Back to skill

Security audit

Hyperframes Cli

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed guide for using the HyperFrames CLI, and its file creation, media processing, preview, rendering, and tool download effects fit that purpose.

Safe to install based on the available evidence. Before running `npx hyperframes init` or render commands, expect local file writes, media copying/transcription, possible model or browser downloads, local preview servers, and significant resource use; review paths and flags, especially `--non-interactive` and media inputs.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
88% confidence
Finding
The description is broad enough to trigger this skill for generic build or troubleshooting requests, increasing the chance an agent invokes `npx hyperframes` in situations where the user did not explicitly ask to run the HyperFrames toolchain. Because this skill can scaffold projects, copy media, transcribe audio, open browsers, and install additional skills, over-broad routing expands the chance of unintended side effects.

Missing User Warnings

Medium
Confidence
93% confidence
Finding
The `init` behavior performs consequential actions beyond simple scaffolding, including copying media, transcribing audio with Whisper, and installing AI coding skills, but the description does not warn the user before those actions. In an agent context, this can lead to unanticipated file writes, model downloads, network access, or installation of additional capabilities without informed consent.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.