remotion-video

Pass

Audited by Gen Agent Trust Hub on Aug 10, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the AI agent to execute a discovery command using ls to check for installed companion skills in local directories like ~/.claude/skills/ and ~/.agent/skills/. This is a documented feature for suggesting recommended tools and does not involve malicious intent.
  • [PROMPT_INJECTION]: The skill exposes an indirect prompt injection surface as it is designed to process untrusted user data and external API content for video generation. Ingestion points: Processes text strings for components like WordByWord and Typewriter, and ingests dynamic data via useAsyncData. Boundary markers: None are explicitly defined in the provided prompt templates. Capability inventory: The skill possesses filesystem access for static assets and supports video rendering via CLI tools and programmatic APIs. Sanitization: The skill mitigates risks by implementing and recommending zod schema validation for all input properties and data structures.
  • [EXTERNAL_DOWNLOADS]: The skill references and utilizes standard, well-known packages from the Remotion ecosystem, including zod, @remotion/google-fonts, @remotion/bundler, @remotion/renderer, and @remotion/lambda. It also provides standard installation and project scaffolding commands using npx.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 10, 2026, 02:06 PM
Security Audit — agent-trust-hub — remotion-video