hyperframes-creative
Pass
Audited by Gen Agent Trust Hub on Oct 5, 2026
Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: The
scripts/extract-audio-data.pyscript usessubprocess.runto invoke theffmpegtool for audio frequency extraction. Additionally,scripts/package-loader.mjsexecutes thenpmbinary to manage package installations. - [DYNAMIC_EXECUTION]: In
scripts/package-loader.mjs, the skill dynamically imports Node.js modules usingimport()with computed file paths. It also useschild_process.spawnSyncto re-launch its own process after bootstrapping dependencies to ensure the runtime environment is correctly configured. - [EXTERNAL_DOWNLOADS]: The skill downloads required functional packages from the npm registry using the
npm installcommand. It also references and loads the GSAP animation library from the jsDelivr CDN within its HTML templates. - [INDIRECT_PROMPT_INJECTION]: The
templates/design-picker.htmltool processes user-defined strings and inserts them into the document via.innerHTMLwithout sanitization. This creates a surface for cross-site scripting (XSS) if the AI agent populates the template with malicious content derived from untrusted user prompts. - Ingestion points: User-supplied text interpolated into the
.innerHTMLof the preview panel intemplates/design-picker.html. - Boundary markers: None present; the template uses direct string substitution.
- Capability inventory: Uses
innerHTMLfor DOM manipulation and starts a local web server viahttp.serverto display the picker. - Sanitization: None performed on the client-side JavaScript.
Audit Metadata