remotion-best-practices

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructions provide standard commands for installing official Remotion modules using package managers (e.g., npx remotion add @remotion/media). these are routine setup operations for the framework described.
  • [EXTERNAL_DOWNLOADS]: The skill contains examples for fetching remote media assets and Lottie animations from established domains such as remotion.media and lottiefiles.com. These are documented as part of the intended functionality for video creation.
  • [INDIRECT_PROMPT_INJECTION]: The skill demonstrates patterns for ingesting untrusted external data, which creates a surface for indirect prompt injection attacks.
  • Ingestion points: Data fetching via the fetch API is demonstrated in calculateMetadata functions (rules/calculate-metadata.md, rules/compositions.md), subtitle parsing (rules/import-srt-captions.md), and Lottie animation loading (rules/lottie.md).
  • Boundary markers: The provided code snippets do not include delimiters or specific instructions to the agent to ignore embedded commands within the fetched data.
  • Capability inventory: The skill describes the use of network operations (fetch), file system access via staticFile(), and UI rendering capabilities.
  • Sanitization: There is no evidence of data sanitization or validation in the examples provided for processing external JSON or SRT content.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:20 AM
Security Audit — agent-trust-hub — remotion-best-practices