remotion
Pass
Audited by Gen Agent Trust Hub on Aug 24, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADSREMOTE_CODE_EXECUTION
Full Analysis
- [PROMPT_INJECTION]: The skill incorporates several prescriptive execution protocols (e.g., [WORKFLOW-EXECUTION-PROTOCOL], [LESSON-LEARNED-REMINDER]) that use authoritative language like "MANDATORY" and "BLOCKING" to control the agent's decision-making process and override default behaviors.
- [INDIRECT_PROMPT_INJECTION]: The skill presents an attack surface where untrusted data could influence agent actions.
- Ingestion points: User-provided video descriptions in SKILL.md and metadata from external URLs processed via mediabunny-utils.ts.
- Boundary markers: None identified; the instructions do not explicitly warn the agent to ignore instructions embedded in these inputs.
- Capability inventory: Shell command execution via npm and npx, and file system writes identified in SKILL.md and generate-voiceover.ts.
- Sanitization: No explicit sanitization or validation logic is provided for these external inputs.
- [COMMAND_EXECUTION]: The skill relies on various shell commands (e.g., npm, npx, find, grep, mkdir) for project lifecycle management, filesystem discovery, and environment auditing.
- [UNVERIFIABLE_DEPENDENCIES_AND_REMOTE_CODE_EXECUTION]: The skill facilitates the installation of numerous third-party packages and executes remote scripts (e.g., npx create-video). While these operations target well-known and reputable services such as the npm registry, ElevenLabs, and Mapbox, they represent a remote code execution vector.
- [DYNAMIC_EXECUTION]: The skill utilizes runtime configurations via the calculateMetadata function, which can fetch and integrate external data into the video composition properties during the rendering process.
Audit Metadata