Back to skill

Security audit

Remotion Animator

Security checks for vulnerabilities and agentic risk

Overview

This video-generation skill is mostly purpose-aligned, but its helper scripts and dependency setup can affect more of the filesystem and network supply chain than its own permissions describe.

Review this before installing. Use only simple relative project names and project-local output paths, do not enable recurring cron renders unless the schedule, output folder, retention, and removal method are explicit, and consider pinning dependencies with a lockfile before running npm install or rendering.

Vulnerability Patterns
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/new-project.py:31
Finding

Unrestricted project destination permits writes outside the workspace

Content
View full analysis
Remediation
View remediation

T05 · Unauthorized Access and Privilege Escalation

Warning
Location
scripts/render.py:20
Finding

Unrestricted render output path permits writes and overwrites outside the project

Content
View full analysis
Remediation
View remediation

T08 · Insecure Dependencies

Warning
Location
assets/boilerplate/package.json:5
Finding

Mutable dependencies and implicit npx installation make execution non-reproducible

Content
View full analysis
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Behavioral ASTexec() Call, eval() Call, Dynamic Import
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
Findings (21)

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
70% confidence
Finding

Without declared permissions the skill's intent is opaque and cannot be validated.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/proactivity.md (reported line 64)May include surrounding context.

md
## Anti-Patterns (Don't Do This)

❌ "I'm going to make a video for you" — never auto-generate without asking
❌ Re-offering after a "no" on the same content
❌ Suggesting video for text that is clearly meant to stay text (code, config, email draft)
❌ Overwhelming with options: "I can do 5 different templates!" — pick the best one, offer one

Description-Behavior Mismatch

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The file provides recurring cron-based automation examples but omits the explicit consent safeguards required by the skill metadata: confirming schedule, output directory, file retention policy, and a disable method before creating any cron job. In an agentic system that can run shell commands, this gap can lead to unauthorized or insufficiently understood background automation, causing repeated file generation and persistence beyond user intent.

Content

No source excerpt is available for this finding.

Intent-Code Divergence

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The recurring guidance says to 'Set up cron jobs for recurring video creation' and lists trigger/action pairs without the mandatory step of asking the user and obtaining the required confirmations first. That contradicts the skill's stated permission boundary and increases the chance an agent will treat recurring execution as routine rather than opt-in, enabling ongoing automated actions the user did not fully approve.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The automation section describes recurring video generation without warning users that their content may be processed repeatedly and that automated jobs will continue running until disabled. Even without networking or external file access, repeated use of workspace content and ongoing renders can surprise users, consume resources, and retain derivative outputs longer than expected.

Content

No source excerpt is available for this finding.

Scope Creep

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The script joins the user-supplied project name directly with the current working directory, so names containing path traversal sequences or absolute paths can cause files to be created outside the intended project directory boundary. In this skill, the ability to scaffold and write many files makes boundary bypass more significant because it could overwrite or plant project content elsewhere in the workspace despite the manifest claiming writes are constrained.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
83% confidence
Finding

Using npx remotion without pinning a specific version can cause execution of whatever package version is resolved at runtime, which may differ across environments or unexpectedly pull newer code. In a skill that is allowed to run Node/npm shell commands, this increases supply-chain risk and weakens reproducibility, especially if package resolution is not tightly controlled.

Content

No source excerpt is available for this finding.

subprocess module call

Medium
Category
Dangerous Code Execution
Confidence
70% confidence
Finding

subprocess module calls execute external commands. Without careful input validation, this enables command injection.

