remotion-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructions recommend the installation of official Remotion ecosystem packages (such as
@remotion/three,@remotion/media,@remotion/captions,@remotion/lottie,@remotion/layout-utils, and@remotion/transitions) via theremotion addcommand. These are standard dependencies for the framework's functionality. - [EXTERNAL_DOWNLOADS]: The skill references and provides code for the
mediabunnylibrary to handle browser-side media decoding, metadata extraction, and frame processing. This is a functional utility for the skill's domain. - [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data through
fetch()operations, such as loading Lottie animation data fromassets4.lottiefiles.com, fetching subtitle files, or retrieving dynamic composition metadata from external APIs. While these represent surfaces for untrusted data, they are standard patterns for dynamic video generation. - Ingestion points: Network fetch calls in
rules/calculate-metadata.md,rules/compositions.md,rules/import-srt-captions.md, andrules/lottie.md. - Boundary markers: None explicitly implemented in the provided code snippets to delimit untrusted data from instructions.
- Capability inventory: The skill patterns involve network requests (
fetch) and asset rendering within the React/Remotion environment. - Sanitization: Standard React rendering is used; no specialized sanitization for data-driven prompts is demonstrated in these snippets.
Audit Metadata