remotion-best-practices

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill instructions recommend the installation of official Remotion ecosystem packages (such as @remotion/three, @remotion/media, @remotion/captions, @remotion/lottie, @remotion/layout-utils, and @remotion/transitions) via the remotion add command. These are standard dependencies for the framework's functionality.
  • [EXTERNAL_DOWNLOADS]: The skill references and provides code for the mediabunny library to handle browser-side media decoding, metadata extraction, and frame processing. This is a functional utility for the skill's domain.
  • [INDIRECT_PROMPT_INJECTION]: The skill facilitates the ingestion of external data through fetch() operations, such as loading Lottie animation data from assets4.lottiefiles.com, fetching subtitle files, or retrieving dynamic composition metadata from external APIs. While these represent surfaces for untrusted data, they are standard patterns for dynamic video generation.
  • Ingestion points: Network fetch calls in rules/calculate-metadata.md, rules/compositions.md, rules/import-srt-captions.md, and rules/lottie.md.
  • Boundary markers: None explicitly implemented in the provided code snippets to delimit untrusted data from instructions.
  • Capability inventory: The skill patterns involve network requests (fetch) and asset rendering within the React/Remotion environment.
  • Sanitization: Standard React rendering is used; no specialized sanitization for data-driven prompts is demonstrated in these snippets.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 02:33 PM
Security Audit — agent-trust-hub — remotion-best-practices