hyperframes-audio

Pass

Audited by Gen Agent Trust Hub on Oct 11, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The script scripts/carve.mjs executes the ffmpeg binary using execFileSync to perform audio decoding tasks. This is a legitimate use of a well-known system utility for media processing.
  • [DYNAMIC_EXECUTION]: The skill uses the import() function to dynamically load modules from the @hyperframes/core package. It resolves these modules relative to the target project's node_modules directory, allowing for tight integration with the HyperFrames ecosystem.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests and modifies HTML files and processes audio files defined within those templates. While this involves processing external data, the script uses structured parsing and safe command execution methods.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 11, 2026, 09:41 AM