slideshow
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPERSISTENCEDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [REMOTE_CODE_EXECUTION]: The skill instructs the agent to run
npx hyperframes skills update slideshowto refresh its instructions and dependencies. This pattern involves downloading and executing code from the NPM registry at runtime. - [COMMAND_EXECUTION]: The skill makes extensive use of CLI tools for its workflow, including
hyperframes present,hyperframes preview,hyperframes lint, andhyperframes check. These commands are used to serve, validate, and render the slideshow projects. - [EXTERNAL_DOWNLOADS]: The skill references the Three.js library from the
jsdelivr.netCDN, a well-known service, to enable 3D visual effects within the slideshow compositions. - [PERSISTENCE]: The skill implements a persistence mechanism for speaker notes using the browser's
localStorage. Notes are stored and retrieved using deterministic keys derived from the deck's URL and title. - [DYNAMIC_EXECUTION]: The
references/standalone-harness.mdfile contains significant JavaScript logic intended to be injected into user projects. This includes a bootstrap script that usesparent.postMessage(..., "*")to communicate timeline metadata. The use of the*wildcard for the target origin is an insecure practice that can allow unintended origins to intercept the data. - [INDIRECT_PROMPT_INJECTION]: The skill processes structured data from a JSON island inside HTML files, which includes user-controllable fields such as
notesandlabelthat are subsequently displayed to the user. - Ingestion points: Data is read from
<script type="application/hyperframes-slideshow+json">blocks within composition files likeindex.html. - Boundary markers: The data is encapsulated within a specific JSON schema and script type identifier.
- Capability inventory: The skill has the ability to write files, execute subprocesses via the
hyperframesCLI, and perform network operations through the agent's environment. - Sanitization: The instructions emphasize SVG sanitization and font token resolution but do not detail specific sanitization for natural language fields in the JSON manifest.
Audit Metadata