{"data":{"skill":{"slug":"heygen-com-remotion-to-hyperframes","name":"remotion-to-hyperframes","icon":"📦","repo":"https://github.com/heygen-com/hyperframes/tree/main/skills/remotion-to-hyperframes/","status":"approved","author":"heygen-com","authorVersion":null,"skillstoreRevision":null},"audit":{"id":"0f9872b5-00b3-420c-971d-816518c19be6","skill_id":"238a1a51-c9aa-4f90-acd3-0ef5e0894038","version":1,"content_hash":"eeab3a6aac19afc77b9833f1e50f7268","risk_level":"low","is_blocked":false,"safe_to_publish":true,"analysis_status":"ok","agent_auto_install_policy":null,"manual_install_policy":null,"summary":"This is a legitimate code translation skill that converts Remotion React video compositions to HyperFrames HTML. The extensive static findings (1025 patterns) are primarily located in test infrastructure (assets/test-corpus/), documentation references, and test fixtures - not in the skill's execution path. The skill reads Remotion code and generates HyperFrames HTML output. Shell command patterns detected in markdown files represent documented syntax examples, not actual execution. No malicious intent or user data exfiltration patterns detected.","remediation":[],"risk_factor_evidence":[{"factor":"external_commands","evidence":[{"file":"assets/test-corpus/run.sh","line_end":17,"line_start":17},{"file":"assets/test-corpus/run.sh","line_end":45,"line_start":45},{"file":"scripts/frame_strip.sh","line_end":52,"line_start":52}]},{"factor":"filesystem","evidence":[{"file":"scripts/tests/smoke.sh","line_end":27,"line_start":27}]},{"factor":"network","evidence":[{"file":"references/fonts.md","line_end":19,"line_start":19}]},{"factor":"env_access","evidence":[{"file":"assets/test-corpus/tier-4-escape-hatch/validate.sh","line_end":39,"line_start":39}]},{"factor":"scripts","evidence":[{"file":"references/limitations.md","line_end":79,"line_start":79}]}],"critical_findings":[],"high_findings":[],"medium_findings":[{"title":"Shell Command Patterns in Test Infrastructure","locations":[{"file":"assets/test-corpus/run.sh","line_end":17,"line_start":17},{"file":"assets/test-corpus/run.sh","line_end":45,"line_start":45},{"file":"scripts/frame_strip.sh","line_end":52,"line_start":52}],"confidence":0.25,"description":"Ruby/shell backtick execution patterns detected in assets/test-corpus/ files, scripts/, and references/ documentation. These are test fixtures, documentation examples, and test corpus files - not skill execution paths. The skill itself does not execute these patterns at runtime.","confidence_reasoning":"Pattern detected in test infrastructure and documentation files. The skill is a code translator that generates HTML output - it does not execute shell commands at runtime."}],"low_findings":[{"title":"Path Traversal Patterns in Test Data","locations":[{"file":"assets/test-corpus/tier-3-data-driven/remotion-src/src/scenes/OutroScene.tsx","line_end":2,"line_start":2},{"file":"assets/test-corpus/tier-3-data-driven/remotion-src/src/scenes/StatsScene.tsx","line_end":2,"line_start":2}],"confidence":0.15,"description":"Path traversal sequences (../) detected in test corpus files and documentation examples. These represent legitimate path references in test fixtures for testing the skill's handling of import paths.","confidence_reasoning":"These are test fixture files demonstrating import path handling - not user-controllable paths exploited at runtime."},{"title":"System Reconnaissance in Test Scripts","locations":[{"file":"scripts/tests/smoke.sh","line_end":58,"line_start":58}],"confidence":0.1,"description":"Commands like `which` for tool detection found in test scripts. These are legitimate checks for development tool availability.","confidence_reasoning":"Standard tool availability checks in development/test scripts - common practice for build systems."},{"title":"Weak Crypto Algorithm References in Test Data","locations":[{"file":"assets/test-corpus/tier-1-title-card/expected.json","line_end":5,"line_start":5}],"confidence":0.1,"description":"Weak cryptographic algorithm mentions in expected.json test data files. These are test assertions for evaluating skill outputs against known-good examples.","confidence_reasoning":"Test data containing algorithm names for comparison purposes - not actual cryptographic operations."},{"title":"Hardcoded URLs in Documentation","locations":[{"file":"references/fonts.md","line_end":19,"line_start":19}],"confidence":0.1,"description":"Hardcoded CDN and documentation URLs in reference files. These are legitimate resource references for font loading and documentation.","confidence_reasoning":"Standard documentation of external font resources - no credential or sensitive data involved."}],"dangerous_patterns":[],"files_scanned":70,"total_lines":4660,"audit_model":"claude","audited_at":"2026-05-11T09:22:41.197+00:00","created_at":"2026-05-11T10:25:03.573446+00:00","static_findings":[],"finding_verdicts":[],"semantic_findings":[],"subject_marketplace_commit_sha":null,"subject_content_hash":null,"subject_tree_hash":null,"subject_plugin_path":null,"audit_payload_hash":null,"confirmed_risk_level":null,"scanner_version":null,"policy_version":null,"subject":{"marketplaceCommitSha":null,"contentHash":null,"treeHash":null,"pluginPath":null,"auditPayloadHash":null},"scannerVersion":null,"policyVersion":null},"auditTranslation":null,"localization":{"requestedLocale":"en","contentLocale":"en","availableLocales":["en"],"fallbackToEnglish":false},"attestation":{"availability":"not_attestable","url":null,"status":null,"reason":"canonical install advisories are incomplete"},"trust":{"publicState":"public","auditState":"complete","auditCurrentness":null,"confirmedRiskLevel":"low","confirmedFindingCount":3,"capabilityReviewCount":1,"needsReviewCount":0,"falsePositiveCount":1,"agentAutoInstallPolicy":null,"manualInstallPolicy":null,"artifactSignatureState":"available","attestationState":"not_attestable","verificationState":"not_verified"},"isLatest":false}}