Back to skill

Security audit

Remotion Best Practices

Security checks for vulnerabilities and agentic risk

Overview

This skill is a coherent Remotion video-development guide, but users should be careful with unpinned npm commands and AWS credential handling.

Install only if you are comfortable with a developer workflow that runs npm/npx commands. Prefer pinned Remotion versions or a project-local locked CLI, avoid blindly using @latest in CI, and use scoped or short-lived AWS credentials if following the optional Lambda rendering guide.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (1)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:30
Finding

Unpinned npm Package Retrieval and Execution

Content
View full analysis

Vulnerability Details

File Locations:

  • SKILL.md:30-34
  • references/setup.md:7-13
  • references/setup.md:97-109
  • references/animations.md:343-349
  • references/lambda.md:37-43

Vulnerability Type: Unpinned and mutable third-party dependencies
Risk Level: Medium

Vulnerable Code

SKILL.md:30-34:

bash
- If not found: scaffold a new project:

```bash
npx create-video@latest my-video
text

`references/setup.md:7-13`:

```bash
Create a new Remotion project using the official scaffolding tool:

```bash
npx create-video@latest my-video
cd my-video
npm install
text

`references/setup.md:97-109`:

```bash
Verify version alignment:

```bash
npm ls | grep remotion

If versions are mismatched, update all at once:

bash
npm install remotion@latest @remotion/cli@latest @remotion/bundler@latest

If you use optional packages, include them in the update:

bash
npm install remotion@latest @remotion/cli@latest @remotion/bundler@latest @remotion/player@latest @remotion/lambda@latest @remotion/media-utils@latest @remotion/transitions@latest
text

`references/animations.md:343-349`:

```bash
### Installation

```bash
npm install @remotion/transitions

Ensure the version matches your other @remotion/* packages.

text

`references/lambda.md:37-43`:

