Back to skill

Security audit

Remotion

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly coherent Remotion guidance, but it repeatedly tells agents to run unpinned package-manager commands and includes an arbitrary URL-fetching metadata example without security scoping.

Review before installing or using this skill in agent-assisted coding. Prefer pinned Remotion package versions and lockfile-controlled installs, and do not copy the arbitrary dataUrl fetch pattern into render services that accept untrusted props unless you add URL allowlisting, timeouts, response limits, and network egress controls.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Warning
Location
rules/audio.md:15
Finding

Unpinned Package-Runner Commands Permit Mutable Supply-Chain Execution

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
rules/calculate-metadata.md:79
Finding

Caller-Controlled Metadata URL Can Enable Server-Side Request Forgery

Content
View full analysis
= async ({props, abortSignal}) => { const response = await fetch(props.dataUrl, {signal: abortSignal}); const data = await response.json(); return { props: { ...props, fetchedData: data, }, }; }; ``` ### Technical Analysis The example passes `props.dataUrl` directly to `fetch()` without validating the URL scheme, hostname, destination address, port, or redirect chain. It also lacks explicit response-size limits, a fixed request timeout, status validation, and content-type validation. Remotion metadata calculation may execute as part of a rendering workflow. If this pattern is used by a server-side renderer that accepts untrusted composition properties, the request originates from the renderer rather than from the external caller. Consequently, the renderer can be induced to reach services that are inaccessible to the attacker directly. The supplied `abortSignal` only allows stale requests to be cancelled when properties change. It does not prevent requests to private networks and does not provide a complete security timeout or response-size control. ### Attack Path 1. An application exposes a rendering or metadata endpoint that accepts composition properties from a user. 2. The attacker supplies a `dataUrl` pointing to a loopback, link-local, private-network, cloud metadata, or other internal endpoint. 3. `calculateMetadata()` executes in the renderer and calls `fetch()` with the attacker-controlled URL. 4. The server follows the request, and potentially redirects, using its own network position. 5. The response is parsed as JSON and placed in `fetchedData`. 6. If rendered data or met ...[truncated 1074 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (17)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

Line L10 says to use the skill "whenever you are dealing with Remotion code," which is a very broad condition rather than a narrowly scoped trigger. It does not define boundaries, exclusions, or specific trigger phrases, increasing the chance of unintended invocation across routine Remotion conversations.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The documentation instructs users to run npx remotion add @remotion/three without pinning a specific package version. npx may fetch the latest package and execute package-provided code, which creates a supply-chain risk if a malicious or compromised release is published or if behavior changes unexpectedly over time.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · rules/compositions.md (reported line 117)May include surrounding context.

md
props,
  abortSignal,
}) => {
  const data = await fetch(`https://api.example.com/video/${props.videoId}`, {
    signal: abortSignal,
  }).then((res) => res.json());

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The documentation recommends executing npx remotion without pinning a specific package version, which can cause users to fetch and run whatever version is current at execution time. If the upstream package, dependency chain, or distribution channel is compromised, users may execute unintended code, making this a real supply-chain risk even though the example is instructional.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The documentation instructs users to run npx remotion add @remotion/google-fonts without pinning a specific package version. This can lead to non-reproducible installs and exposes users to supply-chain risk if a newer malicious or compromised version of remotion is published, because npx resolves and executes the latest matching package by default.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The documentation again recommends npx remotion add @remotion/fonts without an explicit version. Unpinned execution of package manager helper commands increases supply-chain exposure and can cause unexpected behavior or execution of compromised future releases in developer environments.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · rules/gifs.md (reported line 57)May include surrounding context.

Control what happens when the animation finishes:

tsx
// Loop indefinitely (default)
<AnimatedImage src={staticFile("animation.gif")} width={500} height={500} loopBehavior="loop" />

// Play once, show final frame

Rp1

Medium
Category
MCP Rug Pull
Confidence
94% confidence
Finding

The documentation recommends executing npx remotion without pinning an exact package version, which can cause users to run whatever version is current at execution time. In the event of a compromised upstream package, typo-squatting, or a malicious/broken newly published release, this creates a supply-chain risk because arbitrary package code may be fetched and executed on the user's system.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
89% confidence
Finding

The documentation instructs users to run npx remotion add @remotion/transitions without pinning a specific version of the CLI or package. This can cause users to fetch and execute whatever version is current at the time, creating a supply-chain risk if an upstream package is compromised or a breaking/malicious release is published.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation explicitly encourages loading audio from remote URLs without any warning that this causes external network requests and may leak user IP address, request metadata, or access patterns to third parties. In rendering or preview environments, remote media can also create reliability and compliance issues if untrusted or unavailable external content is fetched at runtime.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This markdown example instructs users to fetch data from props.dataUrl before rendering, which implies outbound network access and transmission of request metadata or user-supplied URLs. Under the markdown-specific warning criterion, the document does not mention any privacy, security, or trust considerations for remote requests.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.