remotion-best-practices

Pass

Audited by Gen Agent Trust Hub on Jul 14, 2026

Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [COMMAND_EXECUTION]: The skill uses shell commands via npx, ffmpeg, node, npm, and bun for scaffolding projects, rendering videos, and managing media assets. These operations are restricted to the tools specified in the frontmatter.
  • [EXTERNAL_DOWNLOADS]: Instructions include the installation of official framework packages (@remotion/*) and standard libraries (zod, mapbox-gl, mediabunny) from well-known public registries.
  • [DATA_EXPOSURE]: The skill includes internal maintainer documentation (mirrored from the upstream project) describing credential management using 1Password and AWS CLIs. These are explicitly scoped as internal developer workflows for the project's maintainers and do not represent automated exfiltration or unsafe credential handling for general users.
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests user-provided brand files (brand/*.md) to guide the creative direction of videos. This is a documented design pattern for the skill's creative purpose and does not include logic for bypassing agent constraints or exfiltrating data.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 14, 2026, 02:06 PM
Security Audit — agent-trust-hub — remotion-best-practices