update-from-upstream-main

Pass

Audited by Gen Agent Trust Hub on Aug 8, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill implements standard version control operations using Git to sync with the remotion-dev/remotion repository. These operations are performed on the local filesystem and target a well-known, vendor-consistent repository.
  • [SAFE]: Verification steps utilize 'bun' for building and styling checks, which are typical development tasks for this environment. No external code is downloaded or executed from untrusted sources.
  • [SAFE]: The skill includes a surface for indirect prompt injection when checking resolved files for conflict markers, but the capabilities are restricted to standard development workflows.
  • Ingestion points: Content of files marked as resolved during merge (SKILL.md)
  • Boundary markers: Absent
  • Capability inventory: git commit, git push, bun run (SKILL.md)
  • Sanitization: Absent
  • [SAFE]: No evidence of data exfiltration, hardcoded credentials, or obfuscated content was found within the skill's instructions or metadata.
Audit Metadata
Risk Level
SAFE
Analyzed
Aug 8, 2026, 01:54 PM
Security Audit — agent-trust-hub — update-from-upstream-main