Back to skill

Security audit

Remotion Best Practices

Security checks for vulnerabilities and agentic risk

Overview

This is a Remotion guidance skill with no hidden execution, but its examples should be used carefully around remote URLs and package installs.

Before installing, treat this as a Remotion reference skill rather than security-hardened production guidance. Ask your agent to confirm before running package-manager commands, prefer pinned versions and lockfiles, and validate or allowlist any remote URLs used in server-side rendering or metadata extraction.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T09 · Insecure Skill Coding Practices

Warning
Location
rules/calculate-metadata.md:79
Finding

Unrestricted User-Controlled URL Fetching May Enable Server-Side Request Forgery

Content
View full analysis
= async ({props, abortSignal}) => { const response = await fetch(props.dataUrl, {signal: abortSignal}); const data = await response.json(); return { props: { ...props, fetchedData: data, }, }; }; ``` The related `UrlSource` example accepts an arbitrary source string in the same manner: ```tsx export const canDecode = async (src: string) => { const input = new Input({ formats: ALL_FORMATS, source: new UrlSource(src, { getRetryDelay: () => null, }), }); try { await input.getFormat(); } catch { return false; } const videoTrack = await input.getPrimaryVideoTrack(); if (videoTrack && !(await videoTrack.canDecode())) { return false; } const audioTrack = await input.getPrimaryAudioTrack(); if (audioTrack && !(await audioTrack.canDecode())) { return false; } return true; }; ``` ### Technical Analysis The documented implementation passes `props.dataUrl` directly to `fetch()` without validating the URL scheme, hostname, resolved address, port, or redirect destination. If composition properties can be supplied by an untrusted user and metadata calculation runs in a server-side Remotion renderer, the renderer can be induced to issue requests from its privileged network context. The `UrlSource` helpers have the same trust-boundary issue. They accept arbitrary strings and may perform network requests while parsing media metadata. No controls ...[truncated 1986 chars]
Remediation
View remediation

T08 · Insecure Dependencies

Note
Location
rules/audio.md:12
Finding

Unpinned Package-Runner Installation Commands Create Supply-Chain Exposure

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The phrase "Use this skills whenever you are dealing with Remotion code" is a broad activation condition without clear boundaries, exclusions, or specific trigger phrases. This could cause the skill to be invoked in many ordinary Remotion-related contexts where the user may not actually want this particular best-practices skill.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · rules/compositions.md (reported line 117)May include surrounding context.

md
props,
  abortSignal,
}) => {
  const data = await fetch(`https://api.example.com/video/${props.videoId}`, {
    signal: abortSignal,
  }).then((res) => res.json());

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The documentation instructs users to run npx remotion without pinning an exact package version, which can cause execution of whatever version is currently published or resolved at install time. If the upstream package, a dependency, or the registry resolution path is compromised, users may execute unintended code during installation or CLI invocation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The documentation instructs users to run npx remotion add @remotion/google-fonts without pinning the package version, which can fetch and execute whatever version is current at install time. In a supply-chain compromise or unexpected upstream release, this could lead to execution of unreviewed code on the developer's machine during setup.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

This example again uses npx remotion add @remotion/fonts without a pinned version, causing users to execute a mutable remote package version at install time. That creates a supply-chain risk because a malicious or compromised upstream package release could run arbitrary code in the user's environment.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · rules/gifs.md (reported line 57)May include surrounding context.

Control what happens when the animation finishes:

tsx
// Loop indefinitely (default)
<AnimatedImage src={staticFile("animation.gif")} width={500} height={500} loopBehavior="loop" />

// Play once, show final frame

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The documentation instructs users to run npx remotion without pinning an exact package version, which can cause execution of whatever version is currently resolved from the registry. In a supply-chain compromise or typo/namespace issue, this could lead to running unexpected code on the developer machine during installation or scaffolding.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The documentation instructs users to run npx remotion without pinning a specific package version, which can fetch and execute whatever version is current at install time. This creates a supply-chain risk: if a malicious or compromised release is published, users may execute unintended code during setup.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
86% confidence
Finding

The documentation instructs users to run npx remotion add ... without pinning the remotion package version. npx may fetch the latest published package at execution time, which creates a supply-chain risk: a compromised, typosquatted, or unexpectedly changed upstream release could execute code on the user's machine. In a skill that gives copy-pastable install commands, this is more dangerous because users are likely to execute them directly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The documentation instructs users to run npx remotion add @remotion/transitions without pinning a specific package version. This can cause execution of whatever version is current at install time, which increases supply-chain risk if a compromised or unexpected release is published, especially because npx may fetch and execute code directly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

The documentation explicitly encourages loading remote images directly via HTTPS without warning that this causes external network access during rendering. In a video-rendering context, this can leak IP address, timing, and request metadata to third parties, and can introduce tracking, reliability, or supply-chain risks if remote assets change or become unavailable.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown file includes an example using a remote URL as the src for a video, which implies a network request to an external host. The surrounding documentation does not warn that using remote media may transmit request metadata or depend on external resources, so users are not alerted to the privacy and network implications.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.