remotion-best-practices

Pass

Audited by Gen Agent Trust Hub on Apr 11, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [PROMPT_INJECTION]: The skill identifies a potential surface for indirect prompt injection by instructing the agent to fetch and process untrusted data from external URLs.
  • Ingestion points: Data is retrieved using fetch() and WebFetch in files such as rules/calculate-metadata.md, rules/import-srt-captions.md, rules/lottie.md, and rules/compositions.md.
  • Boundary markers: The provided code examples do not include delimiters or specific instructions to treat external data as untrusted or to ignore embedded instructions.
  • Capability inventory: The skill utilizes network access to fetch JSON data, subtitles, and animation assets from remote locations.
  • Sanitization: The examples do not demonstrate validation or sanitization of the fetched external content before it is used in the rendering process.
  • [PROMPT_INJECTION]: Metadata inconsistency detected in the SKILL.md frontmatter. The author is declared as 'remotion-dev', which differs from the platform-provided author identity 'AndrewHaward2310'. This discrepancy could mislead users regarding the skill's official origin.
  • [EXTERNAL_DOWNLOADS]: The skill recommends the installation of various Node.js packages within the Remotion ecosystem and the mediabunny library to handle media metadata and processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 11, 2026, 06:19 PM
Security Audit — agent-trust-hub — remotion-best-practices