hyperframes-talking-head-recut

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted transcript data from local Whisper to generate HTML fragments that are subsequently rendered via a headless browser. Ingestion Points: transcript.json (SKILL.md Step 4). Boundary Markers: Utilizes CSS scoping requirements (.card[data-card-id="..."]) and a built-in linter to isolate content (SKILL.md Step 8). Capability Inventory: Uses hyperframes render to execute HTML/CSS/GSAP in a browser and ffmpeg for media encoding. Sanitization: Employs a linter that rejects scripts and external URLs in card HTML (SKILL.md Step 9).
  • [COMMAND_EXECUTION]: The skill uses multiple shell commands to process media and execute the rendering engine. Evidence: Invokes npx hyperframes (doctor, transcribe, render, etc.), ffmpeg, and ffprobe across the workflow (SKILL.md Steps 1, 3, 4, 9, 10).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 12:51 PM
Security Audit — agent-trust-hub — hyperframes-talking-head-recut