hyperframes-explainer-builder
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill processes untrusted data from external websites to generate video scripts, creating a surface for indirect prompt injection.\n
- Ingestion points: External URLs fetched via WebFetch and WebSearch in SKILL.md.\n
- Boundary markers: None; external content is interpolated directly into narrative extraction steps.\n
- Capability inventory: The skill utilizes Bash, Write, and Agent tools for rendering and file management.\n
- Sanitization: No sanitization of the external web content is specified.\n- [COMMAND_EXECUTION]: The skill uses Bash to run hyperframes-cli for initializing, linting, and rendering video projects, which are standard operations for its stated purpose.\n- [EXTERNAL_DOWNLOADS]: Fetches content from external websites to gather source material for the explainer videos.
Audit Metadata