remotion-video-toolkit

Pass

Audited by Gen Agent Trust Hub on Sep 27, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill instructs the agent to build dynamic video rendering pipelines that ingest external data, creating a potential attack surface.
  • Ingestion points: In rules/calculate-metadata.md, the calculateMetadata function is shown fetching data from props.dataUrl. In rules/rendering.md, an Express server pattern uses req.body directly to define composition properties.
  • Boundary markers: The code examples do not demonstrate the use of delimiters or 'ignore' instructions for data incorporated into the rendering context.
  • Capability inventory: The skill leverages powerful capabilities including local rendering via Node.js/CLI, and deployment/execution on AWS Lambda and Google Cloud Run.
  • Sanitization: No input validation, escaping, or sanitization logic is provided for external data before it is passed to the Remotion bundler or renderer.
  • [EXTERNAL_DOWNLOADS]: The skill fetches documentation and instructions from remotion.dev and retrieves animation assets from lottiefiles.com. These are well-known services relevant to the skill's primary purpose and are documented neutrally.
  • [COMMAND_EXECUTION]: The skill includes instructions for common developer operations such as scaffolding projects with create-video, rendering via the Remotion CLI, and managing serverless deployments for video processing.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 27, 2026, 05:09 AM
Security Audit — agent-trust-hub — remotion-video-toolkit