offload-r2
Upload Remotion repository media assets to the Cloudflare R2 bucket behind remotion.media, switch source code to hosted URLs, verify the public objects, and remove repository-local copies.
How do I install this agent skill?
npx skills add https://github.com/remotion-dev/remotion --skill offload-r2Is this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill facilitates the offloading of local media assets to a Cloudflare R2 bucket. It uses standard command-line utilities and the Bun runtime to manage uploads and verify file integrity. A previously flagged security alert for remote code execution is confirmed as a false positive, as the command computes a file hash rather than executing remote code.
- Socketpass
No alerts
- Snykfail
Risk: CRITICAL · 1 issue
What does this agent skill do?
Offload R2 Asset
Host media on https://remotion.media/, update every in-scope source reference to the public object, and remove the repository-local copy after verification.
Workflow
-
Find the main worktree with
git worktree list --porcelain. Prefer the worktree onrefs/heads/main, normally/Users/jonathanburger/remotion. -
Choose a stable, descriptive object key. Use a feature-specific directory prefix when it prevents collisions, for example
studio-close-ups/demo.mp4. When replacing an asset, prefer a new versioned key so browser and Studio caches cannot serve the previous bytes. -
Load credentials from the main worktree without printing them:
--env-file=/Users/jonathanburger/remotion/packages/remotion-media/.envThe required variables are
AWS_ACCESS_KEY_IDandAWS_SECRET_ACCESS_KEY. -
Upload to the
parser-mediabucket with Bun's S3-compatible client:bun --env-file=/Users/jonathanburger/remotion/packages/remotion-media/.env -e "import {S3Client} from 'bun'; const filePath='<local-file>'; const key='<object-key>'; const client=new S3Client({accessKeyId:Bun.env.AWS_ACCESS_KEY_ID,secretAccessKey:Bun.env.AWS_SECRET_ACCESS_KEY,endpoint:'https://2fe488b3b0f4deee223aef7464784c46.r2.cloudflarestorage.com',bucket:'parser-media'}); const bytes=new Uint8Array(await Bun.file(filePath).arrayBuffer()); await client.write(key,bytes); const remote=await client.file(key).arrayBuffer(); if (remote.byteLength!==bytes.byteLength) throw new Error('Size mismatch'); console.log('uploaded',key,remote.byteLength);" -
Verify the public object and compare its SHA-256 hash with the local file before removing anything:
curl -I --fail https://remotion.media/<object-key> test "$(shasum -a 256 <local-file> | cut -d' ' -f1)" = "$(curl --fail --silent https://remotion.media/<object-key> | shasum -a 256 | cut -d' ' -f1)" -
Replace every in-scope source usage with the public URL. Do not wrap remote URLs in
staticFile()because it rejectshttp://andhttps://URLs. -
After the public hash matches and source references are remote, remove the local copy. Use
git rm -- <local-file>for a tracked file or remove the exact untracked/ignored file directly. Remove obsolete asset-specific.gitignoreentries and empty asset directories. Do not use recursive deletion or broad globs. -
Verify the local copy is gone and search the affected package for remaining local references:
test ! -e <local-file> rg -n '<local-filename>|staticFile\(' <affected-package> -
Run focused lint or style checks for touched packages. Commit or push only when requested.
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/remotion-dev/remotion/offload-r2">View offload-r2 on skillZs</a>