Finding 2 of the final whole-branch review: the sidecar's loopback WebSocket accepted any connection with no origin/auth check, so any local process (or webpage that guessed/scanned the ephemeral port) could drive load-chain to load arbitrary native plugin bundles or read arbitrary files via wavPath. server.py's VstServer now generates a per-process secrets.token_urlsafe token, prints it alongside the ready line, and rejects the WebSocket handshake via websockets' process_request hook unless the connecting client presents it as a `?token=` query param. Threaded through: studio-server's vstSidecar.ts (extended ready-line regex) and routes/vst.ts (/vst/start response), the CLI adapter, and the studio client's useVstHost.ts (connects with the token in the WS URL). vstBounce.ts (the offline render path) is unaffected — it invokes the sidecar's `bounce` CLI subcommand directly and never opens a WebSocket. Also folds in two smaller final-review findings that touch the same files: - vstSidecar.test.ts's mid-spawn-kill test used a fixed 300ms sleep to wait for the child's PID file; replaced with a short-interval poll (waitForFile) to remove a CI-contention flake risk. - useVstHost.ts's handleDisconnect doc-comment claimed trackIndexRef was kept "purely for the FX property panel's own direct loadChain calls" — false (the FX panel never calls loadChain; only useVstPreview does). Corrected to describe it as forward-defensive infrastructure with no current FX-panel caller. Co-Authored-By: Claude Sonnet 5 <noreply@anthropic.com>
hyperframes
CLI for creating, previewing, and rendering HTML video compositions.
Install
npm install -g hyperframes
Or use directly with npx:
npx hyperframes <command>
Requirements: Node.js >= 22, FFmpeg
Commands
init
Scaffold a new Hyperframes project from a template:
npx hyperframes init my-video
cd my-video
preview
Start the live preview studio in your browser:
npx hyperframes preview
# Studio running at http://localhost:3002
npx hyperframes preview --port 4567
render
Render a composition to MP4. Run from the project directory; the positional
argument is the project directory (not a file), so render the project's
index.html directly, or point at a specific composition file with -c:
npx hyperframes render -o output.mp4
npx hyperframes render -c ./my-composition.html -o output.mp4
lint
Validate your Hyperframes HTML:
npx hyperframes lint ./my-composition
npx hyperframes lint ./my-composition --json # JSON output for CI/tooling
npx hyperframes lint ./my-composition --verbose # Include info-level findings
By default only errors and warnings are shown. Use --verbose to also display informational findings (e.g., external script dependency notices). Use --json for machine-readable output with errorCount, warningCount, infoCount, and a findings array.
compositions
List compositions found in the current project:
npx hyperframes compositions
benchmark
Run rendering benchmarks:
npx hyperframes benchmark ./my-composition.html
doctor
Check your environment for required dependencies (Chrome, FFmpeg, Node.js):
npx hyperframes doctor
browser
Manage the bundled Chrome/Chromium installation:
npx hyperframes browser
info
Print version and environment info:
npx hyperframes info
docs
Open the documentation in your browser:
npx hyperframes docs
upgrade
Check for updates and show upgrade instructions:
npx hyperframes upgrade
npx hyperframes upgrade --check --json # machine-readable for agents
Documentation
Full documentation: hyperframes.heygen.com/packages/cli
Related packages
@hyperframes/core— types, parsers, frame adapters@hyperframes/engine— rendering engine@hyperframes/producer— render pipeline@hyperframes/studio— composition editor UI