remotion-best-practices
Pass
Audited by Gen Agent Trust Hub on Mar 29, 2026
Risk Level: SAFE
Full Analysis
- [COMMAND_EXECUTION]: The skill provides instructions for installing various official Remotion packages and utilities (such as
@remotion/three,@remotion/media, and@remotion/captions) using standard package managers including npm, bun, yarn, and pnpm. It also describes routine file system operations for saving generated assets to the project's public directory. - [EXTERNAL_DOWNLOADS]: The skill documentation guides the agent to fetch external resources such as Lottie animation files, fonts, and media assets from established and official sources including Google Fonts, LottieFiles, and Remotion's own media CDN.
- [CREDENTIALS_UNSAFE]: The skill describes the use of API keys for ElevenLabs and Mapbox via environment variables. It implements security best practices by explicitly instructing the agent to prompt the user for these keys if they are not already configured, rather than hardcoding them or using insecure defaults.
- [REMOTE_CODE_EXECUTION]: The skill includes instructions for legitimate local execution tasks, such as running a voiceover generation script and installing binary dependencies like Whisper.cpp through official Remotion helper packages. These activities are standard within the intended scope of video production and automated media processing.
Audit Metadata