hyperframes-testimonial-builder
Pass
Audited by Gen Agent Trust Hub on Jul 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The skill utilizes the Bash tool to execute
hyperframes-clicommands such asinit,lint,preview, andrender. These operations are consistent with the skill's primary purpose of video composition and rendering within the local environment. - [EXTERNAL_DOWNLOADS]: The skill uses
WebFetchto retrieve customer reviews from public profile URLs. This is a functional requirement for gathering the data necessary to create testimonial content. - [PROMPT_INJECTION]: The skill processes untrusted external data, such as customer reviews, emails, and web content. While it emphasizes verbatim extraction, there is a surface area for indirect prompt injection where malicious instructions embedded in a review could potentially influence the agent's behavior during the analysis or story-directing phase.
- [REMOTE_CODE_EXECUTION]: The skill references and invokes other vendor-specific components like the
hyperframesskill andhyperframes-mediafor voiceover and media processing. These are treated as legitimate vendor-owned resources.
Audit Metadata