Back to skill

Security audit

Remotion Server

Security checks across malware telemetry and agentic risk

Overview

This skill is a normal Remotion video-rendering helper; its setup changes the local environment but the behavior is disclosed and aligned with that purpose.

Install this only on a Linux machine where you are comfortable allowing system package installation and npm dependency downloads. Review sudo prompts and generated project content before rendering or publishing videos, especially because the example requests are broad enough that an agent should confirm before running setup or creating a project.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (1)

Vague Triggers

Medium
Confidence
93% confidence
Finding
The example invocation phrases are generic enough to resemble normal user requests, which can cause the assistant to trigger this skill unintentionally when a user simply asks to make a video or promo. In an agent environment, broad trigger language increases the chance of accidental execution of setup, project creation, or rendering workflows without clear user intent to invoke this specific skill.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.