Files
hyperframes/skills/hyperframes-creative/scripts/package-loader.mjs
T
WaterrrForeverandClaude Opus 4.8 535297280a fix(skills): clear two Snyk Fails and harden the network + supply-chain surface (#1804)
* fix(skills): clear Snyk findings and harden supply-chain surface

Address the security-audit findings on the published skills with no change to
any skill's behaviour.

- media-use: resolve.test.mjs runs resolve.mjs via execFileSync with an argv
  array instead of execSync(`node … "${tmp}" …`), removing the command-injection
  (CWE-78) sink that drove the Snyk Fail.
- music-to-video: replace dynamic `element.innerHTML = <var>` with a setSvg()
  helper (DOMParser image/svg+xml + importNode, text fallback) in the
  intro-kinetic-cascade and logo-split-lockup-pulse frame templates, clearing the
  DOM-XSS (CWE-79) Snyk Fail. Renders identical SVG.
- pr-to-video: fetch-people-avatars.mjs refuses any avatar URL that is not https
  on a GitHub avatar host (SSRF guard) and only writes under the project dir
  (path-traversal guard); best-effort, always-exit-0 behaviour is unchanged.
- embedded-captions: pin `uvx --from whisperx==3.8.6` (overridable via
  $WHISPERX_VERSION) so transcription no longer resolves "latest" at runtime.
- gsap: add Subresource Integrity (integrity + crossorigin) to the 8 render-time
  CDN GSAP <script> tags across embedded-captions, music-to-video,
  faceless-explainer, pr-to-video and product-launch-video.
- hyperframes-animation / hyperframes-creative: document package-loader's
  defense-in-depth and note that the installLine strings are display-only.

Verified: media-use resolve (12/12), probe injection (1/1) and manifest (19/19)
tests pass; avatar host-allowlist checks pass; all changed JS passes node --check
and oxfmt.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* docs(skills): clarify product-launch-video vs website-to-video routing

Sharpen the router's product-vs-site decision in hyperframes/SKILL.md: the
split is now "is the site selling a product?" — yes (SaaS / app / product /
company site) → /product-launch-video (a promo; the default for any commercial
URL, even if the site is only named); no, or the user just wants the site shown
as-is (portfolio / blog / docs / personal / event) → /website-to-video (a tour).
Updates the workflow table, the disambiguation bullet, and both workflows'
Input/Output blurbs to match.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* style(skills): satisfy oxfmt in the two music-to-video templates

The CI Format job runs `oxfmt --check .`, which also formats embedded <script> in .html. Reflow the setSvg() blocks added for the DOM-XSS fix to oxfmt's wrapping — no logic change. Regenerate the music-to-video manifest hash to match.

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

* fix(skills): sanitize SVG in music-to-video templates (real CWE-79 fix)

Addresses @Magi's review: the previous setSvg() only swapped the sink
(innerHTML → DOMParser + importNode) but did NOT sanitize, so active SVG
content still executed on insertion into the live document. Verified in
headless Chrome that the old shape fired both an svg `onload` handler and an
inline `<script>`.

setSvg() now runs a default-deny cleanSvg() over the parsed tree before it ever
enters the document: only an allow-list of inert drawing elements
(svg/g/path/line/rect/circle/… ) and presentation attributes
(d/fill/stroke/viewBox/…) survives. Every other element (`<script>`, `<image>`,
`<use>`, `<foreignObject>`, `<a>`, `<animate>`, …), every `on*` handler, and
href/xlink:href/style are stripped — on the root node too. Non-SVG or malformed
input still falls back to textContent.

Trusted content (the bundled icon library + the default spark/cloud marks)
renders byte-identically; only hostile markup in vars.icon / leftMark / rightMark
is neutralized.

Browser-verified (headless Chrome, both templates' helper):
  old setSvg → fired ["script","onload"]
  new setSvg → fired []  · trusted icon still renders · 0 danger nodes · 0 on* attrs

Co-Authored-By: Claude Opus 4.8 (1M context) <noreply@anthropic.com>

---------

Co-authored-by: Claude Opus 4.8 (1M context) <noreply@anthropic.com>
2026-07-01 12:39:42 +08:00

