Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Ai Subtitles
v1.0.0Skip the learning curve of professional editing software. Describe what you want — add subtitles in English and Spanish automatically — and get captioned vid...
⭐ 0· 50·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
Name/description match the instructions: the SKILL.md describes uploading videos, creating sessions, and requesting renders from mega-api-prod.nemovideo.ai, which is coherent for an 'AI Subtitles' service. Minor inconsistency: the registry metadata lists no required config paths, while the SKILL.md frontmatter includes ~/.config/nemovideo/ as a required config path — it's unclear whether the skill actually needs to read/write that path.
Instruction Scope
Instructions stay within the stated purpose: they only describe obtaining/using a NEMO_TOKEN, creating a session, uploading media, driving SSE for edits, and exporting results. They explicitly instruct not to print tokens/raw JSON. The agent will transmit uploaded video/audio to an external service (expected for remote rendering). There are no directives to read unrelated system files, shell history, or other credentials.
Install Mechanism
This is an instruction-only skill with no install spec and no code files — low installation risk. Nothing is downloaded or written by an installer step in the provided materials.
Credentials
The only declared required environment value is NEMO_TOKEN (primary credential), which is proportionate for a remote API. However, the SKILL.md frontmatter declares a config path (~/.config/nemovideo/) that could allow reading/storing tokens or state; the registry metadata does not list this config path, creating an unexplained mismatch. Confirm whether the skill will access that config directory and why.
Persistence & Privilege
The skill is not marked always:true and does not request system-wide changes. It is user-invocable and may run autonomously (platform default), which matches normal skill behavior. There is no instruction to modify other skills or global agent settings.
What to consider before installing
This skill appears to be a straightforward remote subtitle service, but it will upload your video/audio to https://mega-api-prod.nemovideo.ai and requires a NEMO_TOKEN (you can generate an anonymous token via their API). Before installing: (1) Confirm you are comfortable uploading the content (privacy/legal implications), (2) ask the publisher to clarify the apparent mismatch about ~/.config/nemovideo/ (is the skill going to read or write that folder?), (3) verify the service domain and its privacy/terms, and (4) test with non-sensitive sample media first. If you need stronger assurance, request the publisher to provide a clear manifest that matches SKILL.md (explicit config paths and exactly what is persisted).Like a lobster shell, security has layers — review code before you run it.
latestvk978541dx3gh0y3ngaggxkh1j584me6b
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
💬 Clawdis
EnvNEMO_TOKEN
Primary envNEMO_TOKEN
