remotion-composition

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTION
Full Analysis
  • [SAFE]: The skill provides structured documentation, TypeScript templates, and mathematical logic for video composition timing. All code snippets are benign and intended for human review or insertion into a development project.
  • [INDIRECT_PROMPT_INJECTION]: The skill processes user-supplied scene lists and durations to generate its output. While this presents a surface for indirect prompt injection, the risk is negligible as the skill lacks capabilities to execute code, access the network, or write to the filesystem directly.
  • Ingestion points: User-provided scene lists (natural language or markdown) processed via the prompt.
  • Boundary markers: None explicitly defined to separate user input from the generation logic.
  • Capability inventory: Limited to text and code snippet generation. No network, file-system, or subprocess execution capabilities exist within the skill itself.
  • Sanitization: Relies on the underlying LLM's standard safety alignment and output filtering.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 08:08 AM
Security Audit — agent-trust-hub — remotion-composition