remotion-render

Fail

Audited by Socket on Feb 25, 2026

1 alert found:

Malware
MalwareHIGH
SKILL.md

The Remotion-render workflow is coherent and technically plausible for cloud-assisted rendering, but relies on a curl-based installation and external binary distribution, which constitutes notable supply-chain and remote-code-execution risk. While there is some checksum verification described, the lack of explicit signing, pinning, or reproducible builds lowers assurance. Treat as SUSPICIOUS with recommendations to adopt signed installers, pinning of binaries, reproducible builds, and minimized exposure of user code to remote services. Overall risk is moderate to high due to the install/vector insecurity and external dependencies.

Confidence: 95%Severity: 90%
Audit Metadata
Analyzed At
Feb 25, 2026, 05:37 PM
Package URL
pkg:socket/skills-sh/inference-sh-9%2Fskills%2Fremotion-render%2F@11f76206ad3a76f94466025d329107161f73488d