289 lines
9.4 KiB
JavaScript

// package-loader — bootstrap optional helper packages only when missing, with
// defense-in-depth so a malicious or typo'd dependency can't run on install:
// • specs are version-pinned (assertPinnedPackageSpecs) — no floating "latest"
// • install runs `npm install --ignore-scripts` — package lifecycle scripts
// never execute
// • `--no-save` into a throwaway tmp dir — the host project is left untouched
// • requires an interactive y/N (or an explicit $HYPERFRAMES_SKILL_BOOTSTRAP_DEPS=1)
// • npm is spawned with an argv array (no shell) — never a built command string
// The `installLine` strings below are DISPLAY ONLY (shown in the prompt / error
// text); they are never handed to a shell or executed.
import { spawnSync } from "node:child_process";
import { existsSync, mkdtempSync, readFileSync, rmSync } from "node:fs";
import { createRequire } from "node:module";
import { tmpdir } from "node:os";
import { basename, delimiter, dirname, join, parse, resolve } from "node:path";
import { createInterface } from "node:readline/promises";
import { fileURLToPath, pathToFileURL } from "node:url";
const HERE = dirname(fileURLToPath(import.meta.url));
const VERSION_OVERRIDE_ENV = "HYPERFRAMES_SKILL_PKG_VERSION";
const BOOTSTRAP_ENV = "HYPERFRAMES_SKILL_DEPS_BOOTSTRAPPED";
const BOOTSTRAP_CONFIRM_ENV = "HYPERFRAMES_SKILL_BOOTSTRAP_DEPS";
const NODE_MODULES_ENV = "HYPERFRAMES_SKILL_NODE_MODULES";
export async function importPackagesOrBootstrap(packageNames, options = {}) {
const entries = new Map();
const missing = [];
for (const packageName of packageNames) {
const entry = resolvePackageEntry(packageName);
if (entry) entries.set(packageName, entry);
else missing.push(packageName);
}
if (missing.length > 0 && !process.env[BOOTSTRAP_ENV]) {
const npmPackages = options.npmPackages ?? missing;
assertPinnedPackageSpecs(npmPackages);
await confirmBootstrap(npmPackages);
bootstrapWithNpmInstall(npmPackages);
}
if (missing.length > 0) {
throw new Error(
[
`Could not resolve required package(s): ${missing.join(", ")}`,
"Install them in this project, for example:",
` npm install --save-dev ${packageNames.map(shellQuote).join(" ")}`,
].join("\n"),
);
}
const modules = {};
for (const [packageName, entry] of entries) {
modules[packageName] = await import(pathToFileURL(entry).href);
}
return modules;
}
export function hyperframesPackageSpec(packageName) {
const override = process.env[VERSION_OVERRIDE_ENV]?.trim();
if (override) return `${packageName}@${override}`;
const version = readBundledHyperframesVersion();
if (version) return `${packageName}@${version}`;
// Global skill installs (e.g. ~/.claude/skills) have no hyperframes package.json
// in their ancestor chain, so the bundled version is unknowable. Fall back to
// @latest instead of throwing: already-installed packages still import, and a
// bootstrap install can still proceed (@latest satisfies the pinned-spec guard).
process.stderr.write(
[
`hyperframes: could not determine the bundled version for ${packageName}; using @latest.`,
`Set ${VERSION_OVERRIDE_ENV}=<version> to pin it.`,
"",
].join("\n"),
);
return `${packageName}@latest`;
}
function resolvePackageEntry(packageName) {
const bases = [process.cwd(), HERE, ...envNodeModulesDirs(), ...nodeModulesDirsFromPath()];
const seen = new Set();
for (const base of bases) {
const normalized = resolve(base);
if (seen.has(normalized)) continue;
seen.add(normalized);
try {
return createRequire(join(normalized, "__hyperframes_skill_loader__.cjs")).resolve(
packageName,
);
} catch {
const packageDir = findPackageDir(normalized, packageName);
const packageEntry = packageDir ? readPackageEntry(packageDir) : null;
if (packageEntry) return packageEntry;
}
}
return null;
}
function readBundledHyperframesVersion() {
for (const ancestor of ancestors(HERE)) {
const directVersion = readPackageVersion(join(ancestor, "package.json"));
if (directVersion) return directVersion;
const monorepoCliVersion = readPackageVersion(
join(ancestor, "packages", "cli", "package.json"),
);
if (monorepoCliVersion) return monorepoCliVersion;
}
return null;
}
function readPackageVersion(packageJsonPath) {
try {
const manifest = JSON.parse(readFileSync(packageJsonPath, "utf8"));
if (manifest.name === "hyperframes" || manifest.name === "@hyperframes/cli") {
return typeof manifest.version === "string" ? manifest.version : null;
}
} catch {
