hyperframes-registry

Warn

Audited by Snyk on Jul 4, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (medium risk: 0.65). The hyperframes add <name> workflow installs registry items by fetching from the configured public registry URL (e.g., hyperframes.json#registry points to a raw GitHub URL) and then the installed block/component HTML (outsider-authored) is read/loaded into the runtime DOM/JS context via data-composition-src (blocks) or pasted snippet content (components), creating an indirect prompt-injection surface if that HTML/JS contains attacker-controlled free text.

MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).

Issues (2)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

W012
MEDIUM

Unverifiable external dependency detected (runtime URL that controls agent).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 4, 2026, 11:52 AM
Issues
2
Security Audit — snyk — hyperframes-registry