T08 · Insecure Dependencies
- Location
rules/audio.md:15- Finding
Unpinned Package-Runner Commands Permit Mutable Supply-Chain Execution
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill is mostly coherent Remotion guidance, but it repeatedly tells agents to run unpinned package-manager commands and includes an arbitrary URL-fetching metadata example without security scoping.
Review before installing or using this skill in agent-assisted coding. Prefer pinned Remotion package versions and lockfile-controlled installs, and do not copy the arbitrary dataUrl fetch pattern into render services that accept untrusted props unless you add URL allowlisting, timeouts, response limits, and network egress controls.
rules/audio.md:15Unpinned Package-Runner Commands Permit Mutable Supply-Chain Execution
rules/calculate-metadata.md:79Caller-Controlled Metadata URL Can Enable Server-Side Request Forgery
Line L10 says to use the skill "whenever you are dealing with Remotion code," which is a very broad condition rather than a narrowly scoped trigger. It does not define boundaries, exclusions, or specific trigger phrases, increasing the chance of unintended invocation across routine Remotion conversations.
The documentation instructs users to run npx remotion add @remotion/three without pinning a specific package version. npx may fetch the latest package and execute package-provided code, which creates a supply-chain risk if a malicious or compromised release is published or if behavior changes unexpectedly over time.
Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.
props,
abortSignal,
}) => {
const data = await fetch(`https://api.example.com/video/${props.videoId}`, {
signal: abortSignal,
}).then((res) => res.json());
The documentation recommends executing npx remotion without pinning a specific package version, which can cause users to fetch and run whatever version is current at execution time. If the upstream package, dependency chain, or distribution channel is compromised, users may execute unintended code, making this a real supply-chain risk even though the example is instructional.
The documentation instructs users to run npx remotion add @remotion/google-fonts without pinning a specific package version. This can lead to non-reproducible installs and exposes users to supply-chain risk if a newer malicious or compromised version of remotion is published, because npx resolves and executes the latest matching package by default.
The documentation again recommends npx remotion add @remotion/fonts without an explicit version. Unpinned execution of package manager helper commands increases supply-chain exposure and can cause unexpected behavior or execution of compromised future releases in developer environments.
Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.
Control what happens when the animation finishes:
// Loop indefinitely (default)
<AnimatedImage src={staticFile("animation.gif")} width={500} height={500} loopBehavior="loop" />
// Play once, show final frame
The documentation recommends executing npx remotion without pinning an exact package version, which can cause users to run whatever version is current at execution time. In the event of a compromised upstream package, typo-squatting, or a malicious/broken newly published release, this creates a supply-chain risk because arbitrary package code may be fetched and executed on the user's system.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.
The documentation instructs users to run npx remotion add @remotion/transitions without pinning a specific version of the CLI or package. This can cause users to fetch and execute whatever version is current at the time, creating a supply-chain risk if an upstream package is compromised or a breaking/malicious release is published.
The documentation explicitly encourages loading audio from remote URLs without any warning that this causes external network requests and may leak user IP address, request metadata, or access patterns to third parties. In rendering or preview environments, remote media can also create reliability and compliance issues if untrusted or unavailable external content is fetched at runtime.
This markdown example instructs users to fetch data from props.dataUrl before rendering, which implies outbound network access and transmission of request metadata or user-supplied URLs. Under the markdown-specific warning criterion, the document does not mention any privacy, security, or trust considerations for remote requests.
No suspicious patterns detected.