remotion-asset-coordinator
Pass
Audited by Gen Agent Trust Hub on Sep 15, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from design specifications to generate asset manifests and code snippets, which is a potential injection vector.
- Ingestion points: Processes content from
VIDEO_SPEC.mdandCODE_SCAFFOLD.mdas specified in the skill body. - Boundary markers: Does not employ explicit delimiters or instructions to the agent to ignore instructions embedded within the processed specification files.
- Capability inventory: Generates complex TypeScript code for Remotion components and suggests shell commands for image/video/audio processing.
- Sanitization: No explicit sanitization or validation logic is defined for the input content before it is interpolated into the generated output files.
Audit Metadata