remotion-best-practices

Pass

Audited by Gen Agent Trust Hub on Feb 28, 2026

Risk Level: SAFEPROMPT_INJECTIONEXTERNAL_DOWNLOADSCOMMAND_EXECUTION
Full Analysis
  • [PROMPT_INJECTION]: The skill demonstrates patterns for fetching data from external URLs (e.g., rules/calculate-metadata.md, rules/compositions.md, and rules/lottie.md) and using it to populate component properties or metadata. This creates an indirect prompt injection surface where untrusted data could influence agent behavior.\n
  • Ingestion points: rules/calculate-metadata.md, rules/compositions.md, and rules/lottie.md.\n
  • Boundary markers: Code examples lack delimiters for external data.\n
  • Capability inventory: Examples use fetch for network requests.\n
  • Sanitization: No data sanitization or validation is demonstrated.\n- [EXTERNAL_DOWNLOADS]: The documentation describes installing various official @remotion/* packages and the mediabunny utility. These are standard dependencies for the Remotion ecosystem.\n- [COMMAND_EXECUTION]: The skill includes example shell commands for adding project dependencies using npx, yarn, pnpm, and bun.
Audit Metadata
Risk Level
SAFE
Analyzed
Feb 28, 2026, 11:38 AM