Content

Scanner excerpt · scripts/render.py (reported line 46)May include surrounding context.

python
cmd += ["--concurrency", str(args.concurrency)]

    print("Running:", " ".join(cmd))
    result = subprocess.run(cmd)
    sys.exit(result.returncode)

Scope Creep

Low
Category
Not specified by scanner
Confidence
85% confidence
Finding

The manifest's permission boundaries state 'No networking', which sets an expectation that the skill stays local to the workspace. SKILL.md includes a direct external GitHub release link for the showcase video, which introduces network access outside the declared boundary.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · assets/boilerplate/package.json (reported line 6)May include surrounding context.

json
"version": "1.0.0",
  "private": true,
  "dependencies": {
    "@remotion/cli": "^4.0.0",
    "@remotion/tailwind-v4": "^4.0.0",
    "react": "^19.0.0",
    "react-dom": "^19.0.0",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · assets/boilerplate/package.json (reported line 7)May include surrounding context.

json
"private": true,
  "dependencies": {
    "@remotion/cli": "^4.0.0",
    "@remotion/tailwind-v4": "^4.0.0",
    "react": "^19.0.0",
    "react-dom": "^19.0.0",
    "remotion": "^4.0.0",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · assets/boilerplate/package.json (reported line 8)May include surrounding context.

json
"dependencies": {
    "@remotion/cli": "^4.0.0",
    "@remotion/tailwind-v4": "^4.0.0",
    "react": "^19.0.0",
    "react-dom": "^19.0.0",
    "remotion": "^4.0.0",
    "tailwindcss": "^4.0.0"

Unverifiable Dependency: react has 2 known advisory(ies) (CVE-2013-7035 (Cross-Site Scripting in react); GHSA-hg79-j56m-fxgv (Cross-Site Scripting in react)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · assets/boilerplate/package.json (reported line 9)May include surrounding context.

json
"@remotion/cli": "^4.0.0",
    "@remotion/tailwind-v4": "^4.0.0",
    "react": "^19.0.0",
    "react-dom": "^19.0.0",
    "remotion": "^4.0.0",
    "tailwindcss": "^4.0.0"
  },

Unverifiable Dependency: react-dom has 1 known advisory(ies) (CVE-2018-6341 (Cross-Site Scripting in react-dom)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · assets/boilerplate/package.json (reported line 10)May include surrounding context.

json
"@remotion/tailwind-v4": "^4.0.0",
    "react": "^19.0.0",
    "react-dom": "^19.0.0",
    "remotion": "^4.0.0",
    "tailwindcss": "^4.0.0"
  },
  "devDependencies": {

Unverifiable Dependency: remotion has 2 known advisory(ies) (CVE-2026-30120 (Remotion: remote code execution (RCE) vulnerability); CVE-2026-30121 (Remotion: arbitrary file write vulnerability)), but the manifest does not pin a version, so it is unknown whether the installed release is affected

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependency has known vulnerabilities (CVEs). Using packages with unpatched security flaws exposes the environment to known exploits.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · assets/boilerplate/package.json (reported line 11)May include surrounding context.

json
"react": "^19.0.0",
    "react-dom": "^19.0.0",
    "remotion": "^4.0.0",
    "tailwindcss": "^4.0.0"
  },
  "devDependencies": {
    "@types/react": "^19.0.0",

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · assets/boilerplate/package.json (reported line 14)May include surrounding context.

json
"tailwindcss": "^4.0.0"
  },
  "devDependencies": {
    "@types/react": "^19.0.0",
    "@types/web": "^0.0.166",
    "typescript": "^5.5.0"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · assets/boilerplate/package.json (reported line 15)May include surrounding context.

json
},
  "devDependencies": {
    "@types/react": "^19.0.0",
    "@types/web": "^0.0.166",
    "typescript": "^5.5.0"
  },
  "scripts": {

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
40% confidence
Finding

Dependencies lack version pinning, allowing potential malicious package updates. Consider pinning versions.

Content

Scanner excerpt · assets/boilerplate/package.json (reported line 16)May include surrounding context.

json
"devDependencies": {
    "@types/react": "^19.0.0",
    "@types/web": "^0.0.166",
    "typescript": "^5.5.0"
  },
  "scripts": {
    "dev": "remotion studio",

Static analysis

No suspicious patterns detected.