remotion-best-practices
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to process external media and metadata, creating a standard surface for indirect prompt injection via untrusted user-supplied content.
- Ingestion points: Files
rules/display-captions.md,rules/import-srt-captions.md,rules/videos.md, andrules/audio.mddescribe loading external captions (JSON/SRT), audio, and video assets. - Boundary markers: The instructions do not define explicit delimiters or instructions for the agent to ignore potential commands embedded within data fields of ingested files (e.g., subtitle text).
- Capability inventory: The skill utilizes subprocess calls for FFmpeg (
rules/ffmpeg.md) and network operations viafetchfor ElevenLabs TTS and Mapbox services (rules/voiceover.md,rules/mapbox.md). - Sanitization: There are no specific instructions for sanitizing or validating the content of ingested captions or external metadata.
- [COMMAND_EXECUTION]: The skill utilizes standard Remotion CLI tools through
npxfor project scaffolding, studio previewing, and video processing with FFmpeg. These operations are within the expected scope of the skill's functionality and involve standard development commands. - [EXTERNAL_DOWNLOADS]: The skill references and installs several standard Node.js packages from the Remotion ecosystem and well-known libraries such as
mapbox-gl,zod, andmediabunny. It also fetches data from established services like Mapbox, ElevenLabs, and LottieFiles, which is routine for the intended use case.
Audit Metadata