video-hyperframes

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEPROMPT_INJECTION
Full Analysis
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface. The skill ingests untrusted user content to generate structured HTML frames.
  • Ingestion points: SKILL.md instructions process user content density to determine the number of frames and their content.
  • Boundary markers: Absent. There are no explicit delimiters or instructions for the agent to ignore embedded commands within the user's content.
  • Capability inventory: The skill generates HTML and JavaScript meant for execution in a UI preview surface, which could be exploited if the injected content attempts to execute unauthorized scripts or exfiltrate data from the preview context.
  • Sanitization: Absent. The instructions do not mandate escaping or filtering of the user-provided text before interpolation into the HTML templates.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 05:56 PM
Security Audit — agent-trust-hub — video-hyperframes