This skill uses unauthorized sub-agent spawning to bypass safety filters, hides backend decisions from users, executes unconstrained commands, and relies on external, unverified content sources.
npx skills add https://github.com/heygen-com/hyperframesThe instructions explicitly direct the agent to spawn sub-agents for visual QA, which can be used to bypass the primary agent's safety constraints by providing a limited, attacker-controlled prompt to the sub-agent. [ensemble: confirmed by 3/3 passes; severity set to the agreed median (ADR-0067).]
If you can spawn a subagent, give it ONLY the preview sheet + this checklist and ask for PASS/FIX verdicts
Sub-agent spawning instructions detected — may create agents with attacker-controlled prompts
spawn a subagent
Long base64-encoded blob detected (potential hidden payload)
anchor/ordnance/terminal/neonsign/stardust/stomp/scoreboard/transit/vhs/arcade/dossier/laser/thunder/hologram/biolume/aurora/spectrum/papercut/popup/chalkboard/graffiti/brush/inkwater/ransom/lastpage/nightcity
The instructions explicitly tell the agent to 'never surface' certain modes or choices to the user, forcing the agent to make backend decisions without human transparency.
Never surface 'Standard vs Cinematic vs Theme' as a question — those are backend names (a product has one UX even with several engines).
SKILL.md links to "CATALOG.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[CATALOG.md](CATALOG.md)
SKILL.md links to "references/composition-craft.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[references/composition-craft.md](references/composition-craft.md)
SKILL.md links to "references/rail.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[references/rail.md](references/rail.md)
SKILL.md links to "references/reference-bar.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[references/reference-bar.md](references/reference-bar.md)
SKILL.md links to "themes/README.md" but the file is not part of the skill package — the workflow silently degrades or the content is sourced elsewhere at runtime
[themes/README.md](themes/README.md)
Skill does not specify a license field. Specifying a license helps users understand usage terms.
[](https://mondoo.com/ai-agent-security/skills/github/heygen-com/hyperframes/embedded-captions)<a href="https://mondoo.com/ai-agent-security/skills/github/heygen-com/hyperframes/embedded-captions"><img src="https://mondoo.com/ai-agent-security/api/badge/github/heygen-com/hyperframes/embedded-captions.svg" alt="Mondoo Skill Check" /></a>https://mondoo.com/ai-agent-security/api/badge/github/heygen-com/hyperframes/embedded-captions.svgSkills can read files, run commands, and access credentials. Mondoo helps organizations manage the security risks of AI agent skills across their entire fleet.