general-video
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied data from
STORYBOARD.mdandBRIEF.md, which is then distributed to worker agents through generated instruction packets. This creates a surface for indirect prompt injection where malicious instructions could influence sub-agent behavior. - Ingestion points: The skill reads user-controlled data from
STORYBOARD.mdandBRIEF.mdwithinSKILL.mdandscripts/lib/frame-packets-core.mjs. - Boundary markers: The orchestration script
scripts/lib/frame-packets-core.mjsuses markdown headers to separate storyboard content in generated packets, providing basic structure but not full isolation. - Capability inventory: The skill executes shell commands (
npx hyperframes), writes files to the project directory, and performs network-based searches. - Sanitization: No explicit sanitization or escaping of the storyboard text is performed before it is interpolated into instructions for sub-agents.
- [COMMAND_EXECUTION]: The skill utilizes multiple shell commands to manage project state, initialize repositories, and perform quality checks.
- Executes
npx hyperframesfor project initialization (init), authentication status, usage tracking, linting, and final project verification. - Executes local JavaScript scripts using
nodeto record preferences, apply recipes, and generate worker packets. - [EXTERNAL_DOWNLOADS]: The skill depends on external resources and package runners for tool execution and updates.
- Performs skill updates via
npx hyperframes skills update, which fetches and installs updated skill logic from a remote registry. - Queries a hosted registry for visual treatments and components using
npx hyperframes catalog.
Audit Metadata