hyperframes-cli

Pass

Audited by Gen Agent Trust Hub on Oct 3, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The capture command allows the agent to ingest content from arbitrary URLs, converting them into local project files. For more info:
  • Ingestion points: The npx hyperframes capture <URL> command (found in SKILL.md and references/init-and-scaffold.md) ingests external web content.
  • Boundary markers: The skill instructs the agent to look for a BLOCKED.md file as a hard stop for safety violations but does not specify delimiters for the captured data itself.
  • Capability inventory: The skill has access to shell execution, file system writes, and network operations including cloud infrastructure deployment (lambda deploy, cloudrun deploy).
  • Sanitization: The hyperframes check utility is used to audit the resulting project for runtime errors and layout defects before rendering.
  • [EXTERNAL_DOWNLOADS]: The skill downloads several components required for its operation from the vendor's infrastructure.
  • Fetches a pinned version of Chromium for consistent cross-platform rendering results (npx hyperframes browser ensure).
  • Downloads project templates and examples from the official registry during the init process.
  • Installs updated instruction sets ("skills") for AI tools from the vendor's GitHub repository.
  • [COMMAND_EXECUTION]: Extensive use of CLI tools is required for the full development and deployment loop.
  • Executes the hyperframes CLI via npx for core functionality.
  • Orchestrates system utilities such as ffmpeg, ffprobe, docker, and bun.
  • Invokes cloud management tools including terraform, gcloud, and aws-sam for infrastructure tasks.
  • [DYNAMIC_EXECUTION]: Deployment commands involve the creation and execution of dynamic code artifacts.
  • The lambda deploy command uses bun to build a ZIP handler for AWS Lambda.
  • The cloudrun deploy command builds container images for deployment to Google Cloud Run.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 3, 2026, 09:18 AM
Security Audit — agent-trust-hub — hyperframes-cli