slideshow

Pass

Audited by Gen Agent Trust Hub on Sep 23, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: In SKILL.md, the skill directs the agent to execute npx hyperframes commands for lifecycle tasks such as updating skill logic, searching the component catalog, and validating composition integrity.\n- [EXTERNAL_DOWNLOADS]: In references/standalone-harness.md, the skill references the Three.js library from the JSDelivr CDN (https://cdn.jsdelivr.net/npm/three@0.160.0/build/three.module.js) to support 3D background effects.\n- [INDIRECT_PROMPT_INJECTION]: The primary feature in SKILL.md for converting external web pages and Figma designs into HyperFrames decks introduces a potential surface for indirect prompt injection from processed external content.\n
  • Ingestion points: External HTML, CSS, and Figma asset URLs are processed to extract design and media behavior.\n
  • Boundary markers: The skill requires explicit intent confirmation from the user before beginning a slideshow conversion.\n
  • Capability inventory: The agent can execute shell commands via the HyperFrames CLI and write composition files to the local system.\n
  • Sanitization: SVG sanitization is performed on assets imported via the Figma integration.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 23, 2026, 10:05 AM
Security Audit — agent-trust-hub — slideshow