hyperframes-ad-director
Pass
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill uses the Bash tool to execute development commands during the video generation workflow, specifically invoking 'npx hyperframes lint' and 'npx hyperframes preview'. These are used to validate and visualize the generated HTML compositions.
- [PROMPT_INJECTION]: The skill is susceptible to indirect prompt injection because it incorporates data from various external points into its creative process.
- Ingestion points: Processes marketing briefs, buyer personas retrieved from 'icp-deep-scanner', and visual tokens from 'claude-design-system-architect'.
- Boundary markers: The instructions do not define clear delimiters or use instructions to ignore embedded commands within the ingested data.
- Capability inventory: The skill has access to shell execution ('Bash') and file system operations ('Write').
- Sanitization: There is no explicit evidence of sanitization or validation of the input strings before they are used to generate ad scripts or composition code.
Audit Metadata