hyperframes

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes data from untrusted external sources, creating a surface for indirect prompt injection attacks. 1. Ingestion points: The skill ingests content from website URLs, GitHub Pull Requests, and Figma design URLs (documented in SKILL.md and references/routes/). 2. Boundary markers: The system uses an 'intent layer' and human-in-the-loop review cycles (storyboard and plan reviews) before executing build tasks, which provides a layer of oversight. 3. Capability inventory: The skill has access to shell execution, network-based asset capture, and data publishing tools. 4. Sanitization: Documented sanitization processes exist for specific inputs, such as Figma SVG assets.
  • [COMMAND_EXECUTION]: The skill frequently executes shell commands via npx, node, and gh to perform tasks such as project upgrades, asset management, and fetching repository metadata.
  • [EXTERNAL_DOWNLOADS]: The skill dynamically installs workflow-specific logic and updates from the HeyGen GitHub repository (heygen-com/hyperframes) using the npx hyperframes skills update command.
  • [DATA_EXFILTRATION]: The skill includes a 'publish' capability (npx hyperframes publish) that transmits rendered video compositions to a remote server to generate a stable sharing link.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — hyperframes