remotion-to-hyperframes

Warn

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: MEDIUMDYNAMIC_EXECUTIONINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [DYNAMIC_EXECUTION]: Evaluation and utility scripts such as render_diff.sh and frame_strip.sh generate and execute Python code at runtime using stdin heredocs (`python3
  • <<'PY'`). This logic is used for parsing ffmpeg logs and calculating frame-accurate timing.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted Remotion source code and possesses capabilities for shell command execution and file system writes.
  • Ingestion points: Remotion source files (.tsx, .ts).
  • Boundary markers: A linter identifies 'blockers' (e.g., useState, useEffect with deps) to refuse translation.
  • Capability inventory: Shell execution (ffmpeg, npm, npx) and file generation (index.html).
  • Sanitization: Regex-based pattern matching for prohibited React idioms.
  • [COMMAND_EXECUTION]: The workflow relies on executing shell commands, including ffmpeg, ffprobe, npm, and npx, to perform baseline renders, dependency management, and quality validation.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Sep 13, 2026, 03:56 PM
Security Audit — agent-trust-hub — remotion-to-hyperframes