website-to-video
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill captures and analyzes content from arbitrary user-provided URLs to generate narration scripts and storyboard concepts. This introduces a surface for indirect prompt injection where malicious content on a target website could attempt to influence the agent's behavior or exfiltrate credentials stored in the environment.
- Ingestion points: Website text content is extracted to
capture/extracted/visible-text.txtand images are described by Gemini AI incapture/extracted/asset-descriptions.md. Both are used to ground the creative brief and script. - Boundary markers: The workflow enforces human review 'gates' at Step 3 (Storyboard + Script) and Step 6 (Validation), which serves as a significant mitigation against automated injection payloads.
- Capability inventory: The agent has access to sensitive API keys (
HEYGEN_API_KEY,ELEVENLABS_API_KEY,GEMINI_API_KEY) and can perform network operations viacurland CLI tools. - Sanitization: While the
hyperframes linttool checks for code structure, there is no explicit sanitization step for natural language content ingested from external sites. - [COMMAND_EXECUTION]: The skill frequently invokes the
npx hyperframesCLI to perform orchestration tasks, including site capture, registry block installation, and final video rendering. - [EXTERNAL_DOWNLOADS]: The skill downloads external dependencies including JavaScript libraries (GSAP, Three.js, Anime.js) from JSDelivr, and various AI models (Whisper, u2net) and components from the HeyGen/HyperFrames registry. These references target well-known and expected service providers.
- [DYNAMIC_EXECUTION]: The workflow involves generating JavaScript-driven HTML compositions (using GSAP and WebGL shaders) at runtime. The
capabilities.mdfile notes support fortl.call()andonUpdatecallbacks, which are necessary for the skill's rendering logic. - [CREDENTIALS_SAFE]: The skill provides clear instructions for users to store sensitive API keys for Gemini, ElevenLabs, and HeyGen in
.envfiles. This follows established best practices for secure credential management in development tools.
Audit Metadata