remotion
Pass
Audited by Gen Agent Trust Hub on Sep 4, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill processes untrusted data such as project titles, screen names, and descriptions retrieved from the Stitch platform. This external content is interpolated into generated React components (e.g.,
ScreenSlide.tsx) and manifest files (screens.json). While this is functional, it creates a surface for instructions embedded in project metadata to influence the agent's code generation. - Ingestion points: Metadata retrieved via
stitch:list_projects,stitch:list_screens, andstitch:get_screentools as described inSKILL.md. - Boundary markers: None explicitly implemented to isolate external strings from the generated code logic.
- Capability inventory: The skill has
Writeaccess to the filesystem,Bashaccess for shell commands, and execution of theremotionCLI. - Sanitization: No specific sanitization or escaping mechanisms for the interpolated metadata are defined in the provided templates.
- [COMMAND_EXECUTION]: The skill utilizes shell commands to manage its workflow. This includes executing a helper script
scripts/download-stitch-asset.shwhich usescurlto download images, and runningnpmcommands to install dependencies and render video compositions. These operations are essential for the primary functionality and are constrained to standard development tools. - [EXTERNAL_DOWNLOADS]: The skill fetches visual assets from Google Cloud Storage (
storage.googleapis.com) and manages software dependencies from official registries. It also references external agent skills from the officialremotion-devGitHub organization. These sources are well-known and recognized as trusted for development purposes.
Audit Metadata