remotion-upgrade

Pass

Audited by Gen Agent Trust Hub on Jul 20, 2026

Risk Level: SAFE
Full Analysis
  • [REMOTE_CODE_EXECUTION]: The skill executes the remotion package using npx to automate the upgrade process. This is a standard and expected operation for the vendor-authored tool.
  • [COMMAND_EXECUTION]: Employs shell commands such as npm view to retrieve the latest version information and npx remotion versions to audit the project's dependency state.
  • [EXTERNAL_DOWNLOADS]: Retrieves compatibility data from the official vendor website at remotion.dev to ensure correctly matched versions of the Mediabunny library.
  • [PROMPT_INJECTION]: The skill exhibits a surface for indirect prompt injection by processing external data from project manifests and remote documentation.
  • Ingestion points: Project manifests, lockfiles, and remotion.dev compatibility documentation.
  • Boundary markers: None identified.
  • Capability inventory: Package management and shell command execution (npm, npx).
  • Sanitization: None identified.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 20, 2026, 03:03 AM
Security Audit — agent-trust-hub — remotion-upgrade