Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Video Editor Apk

v1.0.0

Turn a 60-second mobile phone recording into 1080p edited MP4 clips just by typing what you need. Whether it's editing mobile-recorded videos into shareable...

0· 25·0 current·0 all-time
Security Scan
VirusTotalVirusTotal
Pending
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The skill's name and description match the actions described (uploading video, requesting a token, creating a session, rendering via cloud GPU). Requesting a NEMO_TOKEN is coherent for a cloud editing backend. However, registry metadata said no config paths while the SKILL.md frontmatter lists ~/.config/nemovideo/ — a minor inconsistency in declared requirements.
Instruction Scope
Instructions stay focused on video upload, SSE streaming, session management, and rendering. They instruct the agent to POST to external endpoints (mega-api-prod.nemovideo.ai), upload user media, poll job state, and map GUI instructions to API calls. The skill also directs the agent to read its own YAML frontmatter and detect install path (~/.clawhub, ~/.cursor) to set attribution headers — this requires reading local file paths and detection of the agent install location, which is outside the pure 'video editing' payload flow but plausibly used only for attribution.
Install Mechanism
No install spec or downloaded code (instruction-only), so nothing is written to disk or fetched at install time. This minimizes install-time risk.
Credentials
The only declared credential is NEMO_TOKEN, which is proportional to a cloud API. However, SKILL.md both checks for an existing NEMO_TOKEN and describes obtaining an anonymous token via the service if missing — this makes the registry's 'required env var' claim ambiguous. The skill also references a local config path in its frontmatter (not declared elsewhere). No other unrelated secrets are requested.
Persistence & Privilege
always is false and the skill doesn't request system-wide changes. It instructs storing a session_id for requests (normal for a sessioned API) but does not ask to modify other skills or global agent configuration.
What to consider before installing
This skill appears to implement a cloud video-editing workflow and will call a third-party API (https://mega-api-prod.nemovideo.ai). Before installing or using it: - Be cautious about uploading sensitive videos — they will be sent to an external service you don't have a homepage or clear owner for. - The skill will try to obtain an anonymous NEMO_TOKEN if none is set; if you prefer control, set your own token or avoid automatic token creation. - Ask the author to clarify the metadata mismatch (SKILL.md lists a config path, registry lists none) and whether any keys/tokens are persisted to disk. - If you need stronger assurances, request the service's privacy policy, data retention rules, and a known publisher/homepage, or use a trusted alternative. Confidence is medium because the behavior is coherent overall but there are small inconsistencies and this skill will send user data to an external endpoint of unknown provenance.

Like a lobster shell, security has layers — review code before you run it.

Runtime requirements

🎬 Clawdis
EnvNEMO_TOKEN
Primary envNEMO_TOKEN
latestvk97cnxt9h0h7wremd0et9tqg2h8521x3
25downloads
0stars
1versions
Updated 1d ago
v1.0.0
MIT-0

Getting Started

Share your video clips and I'll get started on AI video editing. Or just tell me what you're thinking.

Try saying:

  • "edit my video clips"
  • "export 1080p MP4"
  • "trim the clip, add background music,"

First-Time Connection

When a user first opens this skill, connect to the processing backend automatically. Briefly let them know (e.g. "Setting up...").

Authentication: Check if NEMO_TOKEN is set in the environment. If it is, skip to step 2.

  1. Obtain a free token: Generate a random UUID as client identifier. POST to https://mega-api-prod.nemovideo.ai/api/auth/anonymous-token with header X-Client-Id set to that UUID. The response data.token is your NEMO_TOKEN — 100 free credits, valid 7 days.
  2. Create a session: POST to https://mega-api-prod.nemovideo.ai/api/tasks/me/with-session/nemo_agent with Authorization: Bearer <token>, Content-Type: application/json, and body {"task_name":"project","language":"<detected>"}. Store the returned session_id for all subsequent requests.

Keep setup communication brief. Don't display raw API responses or token values to the user.

Video Editor APK — Edit and Export Mobile Videos

This tool takes your video clips and runs AI video editing through a cloud rendering pipeline. You upload, describe what you want, and download the result.

Say you have a 60-second mobile phone recording and want to trim the clip, add background music, and export as MP4 — the backend processes it in about 30-60 seconds and hands you a 1080p MP4.

Tip: shorter clips under 2 minutes process significantly faster.

Matching Input to Actions

User prompts referencing video editor apk, aspect ratio, text overlays, or audio tracks get routed to the corresponding action via keyword and intent classification.

