remotion-best-practices
Pass
Audited by Gen Agent Trust Hub on Oct 10, 2026
Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
- [CREDENTIALS_UNSAFE]:
remotion-docs/REFERENCE.mdcontains a hardcoded Algolia search API key (3e42dbd4f895fe93ff5cf40d860c4a85) and Application ID (PLSDUOL1CA). These are used to provide the agent with the ability to search the official Remotion documentation index at runtime. - [EXTERNAL_DOWNLOADS]: The skill facilitates the download and execution of external libraries and assets from well-known sources, such as CesiumJS from
cesium.com, MapLibre workers fromunpkg.com, and various sound effects fromremotion.media. These are standard dependencies for the rendering and animation tasks described. - [EXTERNAL_DOWNLOADS]: Instructions in
remotion-captions/transcribe-captions.mddescribe downloading the Whisper.cpp binary and AI models for speech-to-text functionality. This is a functional requirement of the@remotion/install-whisper-cpputility mentioned in the documentation. - [COMMAND_EXECUTION]: The skill provides numerous CLI commands for the agent to execute, including project scaffolding (
npx create-video), rendering (npx remotion render), and package management (npx remotion add). These are necessary for managing Remotion projects and performing video operations. - [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow in
remotion-docs/REFERENCE.mdwhere the agent fetches and processes documentation content from external URLs (remotion.dev) based on search results. While this allows external data into the agent's context, the source is the official documentation of the framework being used.
Audit Metadata