm is a well-known service and the package corresponds to the skill's stated purpose, this is a standard development operation. - [COMMAND_EXECUTION]: The instructions direct the agent to run various CLI commands (
lint,check,keyframes,snapshot) usingnpx. These commands are contained within the scope of the animation workflow and are used for verification and snapshotting. - [INDIRECT_PROMPT_INJECTION]: The skill accepts user requests for visual motion and translates them into code. It provides safety guardrails through a "Contract" section and defined "Creator editing boundaries" to ensure subject identity preservation and seek-safe execution, reducing the likelihood of accidental obedience to malicious instructions in processed data.
- Ingestion points: User prompts for animation recipes and creator requests (SKILL.md).
- Boundary markers: "Contract" and "Creator editing boundary" sections provide explicit rules for motion and state management.
- Capability inventory: Execution of
npxcommands for linting and snapshotting; generation of GSAP/CSS/Anime.js code. - Sanitization: Relies on structural rules and deterministic runtime requirements (e.g., synchronous builds, registration of timelines) rather than string sanitization.
Audit Metadata