remotion-best-practices

Pass

Audited by Gen Agent Trust Hub on Oct 10, 2026

Risk Level: SAFECREDENTIALS_UNSAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTION
Full Analysis
  • [CREDENTIALS_UNSAFE]: remotion-docs/REFERENCE.md contains a hardcoded Algolia search API key (3e42dbd4f895fe93ff5cf40d860c4a85) and Application ID (PLSDUOL1CA). These are used to provide the agent with the ability to search the official Remotion documentation index at runtime.
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the download and execution of external libraries and assets from well-known sources, such as CesiumJS from cesium.com, MapLibre workers from unpkg.com, and various sound effects from remotion.media. These are standard dependencies for the rendering and animation tasks described.
  • [EXTERNAL_DOWNLOADS]: Instructions in remotion-captions/transcribe-captions.md describe downloading the Whisper.cpp binary and AI models for speech-to-text functionality. This is a functional requirement of the @remotion/install-whisper-cpp utility mentioned in the documentation.
  • [COMMAND_EXECUTION]: The skill provides numerous CLI commands for the agent to execute, including project scaffolding (npx create-video), rendering (npx remotion render), and package management (npx remotion add). These are necessary for managing Remotion projects and performing video operations.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow in remotion-docs/REFERENCE.md where the agent fetches and processes documentation content from external URLs (remotion.dev) based on search results. While this allows external data into the agent's context, the source is the official documentation of the framework being used.
Audit Metadata
Risk Level
SAFE
Analyzed
Oct 10, 2026, 01:12 PM