marketing-video
Pass
Audited by Gen Agent Trust Hub on Apr 20, 2026
Risk Level: SAFECOMMAND_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATION
Full Analysis
- [COMMAND_EXECUTION]: Executes shell commands for initial environment setup, telemetry logging, and automated discovery of project assets such as images, SVG logos, and brand colors from CSS/Tailwind configurations.\n- [EXTERNAL_DOWNLOADS]: Downloads and installs the official Remotion skills repository and numerous standard Remotion utility packages from NPM (e.g., transitions, fonts, noise, captions). It also handles the installation of well-known third-party binaries like
whisper.cppfor automated captioning.\n- [DATA_EXFILTRATION]: Implements a telemetry system that tracks skill usage metrics, platform information, and timestamps. The skill demonstrates good security practice by explicitly asking for user consent before enabling telemetry and providing instructions on how to disable it via a local configuration file.\n- [INDIRECT_PROMPT_INJECTION]: The agent reads project-level files (package.json,.superstack/idea-context.md, etc.) to inform the creative direction of the video. While this creates a potential surface for indirect injection, the risk is minimized by the requirement for manual user approval of the creative brief prior to code generation and rendering.
Audit Metadata