Analyzed Jun 25, 2026
The skill packages videos with graphic overlays using the hyperframes CLI tool. It downloads external code from the npm registry and processes untrusted video transcripts, which presents a risk of indirect prompt injection and potential shell command injection in suggested scripts.