Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Kinetic Typography Video
v1.0.2Create dynamic kinetic typography and text animation videos with AI-powered motion design.
⭐ 0· 59·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
The declared purpose (create kinetic typography videos) aligns with the instructions (POST to NemoVideo API). Requesting an API token (NEMO_TOKEN) is reasonable for this purpose. However the top-level registry entry lists no required env vars/credentials while SKILL.md declares primaryEnv: NEMO_TOKEN and a config path (~/.config/nemovideo/), which is an inconsistency.
Instruction Scope
SKILL.md only describes sending a generation request to the NemoVideo API and producing video outputs. The documented cURL example uses an Authorization header for a bearer token. The instructions do not ask the agent to read unrelated system files, network endpoints beyond the service, or exfiltrate data.
Install Mechanism
No install spec and no code files—this is an instruction-only skill, so nothing will be written to disk by an installer. Low install risk.
Credentials
SKILL.md names NEMO_TOKEN as the primary credential, which is proportionate to calling the NemoVideo API. The concern is that registry metadata elsewhere shows no required env vars or primary credential; confirm whether the skill actually requires a token and whether that token must be supplied to the agent.
Persistence & Privilege
always:false and no special OS/config privileges are requested. The skill does not request permanent presence or modify other skills' configs.
What to consider before installing
Before installing, verify the metadata mismatch: SKILL.md expects NEMO_TOKEN and references ~/.config/nemovideo/, but the registry lists no credentials or config paths. If you plan to use it, only provide a scoped NemoVideo API token (not unrelated credentials), confirm the apiDomain (https://api.nemovideo.ai) is legitimate, and understand that using the skill will send your prompt/text to an external service (the provider) to generate videos. Check the publisher's homepage/repo for authenticity and ask the publisher to correct the registry metadata so required credentials/config are explicit. If you cannot verify the token requirement or the publisher, treat the mismatch as a reason to delay use.Like a lobster shell, security has layers — review code before you run it.
latestvk97bw6zjnry74xzfqt12b40k3h83t9qn
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
