create-hyperframes-launch
Pass
Audited by Gen Agent Trust Hub on Sep 20, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface by processing user-controlled inputs that are interpolated into agent instructions while the skill holds sensitive capabilities.
- Ingestion points: The
product,duration, andmotionStyleinputs defined inopen-design.jsonaccept arbitrary user strings that are interpolated into the promptquerytemplate. - Boundary markers: The
querytemplate inopen-design.jsonlacks delimiters or explicit instructions for the model to treat the interpolated variables as untrusted data. - Capability inventory: The skill requests
fs:writeandsubprocesscapabilities inopen-design.json, which represent a significant impact surface if malicious commands are injected via the user inputs. - Sanitization: There is no evidence of input validation, character escaping, or sanitization logic to mitigate the risk of instructions embedded within the user-supplied strings.
Audit Metadata