hyperframes-sales-demo-builder
Pass
Audited by Gen Agent Trust Hub on Jun 12, 2026
Risk Level: SAFEPROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill ingests data from external, untrusted sources including prospect websites and CRM notes to personalize video content. This interpolation of external data into agent prompts represents an indirect prompt injection surface. * Ingestion points: CRM records, discovery notes, and public prospect websites defined in Step 1. * Boundary markers: Absent; user-provided data is directly interpolated into script templates in Step 2. * Capability inventory: The skill utilizes the Bash tool for rendering, Write for file management, and Agent for coordination. * Sanitization: No explicit sanitization or escaping mechanisms are described, though instructions prohibit leaking confidential data.
- [COMMAND_EXECUTION]: The skill employs the Bash tool to execute commands for rendering video compositions. These commands are generated dynamically based on the account and composition path, which is a core function for integrating with the HyperFrames media toolchain.
Audit Metadata