hyperframes-cli
Pass
Audited by Gen Agent Trust Hub on Oct 3, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONDYNAMIC_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The
capturecommand allows the agent to ingest content from arbitrary URLs, converting them into local project files. For more info: - Ingestion points: The
npx hyperframes capture <URL>command (found inSKILL.mdandreferences/init-and-scaffold.md) ingests external web content. - Boundary markers: The skill instructs the agent to look for a
BLOCKED.mdfile as a hard stop for safety violations but does not specify delimiters for the captured data itself. - Capability inventory: The skill has access to shell execution, file system writes, and network operations including cloud infrastructure deployment (
lambda deploy,cloudrun deploy). - Sanitization: The
hyperframes checkutility is used to audit the resulting project for runtime errors and layout defects before rendering. - [EXTERNAL_DOWNLOADS]: The skill downloads several components required for its operation from the vendor's infrastructure.
- Fetches a pinned version of Chromium for consistent cross-platform rendering results (
npx hyperframes browser ensure). - Downloads project templates and examples from the official registry during the
initprocess. - Installs updated instruction sets ("skills") for AI tools from the vendor's GitHub repository.
- [COMMAND_EXECUTION]: Extensive use of CLI tools is required for the full development and deployment loop.
- Executes the
hyperframesCLI vianpxfor core functionality. - Orchestrates system utilities such as
ffmpeg,ffprobe,docker, andbun. - Invokes cloud management tools including
terraform,gcloud, andaws-samfor infrastructure tasks. - [DYNAMIC_EXECUTION]: Deployment commands involve the creation and execution of dynamic code artifacts.
- The
lambda deploycommand usesbunto build a ZIP handler for AWS Lambda. - The
cloudrun deploycommand builds container images for deployment to Google Cloud Run.
Audit Metadata