Back to skill

Security audit

Remotion

Security checks across malware telemetry and agentic risk

Overview

This is a documentation-only Remotion guidance skill with normal cautions around package installs and remote media URLs.

Reasonable to install as Remotion reference material. Before copying examples, review package-manager commands, install only packages you intend to add to the target project, and use local or trusted remote media because remote assets and fetch examples can contact external hosts during preview or rendering.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
Findings (1)

Missing User Warnings

Low
Confidence
91% confidence
Finding
The documentation explicitly encourages loading remote images via arbitrary HTTPS URLs but does not mention that doing so causes outbound requests to third-party hosts during preview/rendering. This can leak IP address, timing, and possibly sensitive URL-derived identifiers, and may create supply-chain or reliability risks if external assets change or disappear.

VirusTotal

64/64 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.