```bash
### Package Installation

```bash
npm install @remotion/lambda

Ensure the version matches your other @remotion/* packages.

text

### Technical Analysis

The Skill instructs an Agent or user to retrieve npm packages through mutable version selectors such as `@latest`, as well as unconstrained package names. In particular, `npx create-video@latest` downloads and immediately runs the package version associated with the `latest` registry tag at invocation time.

This means the effective code executed by the documented workflow can differ from the code that 
...[truncated 2173 chars]
Remediation
View remediation

Remediation Suggestions

  1. Replace mutable selectors such as @latest with exact, reviewed versions:

    bash
    npx create-video@X.Y.Z my-video
    npm install --save-exact remotion@X.Y.Z @remotion/cli@X.Y.Z @remotion/bundler@X.Y.Z
    
  2. Pin every Remotion package to the same exact version, including optional packages such as @remotion/lambda and @remotion/transitions.

  3. Commit a reviewed package-lock.json and use reproducible installation in existing projects:

    bash
    npm ci
    
  4. Require package provenance, publisher, registry, and integrity verification before first execution or version upgrades.

  5. Configure npm to use an explicitly trusted registry rather than inheriting an unverified registry configuration.

  6. Where dependency lifecycle scripts are unnecessary, initially install with:

    bash
    npm install --ignore-scripts
    

    Any required lifecycle script should be reviewed before it is enabled.

  7. Perform version upgrades as explicit, separately reviewed changes rather than automatically installing the current release.

  8. Run scaffolding and installation commands in a least-privileged, isolated development environment without unrelated credentials in environment variables.

Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
Findings (28)

Vague Triggers

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The skill description says to use this skill when the user wants to create videos programmatically, and also lists broad phrases such as 'create video' and 'render video'. These phrases are common and not narrowly constrained to Remotion or React contexts, which makes the activation scope ambiguous and increases the chance of accidental routing.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill instructs use of npx create-video@latest, which pulls and executes the latest remote package at runtime rather than a reviewed, pinned version. If the upstream package, dependency chain, or publish account is compromised, users may execute untrusted code during project scaffolding.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
82% confidence
Finding

The skill directs users to run npx remotion preview ... without pinning the CLI version. npx may fetch and execute a package version different from the project's reviewed dependency set, creating supply-chain and reproducibility risk if the remote package is tampered with or unexpectedly updated.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
82% confidence
Finding

The render command uses npx remotion render ... without specifying an exact version, which can cause execution of an unpinned remote CLI. In a developer workflow skill, this creates a realistic supply-chain exposure because users are encouraged to run the command directly on their machines.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
82% confidence
Finding

This command again relies on npx remotion render ... with unpinned package resolution, here additionally passing JSON props. The main issue is not the props but that the skill normalizes direct execution of whatever CLI version npx resolves at runtime.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

The output-format section requires providing an exact npx remotion render command but does not require version pinning, reinforcing unsafe package execution patterns. Repetition increases the likelihood that users will copy-paste an unreviewed remote CLI command.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
80% confidence
Finding

The preview command requirement similarly specifies npx remotion preview src/index.ts without pinning. In context, this is operational guidance intended for direct execution, so it meaningfully increases supply-chain risk despite being common developer documentation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The file shows users how to export long-lived AWS credentials directly into environment variables but does not include any warning about secret handling, least privilege, rotation, or safer alternatives. While environment variables are common, presenting raw credential setup without caution increases the chance of accidental exposure through shell history, screenshots, logs, shared terminals, or misuse of overly privileged keys. In this skill's cloud-rendering context, compromised AWS credentials could enable unauthorized access to Lambda, S3, and related billing-impacting resources.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

The documentation tells users to invoke npx remotion without pinning a specific package version. npx may fetch the latest published package at execution time, which creates a supply-chain risk: users can get unexpected or malicious code if the upstream package is compromised or a breaking release is published. In a developer-facing skill, this is materially relevant because readers may copy-paste these commands directly into production or CI environments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

This example again uses unpinned npx remotion, which can cause execution of whatever version is currently published rather than a reviewed, expected version. That increases supply-chain exposure and reproducibility issues, especially since the command uploads code bundles to AWS-backed infrastructure. The skill context makes this somewhat more sensitive because it targets cloud deployment workflows that may run with privileged credentials.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
87% confidence
Finding

Using npx remotion for rendering without a fixed version exposes users to the same package-resolution risk: the command can execute updated or compromised code at runtime. Because this render step operates with AWS credentials and produces artifacts in S3, an attacker controlling the package distribution path could potentially misuse cloud access or tamper with outputs.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

The status-check command also uses unpinned npx remotion, preserving the same risk of executing an unexpected package version. While this specific command is lower impact than deployment or rendering, it still normalizes insecure command patterns and may run in credentialed environments. The educational context reduces suspicion of malicious intent, but not the underlying supply-chain concern.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The documentation instructs users to invoke npx remotion without pinning a specific package version. npx may fetch the latest published package at execution time, which creates a supply-chain risk: a compromised upstream release or unexpected breaking change could run arbitrary code on the user's machine.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This example uses npx remotion preview without a pinned version, allowing npx to resolve and execute whatever current package version is available. That exposes users to package substitution, malicious upstream releases, or nondeterministic behavior across environments.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The render command at this line relies on npx remotion without version pinning. In documentation, such patterns normalize executing transient, unpinned packages, increasing supply-chain exposure if the package or one of its install-time dependencies is compromised.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The JPEG quality example invokes npx remotion unpinned, which can cause users to execute an arbitrary newer package version at runtime. Since CLI packages may run install scripts and full application code, this is a meaningful supply-chain risk rather than a purely stylistic issue.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This resolution override example uses npx remotion without a fixed version. Unpinned executable package references in user-facing docs can lead to arbitrary code execution through a compromised package release or accidental execution of incompatible versions.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

Passing props is not itself the issue; the vulnerability is that the command executes npx remotion without pinning a version. Because the skill is instructional, repeated unsafe examples amplify the chance that users adopt insecure operational habits.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The still-image render example again relies on transient execution of an unpinned package via npx. If a malicious or tampered version is resolved, the user may execute attacker-controlled code locally while following otherwise routine documentation.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The production video example recommends an unpinned npx remotion invocation. Because this is framed as a standard workflow, it may be copied directly into CI or production build pipelines, extending supply-chain risk beyond local development.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

This fast-preview example also uses npx remotion without version pinning. Even for preview workflows, unpinned package execution can result in malicious code execution or unstable behavior if upstream packages change unexpectedly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The social-upload example includes another unpinned npx remotion execution path. Repetition across the document increases the likelihood that users internalize unsafe copy-paste commands, making the documentation context more dangerous than a one-off mention.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The PNG-sequence example uses unpinned npx remotion, which may fetch and execute arbitrary package code. This is especially relevant because render commands are likely to be run on developer workstations or build runners with filesystem access.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The WebM example repeats the same unpinned npx remotion pattern, carrying the same supply-chain and reproducibility risks. In an instructional skill, these repeated examples are actionable commands, so the risk is practical rather than theoretical.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
95% confidence
Finding

The documentation instructs users to execute npx create-video@latest, which fetches and runs the latest package version at execution time. This creates a supply-chain risk: if the package is compromised or a breaking/malicious version is published, users may execute unreviewed code on their machine. In a setup guide, this is more dangerous because readers are likely to copy-paste commands directly.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.