remotion-render-config
Pass
Audited by Gen Agent Trust Hub on Sep 17, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONDYNAMIC_EXECUTIONCOMMAND_EXECUTION
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill accepts natural language and structured input for render requirements, which it uses to generate shell commands and configuration files. This creates a surface for indirect prompt injection. \n
- Ingestion points: Target Platform/Quality Requirements input (SKILL.md). \n
- Boundary markers: Absent; the skill does not specify delimiters for untrusted input. \n
- Capability inventory: Generates shell commands (
npx remotion render), environment variables (REMOTION_CHROMIUM_PATH), and configuration files (remotion.config.ts). \n - Sanitization: Absent; the skill does not explicitly instruct the agent to sanitize input before interpolating it into commands. \n- [DYNAMIC_EXECUTION]: The skill is designed to generate executable content at runtime from user-provided specifications. \n
- Evidence: Generates
RENDER_CONFIG.mdcontaining shell commands andremotion.config.tscontaining TypeScript configuration code. \n- [COMMAND_EXECUTION]: The skill encourages the execution of various shell commands and environment variable settings. \n - Evidence: Provides templates for
npx remotion rendercommands and suggestions for setting environment variables likeREMOTION_DISABLE_CHROMIUM_SANDBOX=true.
Audit Metadata