remotion-markup

Pass

Audited by Gen Agent Trust Hub on Sep 12, 2026

Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches external libraries and data from well-known services including Cesium, MapTiler, Mapbox, Google Maps, and ElevenLabs to support advanced visualization and media features.
  • [COMMAND_EXECUTION]: Employs standard CLI commands for Remotion project management, such as npx remotion add for package installation, npx remotion studio for previewing, and npx remotion ffmpeg for media processing.
  • [REMOTE_CODE_EXECUTION]: The skill contains logic to dynamically load the CesiumJS library from a well-known CDN at runtime into the browser environment.
  • [INDIRECT_PROMPT_INJECTION]: Ingests and processes user-supplied React code and media assets; contains defensive instructions for the agent to preserve user edits and ask for confirmation before overwriting changes, reducing the risk of accidental or malicious instruction overrides.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 12, 2026, 01:49 PM
Security Audit — agent-trust-hub — remotion-markup