hyperframes-registry

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill relies on a suite of CLI tools for workflow management. Key commands include hyperframes add for package installation, hyperframes catalog for searching items, and hyperframes lint or hyperframes check for validating compositions. These tools interact with the local file system and project configuration.
  • [EXTERNAL_DOWNLOADS]: Registry metadata and component source code are fetched from the heygen-com/hyperframes repository on GitHub. Additionally, the skill's templates reference external libraries such as GSAP and Three.js from the JSDelivr CDN (cdn.jsdelivr.net), and the search catalog may perform a one-time download of a model for on-device ranking.
  • [DATA_EXFILTRATION]: The skill includes a hyperframes feedback command specifically designed to report search gaps by sending user-provided queries to a remote server. This behavior is explicitly documented as a voluntary feedback mechanism for improving registry discovery.
  • [INDIRECT_PROMPT_INJECTION]: The skill manages external code snippets that are merged into the user's project, creating a surface for indirect prompt injection if registry content is manipulated.
  • Ingestion points: hyperframes add downloads HTML and JS files from raw.githubusercontent.com into the project's compositions/ directory.
  • Boundary markers: The documentation does not provide specific delimiters or ignore-instructions for the agent when interpreting or merging the downloaded snippet content.
  • Capability inventory: The environment supports file system writes, network requests, and CLI command execution.
  • Sanitization: Registry items are intended to be integrated directly into the project without automated sanitization logic mentioned in the analysis material.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — hyperframes-registry