remotion-render

Pass

Audited by Gen Agent Trust Hub on Sep 7, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill provides instructions to download the belt CLI and references documentation from trusted domains like GitHub (raw.githubusercontent.com) and the official Remotion documentation site. These are standard procedures for the tool's intended use and do not involve untrusted or risky sources.
  • [COMMAND_EXECUTION]: The documentation includes example shell commands using the belt CLI. These commands are informational and demonstrate how to interact with the service (e.g., belt login, belt app run). They do not contain any malicious logic or hidden flags.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes React/TSX code provided by the user to render a video. While this represents a boundary where external content enters the system, the execution happens within the inference.sh environment which is designed to handle this specific workload. The skill itself does not have autonomous write or privileged execution capabilities that would be susceptible to an injection attack in the context of the agent.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 7, 2026, 10:14 AM
Security Audit — agent-trust-hub — remotion-render