create-hyperframes-launch

Pass

Audited by Gen Agent Trust Hub on Sep 20, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill exhibits an indirect prompt injection attack surface by processing user-controlled inputs that are interpolated into agent instructions while the skill holds sensitive capabilities.
  • Ingestion points: The product, duration, and motionStyle inputs defined in open-design.json accept arbitrary user strings that are interpolated into the prompt query template.
  • Boundary markers: The query template in open-design.json lacks delimiters or explicit instructions for the model to treat the interpolated variables as untrusted data.
  • Capability inventory: The skill requests fs:write and subprocess capabilities in open-design.json, which represent a significant impact surface if malicious commands are injected via the user inputs.
  • Sanitization: There is no evidence of input validation, character escaping, or sanitization logic to mitigate the risk of instructions embedded within the user-supplied strings.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 20, 2026, 03:51 PM
Security Audit — agent-trust-hub — create-hyperframes-launch