remotion-best-practices
Pass
Audited by Gen Agent Trust Hub on Aug 26, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill describes workflows for fetching data from external URLs which serve as ingestion points for untrusted content.\n
- Ingestion points:
rules/calculate-metadata.mdfetches JSON from a user-providedprops.dataUrl.rules/import-srt-captions.mdfetches and parses.srtsubtitle files.rules/lottie.mdfetches Lottie animation JSON files from remote sources.\n - Boundary markers: No boundary markers or instructions to ignore embedded commands are present in the provided templates.\n
- Capability inventory: The skill utilizes
fetchfor network requests andfs.writeFileSyncinrules/transcribe-captions.md. It passes fetched data directly into the component's props, allowing external content to influence the rendering process.\n - Sanitization: The instructions do not include methods for sanitizing or validating the structure of the fetched JSON or text data before processing.\n- [EXTERNAL_DOWNLOADS]: The skill provides instructions for downloading and installing external binaries and models.\n
rules/transcribe-captions.mduses the@remotion/install-whisper-cpputility to install theWhisper.cppengine and associated machine learning models (e.g.,medium.en) to the local project directory.\n- [COMMAND_EXECUTION]: The skill promotes the use of shell-level CLI tools for media manipulation.\nrules/ffmpeg.mdutilizesbunx remotion ffmpegfor re-encoding and trimming video files.\nrules/transcribe-captions.mdprovides a Node.js script intended to be executed from the terminal to manage transcription and file output.
Audit Metadata