// Keep searching ancestor package manifests.
}
return null;
}
function envNodeModulesDirs() {
return (process.env[NODE_MODULES_ENV] ?? "").split(delimiter).filter(Boolean);
}
function nodeModulesDirsFromPath() {
const dirs = [];
for (const entry of (process.env.PATH ?? "").split(delimiter)) {
if (!entry.endsWith(`${join("node_modules", ".bin")}`)) continue;
dirs.push(dirname(entry));
}
return dirs;
}
function findPackageDir(base, packageName) {
const packageSegments = packageName.split("/");
const roots =
basename(base) === "node_modules"
? [base]
: ancestors(base).map((ancestor) => join(ancestor, "node_modules"));
for (const root of roots) {
const packageDir = join(root, ...packageSegments);
if (existsSync(join(packageDir, "package.json"))) return packageDir;
}
return null;
}
function readPackageEntry(packageDir) {
try {
const manifest = JSON.parse(readFileSync(join(packageDir, "package.json"), "utf8"));
const entry = exportEntry(manifest.exports) ?? manifest.module ?? manifest.main ?? "index.js";
const entryPath = join(packageDir, entry);
return existsSync(entryPath) ? entryPath : null;
} catch {
return null;
}
}
function exportEntry(exports) {
const root =
typeof exports === "object" && exports !== null ? (exports["."] ?? exports) : exports;
if (typeof root === "string") return root;
if (typeof root !== "object" || root === null) return null;
if (typeof root.import === "string") return root.import;
if (typeof root.default === "string") return root.default;
if (typeof root.node === "string") return root.node;
if (typeof root.node === "object" && root.node !== null) {
return root.node.import ?? root.node.default ?? null;
}
return null;
}
function assertPinnedPackageSpecs(packageSpecs) {
const unpinned = packageSpecs.filter((spec) => !hasVersionSpec(spec));
if (unpinned.length === 0) return;
throw new Error(
[
`Refusing to bootstrap unpinned package spec(s): ${unpinned.join(", ")}`,
"Pass pinned npm package specs, for example:",
` ${packageSpecs.map((spec) => (hasVersionSpec(spec) ? spec : `${spec}@<version>`)).join(" ")}`,
].join("\n"),
);
}
function hasVersionSpec(packageSpec) {
if (packageSpec.startsWith("@")) {
const slash = packageSpec.indexOf("/");
return slash !== -1 && packageSpec.indexOf("@", slash + 1) !== -1;
}
return packageSpec.includes("@");
}
async function confirmBootstrap(packageSpecs) {
if (process.env[BOOTSTRAP_CONFIRM_ENV] === "1") return;
const installLine = `npm install --ignore-scripts --no-save ${packageSpecs.map(shellQuote).join(" ")}`;
if (!process.stdin.isTTY) {
throw new Error(
[
"Required helper package(s) are missing.",
"To allow a one-time temporary dependency bootstrap for this run, set:",
` ${BOOTSTRAP_CONFIRM_ENV}=1`,
"The bootstrap command will be:",
` ${installLine}`,
].join("\n"),
);
}
const rl = createInterface({ input: process.stdin, output: process.stderr });
try {
const answer = await rl.question(
[
"HyperFrames helper package(s) are missing.",
`Run a temporary install with lifecycle scripts disabled?`,
` ${installLine}`,
"Proceed? [y/N] ",
].join("\n"),
);
if (!/^(y|yes)$/i.test(answer.trim())) {
throw new Error("Dependency bootstrap cancelled.");
}
} finally {
rl.close();
}
}
function ancestors(start) {
const dirs = [];
let current = resolve(start);
const root = parse(current).root;
while (current && current !== root) {
dirs.push(current);
current = dirname(current);
}
dirs.push(root);
return dirs;
}
function bootstrapWithNpmInstall(packageNames) {
const installRoot = mkdtempSync(join(tmpdir(), "hyperframes-skill-deps-"));
const installResult = spawnSync(
process.platform === "win32" ? "npm.cmd" : "npm",
[
"install",
"--silent",
"--no-audit",
"--no-fund",
"--ignore-scripts",
"--no-save",
"--prefix",
installRoot,
...packageNames,
],
{ stdio: "inherit" },
);
if (installResult.error) throw installResult.error;
if (installResult.status !== 0) {
rmSync(installRoot, { recursive: true, force: true });
process.exit(installResult.status ?? 1);
}
const args = [...process.argv.slice(1)];
const result = spawnSync(process.execPath, args, {
stdio: "inherit",
env: {
...process.env,
[BOOTSTRAP_ENV]: "1",
[NODE_MODULES_ENV]: join(installRoot, "node_modules"),
},
});
rmSync(installRoot, { recursive: true, force: true });
if (result.error) throw result.error;
process.exit(result.status ?? 1);
}
function shellQuote(value) {
if (/^[A-Za-z0-9_./:@=-]+$/.test(value)) return value;
return `'${value.replace(/'/g, "'\\''")}'`;
}