claude-video-create

Pass

Audited by Gen Agent Trust Hub on May 15, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill utilizes npx create-video to fetch project templates and triggers the download of Chrome Headless Shell during the rendering process.
  • [COMMAND_EXECUTION]: The Bash tool is used to run standard development commands such as npm install and npx remotion render for project management and video production.
  • [REMOTE_CODE_EXECUTION]: React components authored by the agent are executed within the Remotion rendering environment to produce video content.
  • [PROMPT_INJECTION]: The skill is designed to ingest data for video generation through command-line arguments.
  • Ingestion points: The --props flag used in the npx remotion render command within SKILL.md.
  • Boundary markers: Absent.
  • Capability inventory: Access to the Bash tool for command execution.
  • Sanitization: No sanitization of the input data is explicitly described.
Audit Metadata
Risk Level
SAFE
Analyzed
May 15, 2026, 02:55 PM
Security Audit — agent-trust-hub — claude-video-create