remotion-video-toolkit
Pass
Audited by Gen Agent Trust Hub on Jul 23, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [PROMPT_INJECTION]: The skill defines patterns for fetching and processing external data such as JSON (rules/calculate-metadata.md) and SRT subtitles (rules/import-srt-captions.md). This creates an attack surface for indirect prompt injection where instructions could be hidden in external data sources. The skill lacks boundary markers or sanitization logic in its examples to mitigate this risk, and it possesses significant capabilities for media rendering and network access.
Audit Metadata