Back to skill

Security audit

/remotion-best-practices

Security checks for vulnerabilities and agentic risk

Overview

This skill is a Remotion workflow router with purpose-aligned documentation and examples, but users should run its package-manager and provider-key steps deliberately.

Install this if you want an agent to help build and maintain Remotion projects. Review commands before running them, prefer pinned or lockfile-backed package execution, keep provider credentials in environment files rather than chat, and verify map-provider attribution and licensing terms before hiding logos or attribution.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (115)

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is a router for all Remotion skills, implying dispatch/orchestration behavior. The actual code does not perform any routing, triggering, or skill coordination. Instead, it implements a specialized geospatial algorithm for smoothing longitude/latitude paths for a Cesium/remotion maps flight path. This is a materially different primary purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says this skill is a 'Router for all Remotion skills,' which suggests generic routing or dispatch functionality. The supplied code does not implement any router behavior. Instead, it specifically integrates MapTiler vector tiles into a map by adding a vector source pointing to the MapTiler API, adding layers with styling/filter configuration, and updating paint properties over time. This is a materially different primary purpose from routing, and it also accesses an external MapTiler resource not implied by the description. Therefore, the description does not accurately represent the code's actual behavior.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
96% confidence
Finding

The declared description says this skill is a router for all Remotion skills, which suggests control-flow or delegation logic. The supplied code does not route, dispatch, invoke, or coordinate any skills. It only exports constant values for colors, country fills, video settings, and timing. This is a materially different primary purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
99% confidence
Finding

The declared description says this skill is a router for all Remotion skills, which implies dispatch/orchestration behavior. The supplied code does not perform routing, triggering, or skill coordination. Instead, it implements a specific geometry utility for smoothing longitude/latitude paths and handling antimeridian crossings. This is a materially different primary purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
97% confidence
Finding

The declared description says this skill is a router for all Remotion skills, which suggests coordination or dispatch logic. The supplied code does not implement routing behavior. Instead, it provides concrete map-rendering helpers specific to MapTiler vector elements, including adding an external vector tile source and mutating layer paint properties. This is a materially different primary purpose and includes external resource access not implied by the declaration.

Content

No source excerpt is available for this finding.

Tp4

High
Category
MCP Tool Poisoning
Confidence
98% confidence
Finding

The declared description says this skill is a router for all Remotion skills, implying dispatch/orchestration behavior. The supplied code does not implement any routing logic, triggers, or skill coordination. Instead, it exports static constants used for map visualization styling and video timing in a Remotion project. This is a materially different primary purpose, so the description does not accurately represent the code.

Content

No source excerpt is available for this finding.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · remotion-maps/techniques/mapbox/TECHNIQUE.md (reported line 8)May include surrounding context.

md
tags: map, map animation, mapbox, turf, geojson, route animation
---

Use Mapbox GL JS for rendering maps in Remotion when the user wants Mapbox styles or higher-fidelity map visuals and has a Mapbox access token. Use Turf for geospatial operations such as great-circle routes, distances, slicing lines, and positions along routes.

Use this technique only when the user has a Mapbox access token and wants Mapbox styles or data.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · remotion-maps/techniques/mapbox/TECHNIQUE.md (reported line 10)May include surrounding context.

md
tags: map, map animation, mapbox, turf, geojson, route animation
---

Use Mapbox GL JS for rendering maps in Remotion when the user wants Mapbox styles or higher-fidelity map visuals and has a Mapbox access token. Use Turf for geospatial operations such as great-circle routes, distances, slicing lines, and positions along routes.

Use this technique only when the user has a Mapbox access token and wants Mapbox styles or data.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · remotion-maps/techniques/mapbox/TECHNIQUE.md (reported line 63)May include surrounding context.

md
tags: map, map animation, mapbox, turf, geojson, route animation
---

Use Mapbox GL JS for rendering maps in Remotion when the user wants Mapbox styles or higher-fidelity map visuals and has a Mapbox access token. Use Turf for geospatial operations such as great-circle routes, distances, slicing lines, and positions along routes.

Use this technique only when the user has a Mapbox access token and wants Mapbox styles or data.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · remotion-markup/remotion-maps/techniques/mapbox/TECHNIQUE.md (reported line 8)May include surrounding context.

md
tags: map, map animation, mapbox, turf, geojson, route animation
---

Use Mapbox GL JS for rendering maps in Remotion when the user wants Mapbox styles or higher-fidelity map visuals and has a Mapbox access token. Use Turf for geospatial operations such as great-circle routes, distances, slicing lines, and positions along routes.

