remotion-best-practices
Warn
Audited by Socket on Sep 24, 2026
1 alert found:
AnomalyAnomalyremotion-upgrade/REFERENCE.md
LOWAnomalyLOW
remotion-upgrade/REFERENCE.md
SUSPICIOUS: The core Remotion upgrade steps are coherent and use official Remotion/npm sources, so the main package-upgrade behavior looks benign. The notable risk is the transitive `npx skills update ... --yes` step, which expands trust to multiple additional skills and executes fetched code without separate verification; that makes the skill higher risk than a normal dependency-upgrade helper.
Confidence: 87%Severity: 56%
Audit Metadata