remotion-performance-optimizer

Pass

Audited by Gen Agent Trust Hub on Sep 17, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and analyze untrusted user-provided source code (Remotion compositions). This functionality presents a surface for indirect prompt injection if the files being analyzed contain hidden instructions intended to influence the agent's behavior.
  • Ingestion points: The skill reads composition files (src/remotion/compositions/**/*) and asset metadata.
  • Boundary markers: The skill does not explicitly define delimiters or instructions to ignore embedded commands within the analyzed source code.
  • Capability inventory: The skill primarily performs file reading and markdown generation. It does not appear to have autonomous write access or network capabilities beyond the user's manual execution of suggested commands.
  • Sanitization: No specific sanitization or filtering logic is described for the analyzed source code.
  • [COMMAND_EXECUTION]: The skill provides documentation and example shell commands for users to execute, such as npx remotion for benchmarking and magick (ImageMagick) for image optimization. These are standard developer tools relevant to the skill's purpose.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 17, 2026, 08:08 AM
Security Audit — agent-trust-hub — remotion-performance-optimizer