general-video

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data from STORYBOARD.md and BRIEF.md, which is then distributed to worker agents through generated instruction packets. This creates a surface for indirect prompt injection where malicious instructions could influence sub-agent behavior.
  • Ingestion points: The skill reads user-controlled data from STORYBOARD.md and BRIEF.md within SKILL.md and scripts/lib/frame-packets-core.mjs.
  • Boundary markers: The orchestration script scripts/lib/frame-packets-core.mjs uses markdown headers to separate storyboard content in generated packets, providing basic structure but not full isolation.
  • Capability inventory: The skill executes shell commands (npx hyperframes), writes files to the project directory, and performs network-based searches.
  • Sanitization: No explicit sanitization or escaping of the storyboard text is performed before it is interpolated into instructions for sub-agents.
  • [COMMAND_EXECUTION]: The skill utilizes multiple shell commands to manage project state, initialize repositories, and perform quality checks.
  • Executes npx hyperframes for project initialization (init), authentication status, usage tracking, linting, and final project verification.
  • Executes local JavaScript scripts using node to record preferences, apply recipes, and generate worker packets.
  • [EXTERNAL_DOWNLOADS]: The skill depends on external resources and package runners for tool execution and updates.
  • Performs skill updates via npx hyperframes skills update, which fetches and installs updated skill logic from a remote registry.
  • Queries a hosted registry for visual treatments and components using npx hyperframes catalog.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 03:45 AM
Security Audit — agent-trust-hub — general-video