hyperframes-creative

Pass

Audited by Gen Agent Trust Hub on Oct 5, 2026

Risk Level: SAFECOMMAND_EXECUTIONDYNAMIC_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The scripts/extract-audio-data.py script uses subprocess.run to invoke the ffmpeg tool for audio frequency extraction. Additionally, scripts/package-loader.mjs executes the npm binary to manage package installations.
  • [DYNAMIC_EXECUTION]: In scripts/package-loader.mjs, the skill dynamically imports Node.js modules using import() with computed file paths. It also uses child_process.spawnSync to re-launch its own process after bootstrapping dependencies to ensure the runtime environment is correctly configured.
  • [EXTERNAL_DOWNLOADS]: The skill downloads required functional packages from the npm registry using the npm install command. It also references and loads the GSAP animation library from the jsDelivr CDN within its HTML templates.
  • [INDIRECT_PROMPT_INJECTION]: The templates/design-picker.html tool processes user-defined strings and inserts them into the document via .innerHTML without sanitization. This creates a surface for cross-site scripting (XSS) if the AI agent populates the template with malicious content derived from untrusted user prompts.
  • Ingestion points: User-supplied text interpolated into the .innerHTML of the preview panel in templates/design-picker.html.
  • Boundary markers: None present; the template uses direct string substitution.
  • Capability inventory: Uses innerHTML for DOM manipulation and starts a local web server via http.server to display the picker.
  • Sanitization: None performed on the client-side JavaScript.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 5, 2026, 03:29 AM
Security Audit — agent-trust-hub — hyperframes-creative