website-to-hyperframes

Warn

Audited by Gen Agent Trust Hub on Aug 20, 2026

Risk Level: MEDIUMREMOTE_CODE_EXECUTIONCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill relies on npx hyperframes for project initialization, linting, and rendering. The npx utility downloads and executes packages from the npm registry at runtime.
  • [COMMAND_EXECUTION]: The skill instructions include executing shell commands such as npx hyperframes init --tailwind, npx hyperframes lint, and npx hyperframes render to manage the video creation workflow.
  • [PROMPT_INJECTION]: The skill facilitates the ingestion of content from arbitrary external URLs using Playwright (page.goto(url)), which introduces a surface for indirect prompt injection.
  • Ingestion points: External URLs provided by users and accessed via Playwright browser automation in SKILL.md.
  • Boundary markers: No explicit markers are defined to isolate the captured website content from the agent's instruction context.
  • Capability inventory: The skill utilizes subprocess execution via the npx command and performs file system write operations to the assets/ directory.
  • Sanitization: Instructions recommend injecting CSS to disable animations and transitions to ensure clean captures, but there is no mechanism provided to sanitize or filter potential instructions embedded within the website text.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 20, 2026, 08:41 AM
Security Audit — agent-trust-hub — website-to-hyperframes