remotion-to-hyperframes
Warn
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
- [DYNAMIC_EXECUTION]: Evaluation and utility scripts such as
render_diff.shandframe_strip.shgenerate and execute Python code at runtime using stdin heredocs (`python3 - <<'PY'`). This logic is used for parsing ffmpeg logs and calculating frame-accurate timing.
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted Remotion source code and possesses capabilities for shell command execution and file system writes.
- Ingestion points: Remotion source files (.tsx, .ts).
- Boundary markers: A linter identifies 'blockers' (e.g., useState, useEffect with deps) to refuse translation.
- Capability inventory: Shell execution (ffmpeg, npm, npx) and file generation (index.html).
- Sanitization: Regex-based pattern matching for prohibited React idioms.
- [COMMAND_EXECUTION]: The workflow relies on executing shell commands, including
ffmpeg,ffprobe,npm, andnpx, to perform baseline renders, dependency management, and quality validation.
Audit Metadata