Back to skill

Security audit

Remotion Video Toolkit

Security checks for vulnerabilities and agentic risk

Overview

This is a coherent Remotion video-generation guide, but some copy-paste server and URL-fetch examples could expose users to unsafe public rendering, cost, and internal-network access risks if deployed as written.

Install only if you are comfortable treating this as a development guide that needs security hardening before production use. Pin package versions, use lockfiles, avoid running scaffolding in sensitive environments, and add authentication, authorization, input schemas, URL allowlists, request/output size limits, render quotas, concurrency limits, timeouts, restricted egress, and cost monitoring before exposing any rendering API.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (3)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:129
Finding

Unpinned Package Execution Through npx

Content
View full analysis
Remediation
View remediation
my-video ``` - Document the expected npm registry and advise users to verify package ownership and provenance. - Prefer installing through a project manifest and committed lockfile rather than executing a freshly resolved package directly. - Use npm provenance, integrity metadata, and dependency scanning where supported. - Review package lifecycle scripts and transitive dependencies before using the command in sensitive environments. - Run scaffolding tools in a restricted development container without production credentials or unnecessary filesystem access. ]]>

T09 · Insecure Skill Coding Practices

Error
Location
rules/calculate-metadata.md:80
Finding

Server-Side Request Forgery Through Unvalidated Metadata URL

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
rules/rendering.md:195
Finding

Unauthenticated and Unbounded Video Rendering Endpoint

Content
View full analysis
{ bundled = b; console.log("Bundled and ready"); }); app.post("/render", async (req, res) => { const { compositionId, props } = req.body; const composition = await selectComposition({ serveUrl: bundled, id: compositionId, inputProps: props, }); const result = await renderMedia({ composition, serveUrl: bundled, codec: "h264", outputLocation: null, inputProps: props, }); res.set("Content-Type", "video/mp4"); res.send(result.buffer); }); app.listen(3000); ``` ### Technical Analysis The documented HTTP endpoint exposes computationally expensive video rendering without authentication or authorization. It accepts attacker-controlled `compositionId` and `props` without schema validation or an explicit composition allowlist. The endpoint also lacks: - Request-rate and per-client quotas. - Limits on concurrent rendering jobs. - Render-duration, frame-count, resolution, and output-size restrictions. - A specific JSON body-size limit. - Job cancellation and execution timeouts. - Safe error handling. - Readiness checks for the asynchronous bundle operation. - Network restrictions for media URLs supplied through props. `renderMedia()` performs CPU- and memory-intensive work. Returning the complete video through `result.buffer` retains the generated output in process memory, increasing denial-of-service risk when outputs are large or multiple renders run concurrently ...[truncated 1517 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (42)

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
90% confidence
Finding

The skill encourages exposing video rendering through HTTP endpoints and server-side APIs but provides no warning about handling uploaded media, user props, or generated outputs securely. In this context, users may build services that process personal data, URLs, or arbitrary assets without considering authentication, retention, SSRF, or content privacy risks.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
91% confidence
Finding

The skill instructs users to run npx create-video@latest, which pulls and executes the latest package code at runtime without pinning to a specific reviewed version. If the upstream package is compromised or a breaking/malicious release is published, users could execute untrusted code on their machine or in CI.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
96% confidence
Finding

The quick-start command npx create-video@latest my-video executes code fetched at invocation time from the registry. This creates a supply-chain exposure because the behavior can change over time, and a compromised publisher or dependency could lead to arbitrary code execution.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

Using npx remotion render ... without an explicit version allows whatever package version resolves in the environment to run, or may fetch a current version if not installed locally. In automation or fresh environments this can introduce non-deterministic execution and supply-chain risk from unreviewed package updates.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
88% confidence
Finding

The second npx remotion render example has the same issue: it may execute an unpinned tool version while also handling user-supplied props, making build pipelines depend on mutable external code. The main danger is package compromise or unexpected behavior changes rather than the props example itself.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

The documentation instructs users to run npx remotion add @remotion/three without pinning an exact package version, which allows the latest published package set to be resolved at execution time. If the upstream package or one of its installation-time dependencies is compromised, users following the skill could fetch and execute unintended code, making this a real supply-chain risk.

Content

No source excerpt is available for this finding.

External Transmission

Medium
Category
Data Exfiltration
Confidence
50% confidence
Finding

Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.

Content

Scanner excerpt · rules/compositions.md (reported line 117)May include surrounding context.

md
props,
  abortSignal,
}) => {
  const data = await fetch(`https://api.example.com/video/${props.videoId}`, {
    signal: abortSignal,
  }).then((res) => res.json());

Rp1

Medium
Category
MCP Rug Pull
Confidence
90% confidence
Finding

The documentation instructs users to run npx remotion without pinning a specific package version, which causes the latest CLI version to be fetched and executed at install time. If the upstream package, a dependency, or the publishing account were compromised, users could execute unexpected code, and even absent compromise this harms build reproducibility and can introduce breaking changes.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

The documentation instructs users to run npx remotion add @remotion/google-fonts without pinning the package version. npx resolves and executes the latest published package by default, which creates a supply-chain risk if a malicious or compromised release is published, and readers may copy-paste and execute it directly.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
85% confidence
Finding

This example again recommends executing npx remotion add @remotion/fonts without a pinned version, causing users to fetch and run whatever version is current at execution time. In a developer-facing skill, such copy-pasteable install commands increase practical exploitability of a package hijack or malicious upstream release.

Content

No source excerpt is available for this finding.

Unbounded Resource Access

Medium
Category
Excessive Agency
Confidence
75% confidence
Finding

Skill allows unbounded resource consumption (API calls, storage, compute). Without rate limits or quotas, a compromised or misbehaving agent can cause denial-of-service or cost overruns.

Content

Scanner excerpt · rules/gifs.md (reported line 57)May include surrounding context.

Control what happens when the animation finishes:

tsx
// Loop indefinitely (default)
<AnimatedImage src={staticFile("animation.gif")} width={500} height={500} loopBehavior="loop" />

// Play once, show final frame

Rp1

Medium
Category
MCP Rug Pull
Confidence
92% confidence
Finding

The documentation instructs users to run npx remotion without pinning a specific package version, which can cause execution of whatever version is current at install time. In a supply-chain compromise or unexpected upstream release, users could run altered code locally during dependency installation or project setup.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Rp1

Medium
Category
MCP Rug Pull
Confidence
70% confidence
Finding

npx commands without a version suffix (e.g. @1.0.0) create a rug-pull risk if the upstream server is compromised and publishes a malicious update.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.