hyperframes-animation

Pass

Audited by Gen Agent Trust Hub on Oct 2, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill uses a package-loader.mjs utility to dynamically install necessary vendor dependencies (@hyperframes/producer, @hyperframes/core) from the npm registry if they are missing. It also fetches standard animation libraries (GSAP, Anime.js, Three.js, Lottie) from reputable CDNs like jsDelivr, cdnjs, and unpkg for its animation recipes.
  • [COMMAND_EXECUTION]: The script scripts/animation-map.mjs performs local file system operations and executes shell commands to analyze composition timelines. The bootstrapping logic in package-loader.mjs uses spawnSync to invoke npm install. This process is secured by using --ignore-scripts to prevent the execution of malicious lifecycle scripts and requires an interactive TTY confirmation or an explicit environment variable override.
  • [REMOTE_CODE_EXECUTION]: Through the bootstrapping mechanism in package-loader.mjs, the skill downloads and subsequently imports/executes Node.js modules from the @hyperframes namespace. This behavior is restricted to vendor-owned packages and includes guards such as version pinning and script execution blocks to ensure safe runtime extension.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 2, 2026, 04:37 PM
Security Audit — agent-trust-hub — hyperframes-animation