hyperframes-animation
Pass
Audited by Gen Agent Trust Hub on Oct 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill uses a
package-loader.mjsutility to dynamically install necessary vendor dependencies (@hyperframes/producer, @hyperframes/core) from the npm registry if they are missing. It also fetches standard animation libraries (GSAP, Anime.js, Three.js, Lottie) from reputable CDNs like jsDelivr, cdnjs, and unpkg for its animation recipes. - [COMMAND_EXECUTION]: The script
scripts/animation-map.mjsperforms local file system operations and executes shell commands to analyze composition timelines. The bootstrapping logic inpackage-loader.mjsusesspawnSyncto invokenpm install. This process is secured by using --ignore-scripts to prevent the execution of malicious lifecycle scripts and requires an interactive TTY confirmation or an explicit environment variable override. - [REMOTE_CODE_EXECUTION]: Through the bootstrapping mechanism in
package-loader.mjs, the skill downloads and subsequently imports/executes Node.js modules from the @hyperframes namespace. This behavior is restricted to vendor-owned packages and includes guards such as version pinning and script execution blocks to ensure safe runtime extension.
Audit Metadata