talking-head-recut
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to download and run the
hyperframespackage from the NPM registry usingnpx, as well as to update the skill vianpx hyperframes skills update. - [REMOTE_CODE_EXECUTION]: The use of
npxto fetch and execute CLI tools at runtime constitutes remote code execution from an external registry. - [DYNAMIC_EXECUTION]: The skill involves the dynamic generation of HTML fragments and JavaScript code (GSAP animations). This code is later rendered into video frames using a headless browser engine, creating a runtime execution surface for generated content.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests
transcript.jsondata, which is generated from external audio/video files. This content is used to drive the text and timing of the generated graphic cards, presenting a surface for indirect prompt injection if the source media contains malicious instructions designed to influence the agent's HTML/JS generation. - [COMMAND_EXECUTION]: The workflow relies on multiple shell commands for media processing, including
ffmpegfor audio extraction and re-encoding,ffprobefor metadata retrieval, andnpxfor transcription and rendering tasks.
Audit Metadata