slideshow
Pass
Audited by Gen Agent Trust Hub on Sep 23, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: In
SKILL.md, the skill directs the agent to executenpx hyperframescommands for lifecycle tasks such as updating skill logic, searching the component catalog, and validating composition integrity.\n- [EXTERNAL_DOWNLOADS]: Inreferences/standalone-harness.md, the skill references the Three.js library from the JSDelivr CDN (https://cdn.jsdelivr.net/npm/three@0.160.0/build/three.module.js) to support 3D background effects.\n- [INDIRECT_PROMPT_INJECTION]: The primary feature inSKILL.mdfor converting external web pages and Figma designs into HyperFrames decks introduces a potential surface for indirect prompt injection from processed external content.\n - Ingestion points: External HTML, CSS, and Figma asset URLs are processed to extract design and media behavior.\n
- Boundary markers: The skill requires explicit intent confirmation from the user before beginning a slideshow conversion.\n
- Capability inventory: The agent can execute shell commands via the HyperFrames CLI and write composition files to the local system.\n
- Sanitization: SVG sanitization is performed on assets imported via the Figma integration.
Audit Metadata