remotion
Pass
Audited by Gen Agent Trust Hub on Sep 14, 2026
Risk Level: SAFECOMMAND_EXECUTIONINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSDYNAMIC_EXECUTION
Full Analysis
- [COMMAND_EXECUTION]: The skill includes instructions to run a showcase gallery using
npm run studioin theshowcase/transitionsdirectory for previewing components. - [INDIRECT_PROMPT_INJECTION]: The documentation describes patterns for fetching and processing external data during the video rendering lifecycle.
- Ingestion points: The
reference.mdfile defines usages ofgetInputProps()andcalculateMetadatawhich can ingest external JSON or API data. - Boundary markers: Not explicitly defined in these documentation templates, as they are generic API references.
- Capability inventory: The skill documents the Remotion engine's ability to render media to the filesystem and interact with network APIs for data fetching.
- Sanitization: Standard framework-level protections are assumed; no specific sanitization patterns are provided in the examples.
- [EXTERNAL_DOWNLOADS]: The skill references the official
remotion-dev/skillsrepository for core knowledge and the vendor'sclaude-code-video-toolkitrepository on GitHub for contributions. - [DYNAMIC_EXECUTION]: The skill provides an API reference for the
@remotion/rendererpackage, which involves runtime bundling and execution of React code to generate video frames.
Audit Metadata