Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Ai Video Editor Generative

v1.0.0

Skip the learning curve of professional editing software. Describe what you want — auto-cut the pauses, add B-roll transitions, and generate a cinematic intr...

0· 35·0 current·0 all-time
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name/description (AI video editing) aligns with runtime instructions to upload videos, create sessions, and render via a cloud API. However the SKILL.md frontmatter declares a config path (~/.config/nemovideo/) that is not reflected in the registry summary, an inconsistency that should be clarified.
Instruction Scope
Instructions are detailed and mostly confined to the editing workflow (session creation, SSE streaming, upload endpoints, polling render status). They also instruct generating an anonymous token if NEMO_TOKEN is absent. Two points to watch: (1) headers include X-Skill-Platform derived from install path — this implies the agent might read local install paths to set a header (possible fingerprinting/leak of environment); (2) instructions expect uploading user media (potentially sensitive) to an external domain, which is consistent with the service but is a privacy consideration.
Install Mechanism
Instruction-only skill with no install spec or code files — low-risk from installation perspective (nothing is written/executed locally by an installer).
Credentials
Only NEMO_TOKEN is required (primary credential), which fits a cloud editing service. The SKILL.md also provides a flow to obtain a short-lived anonymous token via the service endpoint. The mismatch between registry 'required config paths: none' and SKILL.md's metadata mentioning ~/.config/nemovideo/ is unexplained and should be resolved. Requesting only one API token is proportional, but any token grants upload and processing of user media on the remote service.
Persistence & Privilege
always:false and normal autonomous invocation allowed. The skill asks to save session_id and manage sessions (expected for a cloud service). No evidence it requests elevation, modifies other skills, or insists on permanent system-wide changes.
What to consider before installing
This skill appears to be a legitimate cloud-based AI video editor, but check a few things before using it: 1) Verify the service domain (mega-api-prod.nemovideo.ai) and the vendor’s reputation/privacy policy — your uploaded media and any tokens will be sent there. 2) Clarify the config-path metadata mismatch: SKILL.md mentions ~/.config/nemovideo/ but registry metadata showed none; confirm whether session tokens or logs will be written to disk and where. 3) Prefer using the anonymous-token flow (short-lived token) rather than providing a long-lived NEMO_TOKEN until you trust the service. 4) Be aware the skill may detect install paths to populate X-Skill-Platform headers — if that’s a concern, request it default to 'unknown' instead of probing local paths. 5) Don’t share highly sensitive footage unless you have acceptable data-retention and privacy assurances. If you want higher assurance, ask the publisher for a privacy/security statement and for clarification about what is stored locally versus on the remote service.

Like a lobster shell, security has layers — review code before you run it.

Runtime requirements

🎬 Clawdis
EnvNEMO_TOKEN
Primary envNEMO_TOKEN
latestvk9745frtyt121rwx8z31qnhtj585b28t
35downloads
0stars
1versions
Updated 22h ago
v1.0.0
MIT-0

Getting Started

Share your raw video clips and I'll get started on generative AI video editing. Or just tell me what you're thinking.

Try saying:

  • "generate my raw video clips"
  • "export 1080p MP4"
  • "auto-cut the pauses, add B-roll transitions,"

Automatic Setup

On first interaction, connect to the processing API before doing anything else. Show a brief status like "Setting things up...".

Token: If NEMO_TOKEN environment variable is already set, use it and skip to Session below.

Free token: Generate a UUID as client identifier, then POST to https://mega-api-prod.nemovideo.ai/api/auth/anonymous-token with header X-Client-Id: <uuid>. The response field data.token becomes your NEMO_TOKEN (100 credits, 7-day expiry).

Session: POST to https://mega-api-prod.nemovideo.ai/api/tasks/me/with-session/nemo_agent with Bearer auth and body {"task_name":"project"}. Save session_id from the response.

Confirm to the user you're connected and ready. Don't print tokens or raw JSON.

AI Video Editor Generative — Generate and Edit Videos with AI

This tool takes your raw video clips and runs generative AI video editing through a cloud rendering pipeline. You upload, describe what you want, and download the result.

Say you have a 2-minute unedited screen recording and want to auto-cut the pauses, add B-roll transitions, and generate a cinematic intro scene — the backend processes it in about 1-2 minutes and hands you a 1080p MP4.

Tip: shorter source clips under 3 minutes give the AI more precise generative control over the output.

Matching Input to Actions

User prompts referencing ai video editor generative, aspect ratio, text overlays, or audio tracks get routed to the corresponding action via keyword and intent classification.

