hyperframes-testimonial-builder

Pass

Audited by Gen Agent Trust Hub on Jul 17, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute hyperframes-cli commands such as init, lint, preview, and render. These operations are consistent with the skill's primary purpose of video composition and rendering within the local environment.
  • [EXTERNAL_DOWNLOADS]: The skill uses WebFetch to retrieve customer reviews from public profile URLs. This is a functional requirement for gathering the data necessary to create testimonial content.
  • [PROMPT_INJECTION]: The skill processes untrusted external data, such as customer reviews, emails, and web content. While it emphasizes verbatim extraction, there is a surface area for indirect prompt injection where malicious instructions embedded in a review could potentially influence the agent's behavior during the analysis or story-directing phase.
  • [REMOTE_CODE_EXECUTION]: The skill references and invokes other vendor-specific components like the hyperframes skill and hyperframes-media for voiceover and media processing. These are treated as legitimate vendor-owned resources.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 17, 2026, 06:05 PM
Security Audit — agent-trust-hub — hyperframes-testimonial-builder