Use this technique only when the user has a Mapbox access token and wants Mapbox styles or data.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · remotion-markup/remotion-maps/techniques/mapbox/TECHNIQUE.md (reported line 10)May include surrounding context.

md
tags: map, map animation, mapbox, turf, geojson, route animation
---

Use Mapbox GL JS for rendering maps in Remotion when the user wants Mapbox styles or higher-fidelity map visuals and has a Mapbox access token. Use Turf for geospatial operations such as great-circle routes, distances, slicing lines, and positions along routes.

Use this technique only when the user has a Mapbox access token and wants Mapbox styles or data.

Credential Access

High
Category
Privilege Escalation
Confidence
70% confidence
Finding

Code accesses credential files (SSH keys, AWS credentials, etc.). This could indicate credential theft attempts.

Content

Scanner excerpt · remotion-markup/remotion-maps/techniques/mapbox/TECHNIQUE.md (reported line 63)May include surrounding context.

md
tags: map, map animation, mapbox, turf, geojson, route animation
---

Use Mapbox GL JS for rendering maps in Remotion when the user wants Mapbox styles or higher-fidelity map visuals and has a Mapbox access token. Use Turf for geospatial operations such as great-circle routes, distances, slicing lines, and positions along routes.

Use this technique only when the user has a Mapbox access token and wants Mapbox styles or data.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The manifest says this skill is a router for Remotion skills, but this file implements a full React/Remotion map animation component with geometry processing, map layer creation, and frame-by-frame visual updates. That is a substantive behavioral mismatch rather than an implementation detail of routing.

Content

No source excerpt is available for this finding.

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
88% confidence
Finding

A broad description like 'Router for all Remotion skills' can cause overly permissive matching and unintended invocation across many unrelated Remotion requests. In agentic systems, over-broad routing increases the chance of loading unnecessary capabilities or sensitive subskills, which can expand attack surface and lead to confused-deputy behavior.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
82% confidence
Finding

Referencing npx remotion render without pinning a package version can cause execution of whatever package version is currently resolved from the registry. In environments that actually follow this guidance, this increases supply-chain risk and can lead to unexpected or malicious code execution through an upstream package compromise or breaking change.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The documentation instructs users to run npx remotion add @remotion/install-whisper-cpp without pinning the remotion package to a specific version. npx resolves and executes a package version from the registry at runtime, so a compromised latest release or unexpected upstream change could execute unreviewed code on the user's machine during installation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The instruction uses npx create-video@latest, which fetches and executes the latest package version at runtime rather than a pinned, reviewed version. In an agent or automation context this creates a supply-chain execution risk: a compromised upstream package, malicious publish, or breaking change could lead to arbitrary code execution on the host.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The command npx remotion studio --no-open executes a package via npx without an explicitly pinned version in the command itself. If the package is not already installed locally and locked, npx may resolve and run an unintended or newly published version, introducing supply-chain risk and reducing reproducibility.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The instruction npx remotion render has the same issue: it may execute an unpinned package version if resolution falls back to remote fetching. In a code-generation or agent workflow, this can expose the environment to arbitrary code from the package supply chain and make builds non-deterministic.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The documentation explicitly instructs users to hide MapTiler logo and attribution UI elements via component settings and CSS, without any warning to verify license terms or preserve required attribution. This can cause downstream users to violate contractual or attribution obligations, creating legal/compliance risk and encouraging deceptive presentation of third-party map data provenance.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The documentation instructs users to execute npx remotion without pinning a specific package version, which can fetch and run whatever version is currently published. This creates a supply-chain risk: a compromised, typosquatted, or unexpectedly changed package release could execute arbitrary code in the user's environment during installation or invocation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
93% confidence
Finding

The documentation instructs users to run npx remotion add @remotion/media without pinning the package version. npx may resolve and execute whatever version is current at runtime, which creates a supply-chain risk and can lead to unexpected code execution or incompatible behavior if the upstream package changes or is compromised. In a skill file, this is more dangerous because users may copy-paste the command directly into a shell.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The guidance recommends npx remotion studio --no-open, which executes an unpinned package from the registry. If the package version changes or the package is ever hijacked, users could run unintended code; even absent compromise, behavior may drift from the documented expectations. Because this appears in operational instructions, it is likely to be executed as-is by end users.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The example URL-check workflow relies on npx remotion again without version pinning, exposing users to the same supply-chain and reproducibility risks. Unpinned executable fetches are especially risky in documentation because they normalize ad hoc remote code execution from package registries. The skill context increases likelihood of execution since this is presented as a recommended validation step.

Content

No source excerpt is available for this finding.

Static analysis

Detected: suspicious.exposed_secret_literal

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
remotion-docs/REFERENCE.md:15

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
remotion-maps/techniques/mapbox/TECHNIQUE.md:101

File appears to expose a hardcoded API secret or token.

Critical
Code
suspicious.exposed_secret_literal
Location
remotion-markup/remotion-maps/techniques/mapbox/TECHNIQUE.md:101