website-to-video

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill captures and analyzes content from arbitrary user-provided URLs to generate narration scripts and storyboard concepts. This introduces a surface for indirect prompt injection where malicious content on a target website could attempt to influence the agent's behavior or exfiltrate credentials stored in the environment.
  • Ingestion points: Website text content is extracted to capture/extracted/visible-text.txt and images are described by Gemini AI in capture/extracted/asset-descriptions.md. Both are used to ground the creative brief and script.
  • Boundary markers: The workflow enforces human review 'gates' at Step 3 (Storyboard + Script) and Step 6 (Validation), which serves as a significant mitigation against automated injection payloads.
  • Capability inventory: The agent has access to sensitive API keys (HEYGEN_API_KEY, ELEVENLABS_API_KEY, GEMINI_API_KEY) and can perform network operations via curl and CLI tools.
  • Sanitization: While the hyperframes lint tool checks for code structure, there is no explicit sanitization step for natural language content ingested from external sites.
  • [COMMAND_EXECUTION]: The skill frequently invokes the npx hyperframes CLI to perform orchestration tasks, including site capture, registry block installation, and final video rendering.
  • [EXTERNAL_DOWNLOADS]: The skill downloads external dependencies including JavaScript libraries (GSAP, Three.js, Anime.js) from JSDelivr, and various AI models (Whisper, u2net) and components from the HeyGen/HyperFrames registry. These references target well-known and expected service providers.
  • [DYNAMIC_EXECUTION]: The workflow involves generating JavaScript-driven HTML compositions (using GSAP and WebGL shaders) at runtime. The capabilities.md file notes support for tl.call() and onUpdate callbacks, which are necessary for the skill's rendering logic.
  • [CREDENTIALS_SAFE]: The skill provides clear instructions for users to store sensitive API keys for Gemini, ElevenLabs, and HeyGen in .env files. This follows established best practices for secure credential management in development tools.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — website-to-video