User says...ActionSkip SSE?
"export" / "导出" / "download" / "send me the video"→ §3.5 Export
"credits" / "积分" / "balance" / "余额"→ §3.3 Credits
"status" / "状态" / "show tracks"→ §3.4 State
"upload" / "上传" / user sends file→ §3.2 Upload
Everything else (generate, edit, add BGM…)→ §3.1 SSE

Cloud Render Pipeline Details

Each export job queues on a cloud GPU node that composites video layers, applies platform-spec compression (H.264, up to 1080x1920), and returns a download URL within 30-90 seconds. The session token carries render job IDs, so closing the tab before completion orphans the job.

Base URL: https://mega-api-prod.nemovideo.ai

EndpointMethodPurpose
/api/tasks/me/with-session/nemo_agentPOSTStart a new editing session. Body: {"task_name":"project","language":"<lang>"}. Returns session_id.
/run_ssePOSTSend a user message. Body includes app_name, session_id, new_message. Stream response with Accept: text/event-stream. Timeout: 15 min.
/api/upload-video/nemo_agent/me/<sid>POSTUpload a file (multipart) or URL.
/api/credits/balance/simpleGETCheck remaining credits (available, frozen, total).
/api/state/nemo_agent/me/<sid>/latestGETFetch current timeline state (draft, video_infos, generated_media).
/api/render/proxy/lambdaPOSTStart export. Body: {"id":"render_<ts>","sessionId":"<sid>","draft":<json>,"output":{"format":"mp4","quality":"high"}}. Poll status every 30s.

Accepted file types: mp4, mov, avi, webm, mkv, jpg, png, gif, webp, mp3, wav, m4a, aac.

Headers are derived from this file's YAML frontmatter. X-Skill-Source is ai-video-editor-generative, X-Skill-Version comes from the version field, and X-Skill-Platform is detected from the install path (~/.clawhub/ = clawhub, ~/.cursor/skills/ = cursor, otherwise unknown).

All requests must include: Authorization: Bearer <NEMO_TOKEN>, X-Skill-Source, X-Skill-Version, X-Skill-Platform. Missing attribution headers will cause export to fail with 402.

Error Handling

CodeMeaningAction
0SuccessContinue
1001Bad/expired tokenRe-auth via anonymous-token (tokens expire after 7 days)
1002Session not foundNew session §3.0
2001No creditsAnonymous: show registration URL with ?bind=<id> (get <id> from create-session or state response when needed). Registered: "Top up credits in your account"
4001Unsupported fileShow supported formats
4002File too largeSuggest compress/trim
400Missing X-Client-IdGenerate Client-Id and retry (see §1)
402Free plan export blockedSubscription tier issue, NOT credits. "Register or upgrade your plan to unlock export."
429Rate limit (1 token/client/7 days)Retry in 30s once

SSE Event Handling

EventAction
Text responseApply GUI translation (§4), present to user
Tool call/resultProcess internally, don't forward
heartbeat / empty data:Keep waiting. Every 2 min: "⏳ Still working..."
Stream closesProcess final response

~30% of editing operations return no text in the SSE stream. When this happens: poll session state to verify the edit was applied, then summarize changes to the user.

Translating GUI Instructions

The backend responds as if there's a visual interface. Map its instructions to API calls:

  • "click" or "点击" → execute the action via the relevant endpoint
  • "open" or "打开" → query session state to get the data
  • "drag/drop" or "拖拽" → send the edit command through SSE
  • "preview in timeline" → show a text summary of current tracks
  • "Export" or "导出" → run the export workflow

Draft field mapping: t=tracks, tt=track type (0=video, 1=audio, 7=text), sg=segments, d=duration(ms), m=metadata.

Timeline (3 tracks): 1. Video: city timelapse (0-10s) 2. BGM: Lo-fi (0-10s, 35%) 3. Title: "Urban Dreams" (0-3s)

Common Workflows

Quick edit: Upload → "auto-cut the pauses, add B-roll transitions, and generate a cinematic intro scene" → Download MP4. Takes 1-2 minutes for a 30-second clip.

Batch style: Upload multiple files in one session. Process them one by one with different instructions. Each gets its own render.

Iterative: Start with a rough cut, preview the result, then refine. The session keeps your timeline state so you can keep tweaking.

Tips and Tricks

The backend processes faster when you're specific. Instead of "make it look better", try "auto-cut the pauses, add B-roll transitions, and generate a cinematic intro scene" — concrete instructions get better results.

Max file size is 500MB. Stick to MP4, MOV, AVI, WebM for the smoothest experience.

Export as MP4 with H.264 codec for the widest platform compatibility.

Comments

Loading comments...