hyperframes
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The
scripts/package-loader.mjsscript facilitates the installation of required Node.js dependencies (@hyperframes/producerandsharp) usingnpm installif they are not already present in the environment. This mechanism is used to support the skill's analysis tools. It implements safety features including the use of the--ignore-scriptsflag to prevent the execution of potentially malicious post-installation scripts, version pinning to ensure integrity, and an interactive confirmation prompt for users. - [DYNAMIC_EXECUTION]: The skill utilizes dynamic imports (
await import()) withinscripts/package-loader.mjsto load the analysis libraries at runtime from paths computed based on their installation location in a temporary directory. The targeted packages are either vendor-specific (@hyperframes) or well-known community libraries (sharp). - [INDIRECT_PROMPT_INJECTION]: The skill processes external HTML files, metadata, and transcription data. While this provides a surface for indirect prompt injection if an attacker provides malicious composition source files, the risk is inherent to the skill's primary purpose of video composition and analysis, and the processing is scoped to media production tasks.
Audit Metadata