remotion-saas
Pass
Audited by Gen Agent Trust Hub on Sep 6, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONCOMMAND_EXECUTIONEXTERNAL_DOWNLOADS
Full Analysis
- [Indirect Prompt Injection Surface]: The skill describes processes for ingesting dynamic metadata in
player.md, creating a potential injection surface if data is unsanitized. 1. Ingestion points: Dynamic props inplayer.md. 2. Boundary markers: Absent. 3. Capability inventory: Video rendering via headless browsers and AWS Lambda (rendering.md). 4. Sanitization: Not specified. - [Credential Management Best Practices]: The skill includes explicit security advice in
rendering.mdto use environment variables for AWS secrets and avoid direct input into chat. - [Command Execution]: Development and rendering workflows use
npx remotioncommands, which interact with the shell environment. - [External Resource Integration]: Links to official templates and documentation on
remotion.devand GitHub are used appropriately for the skill's purpose.
Audit Metadata