hyperframes

Pass

Audited by Gen Agent Trust Hub on Sep 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The scripts/package-loader.mjs script facilitates the installation of required Node.js dependencies (@hyperframes/producer and sharp) using npm install if they are not already present in the environment. This mechanism is used to support the skill's analysis tools. It implements safety features including the use of the --ignore-scripts flag to prevent the execution of potentially malicious post-installation scripts, version pinning to ensure integrity, and an interactive confirmation prompt for users.
  • [DYNAMIC_EXECUTION]: The skill utilizes dynamic imports (await import()) within scripts/package-loader.mjs to load the analysis libraries at runtime from paths computed based on their installation location in a temporary directory. The targeted packages are either vendor-specific (@hyperframes) or well-known community libraries (sharp).
  • [INDIRECT_PROMPT_INJECTION]: The skill processes external HTML files, metadata, and transcription data. While this provides a surface for indirect prompt injection if an attacker provides malicious composition source files, the risk is inherent to the skill's primary purpose of video composition and analysis, and the processing is scoped to media production tasks.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 15, 2026, 08:15 PM
Security Audit — agent-trust-hub — hyperframes