remotion-best-practices

Pass

Audited by Gen Agent Trust Hub on Aug 26, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill describes workflows for fetching data from external URLs which serve as ingestion points for untrusted content.\n
  • Ingestion points: rules/calculate-metadata.md fetches JSON from a user-provided props.dataUrl. rules/import-srt-captions.md fetches and parses .srt subtitle files. rules/lottie.md fetches Lottie animation JSON files from remote sources.\n
  • Boundary markers: No boundary markers or instructions to ignore embedded commands are present in the provided templates.\n
  • Capability inventory: The skill utilizes fetch for network requests and fs.writeFileSync in rules/transcribe-captions.md. It passes fetched data directly into the component's props, allowing external content to influence the rendering process.\n
  • Sanitization: The instructions do not include methods for sanitizing or validating the structure of the fetched JSON or text data before processing.\n- [EXTERNAL_DOWNLOADS]: The skill provides instructions for downloading and installing external binaries and models.\n
  • rules/transcribe-captions.md uses the @remotion/install-whisper-cpp utility to install the Whisper.cpp engine and associated machine learning models (e.g., medium.en) to the local project directory.\n- [COMMAND_EXECUTION]: The skill promotes the use of shell-level CLI tools for media manipulation.\n
  • rules/ffmpeg.md utilizes bunx remotion ffmpeg for re-encoding and trimming video files.\n
  • rules/transcribe-captions.md provides a Node.js script intended to be executed from the terminal to manage transcription and file output.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 26, 2026, 11:03 PM
Security Audit — agent-trust-hub — remotion-best-practices