remotion-best-practices

Pass

Audited by Gen Agent Trust Hub on Feb 16, 2026

Risk Level: LOW
Full Analysis
  • [Prompt Injection] (SAFE): No instructions attempting to override agent behavior, bypass safety filters, or extract system prompts were detected.- [Data Exposure & Exfiltration] (SAFE): The file does not contain hardcoded credentials, access sensitive local file paths, or perform unauthorized network requests.- [Obfuscation] (SAFE): No Base64, zero-width characters, homoglyphs, or other encoding techniques were used to hide content.- [Unverifiable Dependencies & Remote Code Execution] (SAFE): References common, trusted libraries in the React/Remotion ecosystem (e.g., Three.js, Tailwind, Zod). No instances of piping remote scripts to a shell (curl|bash) were found.- [Indirect Prompt Injection] (LOW): The skill describes processing external assets like SRT subtitles and video metadata. However, as a documentation skill, it lacks the automated write or execute capabilities required for a high-severity exploitation surface.- [Privilege Escalation & Persistence] (SAFE): No commands related to sudo, administrative access, or persistent mechanism installation (cron, startup scripts) were identified.
Audit Metadata
Risk Level
LOW
Analyzed
Feb 16, 2026, 05:53 AM