User says...ActionSkip SSE?
"export" / "导出" / "download" / "send me the video"→ §3.5 Export
"credits" / "积分" / "balance" / "余额"→ §3.3 Credits
"status" / "状态" / "show tracks"→ §3.4 State
"upload" / "上传" / user sends file→ §3.2 Upload
Everything else (generate, edit, add BGM…)→ §3.1 SSE

Cloud Render Pipeline Details

Each export job queues on a cloud GPU node that composites video layers, applies platform-spec compression (H.264, up to 1080x1920), and returns a download URL within 30-90 seconds. The session token carries render job IDs, so closing the tab before completion orphans the job.

Base URL: https://mega-api-prod.nemovideo.ai

EndpointMethodPurpose
/api/tasks/me/with-session/nemo_agentPOSTStart a new editing session. Body: {"task_name":"project","language":"<lang>"}. Returns session_id.
/run_ssePOSTSend a user message. Body includes app_name, session_id, new_message. Stream response with Accept: text/event-stream. Timeout: 15 min.
/api/upload-video/nemo_agent/me/<sid>POSTUpload a file (multipart) or URL.
/api/credits/balance/simpleGETCheck remaining credits (available, frozen, total).
/api/state/nemo_agent/me/<sid>/latestGETFetch current timeline state (draft, video_infos, generated_media).
/api/render/proxy/lambdaPOSTStart export. Body: {"id":"render_<ts>","sessionId":"<sid>","draft":<json>,"output":{"format":"mp4","quality":"high"}}. Poll status every 30s.

Accepted file types: mp4, mov, avi, webm, mkv, jpg, png, gif, webp, mp3, wav, m4a, aac.

Skill attribution — read from this file's YAML frontmatter at runtime:

  • X-Skill-Source: video-editor-apk
  • X-Skill-Version: from frontmatter version
  • X-Skill-Platform: detect from install path (~/.clawhub/clawhub, ~/.cursor/skills/cursor, else unknown)

Every API call needs Authorization: Bearer <NEMO_TOKEN> plus the three attribution headers above. If any header is missing, exports return 402.

Error Codes

  • 0 — success, continue normally
  • 1001 — token expired or invalid; re-acquire via /api/auth/anonymous-token
  • 1002 — session not found; create a new one
  • 2001 — out of credits; anonymous users get a registration link with ?bind=<id>, registered users top up
  • 4001 — unsupported file type; show accepted formats
  • 4002 — file too large; suggest compressing or trimming
  • 400 — missing X-Client-Id; generate one and retry
  • 402 — free plan export blocked; not a credit issue, subscription tier
  • 429 — rate limited; wait 30s and retry once

SSE Event Handling

EventAction
Text responseApply GUI translation (§4), present to user
Tool call/resultProcess internally, don't forward
heartbeat / empty data:Keep waiting. Every 2 min: "⏳ Still working..."
Stream closesProcess final response

~30% of editing operations return no text in the SSE stream. When this happens: poll session state to verify the edit was applied, then summarize changes to the user.

Translating GUI Instructions

The backend responds as if there's a visual interface. Map its instructions to API calls:

  • "click" or "点击" → execute the action via the relevant endpoint
  • "open" or "打开" → query session state to get the data
  • "drag/drop" or "拖拽" → send the edit command through SSE
  • "preview in timeline" → show a text summary of current tracks
  • "Export" or "导出" → run the export workflow

Draft field mapping: t=tracks, tt=track type (0=video, 1=audio, 7=text), sg=segments, d=duration(ms), m=metadata.

Timeline (3 tracks): 1. Video: city timelapse (0-10s) 2. BGM: Lo-fi (0-10s, 35%) 3. Title: "Urban Dreams" (0-3s)

Tips and Tricks

The backend processes faster when you're specific. Instead of "make it look better", try "trim the clip, add background music, and export as MP4" — concrete instructions get better results.

Max file size is 500MB. Stick to MP4, MOV, AVI, WebM for the smoothest experience.

Export as MP4 for widest compatibility across all devices and platforms.

Common Workflows

Quick edit: Upload → "trim the clip, add background music, and export as MP4" → Download MP4. Takes 30-60 seconds for a 30-second clip.

Batch style: Upload multiple files in one session. Process them one by one with different instructions. Each gets its own render.

Iterative: Start with a rough cut, preview the result, then refine. The session keeps your timeline state so you can keep tweaking.

Comments

Loading comments...