skills/jscraik/agent-skills/remotion/Gen Agent Trust Hub

remotion

Pass

Audited by Gen Agent Trust Hub on Apr 12, 2026

Risk Level: SAFE
Full Analysis
  • [COMMAND_EXECUTION]: The skill includes a decision feedback protocol that utilizes a local script (utilities/skill-builder/scripts/record_skill_feedback.py) to record performance metrics. This is a standard administrative utility for skill management.
  • [EXTERNAL_DOWNLOADS]: Several rule files (e.g., calculate-metadata.md, lottie.md, can-decode.md) contain code examples for fetching assets, metadata, or JSON data from remote URLs. These examples use well-known services (like Lottiefiles or Remotion's official site) or user-provided parameters, which is consistent with the primary purpose of video composition and media processing.
  • [SAFE]: Installation instructions for Remotion-related packages (e.g., npx remotion add @remotion/three) target the official, well-known ecosystem for the library and do not represent a supply chain risk.
  • [SAFE]: The skill explicitly includes a privacy constraint in SKILL.md to redact secrets, private asset URLs, and internal file paths when summarizing media workflows, demonstrating adherence to security best practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 12, 2026, 01:13 PM
Security Audit — agent-trust-hub — remotion