remotion-video
Pass
Audited by Gen Agent Trust Hub on Aug 10, 2026
Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
- [COMMAND_EXECUTION]: The skill instructs the AI agent to execute a discovery command using
lsto check for installed companion skills in local directories like~/.claude/skills/and~/.agent/skills/. This is a documented feature for suggesting recommended tools and does not involve malicious intent. - [PROMPT_INJECTION]: The skill exposes an indirect prompt injection surface as it is designed to process untrusted user data and external API content for video generation. Ingestion points: Processes text strings for components like
WordByWordandTypewriter, and ingests dynamic data viauseAsyncData. Boundary markers: None are explicitly defined in the provided prompt templates. Capability inventory: The skill possesses filesystem access for static assets and supports video rendering via CLI tools and programmatic APIs. Sanitization: The skill mitigates risks by implementing and recommendingzodschema validation for all input properties and data structures. - [EXTERNAL_DOWNLOADS]: The skill references and utilizes standard, well-known packages from the Remotion ecosystem, including
zod,@remotion/google-fonts,@remotion/bundler,@remotion/renderer, and@remotion/lambda. It also provides standard installation and project scaffolding commands usingnpx.
Audit Metadata