Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Ai Video Editor Enhancer

v1.0.0

Get enhanced edited video ready to post, without touching a single slider. Upload your raw video footage (MP4, MOV, AVI, WebM, up to 500MB), say something li...

0· 45·0 current·0 all-time
bypeandrover adam@peand-rover
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name and description describe cloud video editing and the only declared credential is NEMO_TOKEN, which is appropriate. However the SKILL.md frontmatter lists a config path (~/.config/nemovideo/) while the registry metadata earlier reported no required config paths — this mismatch should be clarified.
Instruction Scope
Instructions are focused on creating a session, uploading user video, and driving remote rendering — consistent with purpose. They do explicitly instruct the agent to POST files and to call an anonymous-token endpoint to obtain NEMO_TOKEN if none is present. The skill also references local install/config paths (to detect X-Skill-Platform and possible config storage), which implies probing the agent environment; that is expected for attribution but worth noting.
Install Mechanism
No install spec or code files are present (instruction-only), so the skill will not write/install binaries. Lower install risk.
Credentials
Only NEMO_TOKEN is required (declared as primary), which is proportional for a cloud service. Two points to check: (1) SKILL.md instructs the skill to acquire an anonymous token from https://mega-api-prod.nemovideo.ai if NEMO_TOKEN is missing (the skill will perform network auth on first use), and (2) frontmatter mentions a config path where tokens/sessions might be stored — clarify whether the skill will read/write that location.
Persistence & Privilege
always:false and normal autonomous invocation settings. The skill does not request global agent changes or broad system privileges in the instructions.
What to consider before installing
This skill appears to do what it says (upload your raw video to a cloud backend for AI editing) but it will contact an external API (mega-api-prod.nemovideo.ai), upload your files, and may generate and store an anonymous NEMO_TOKEN if you don't provide one. Before installing: (1) verify you trust the Nemo/NemoVideo service and its privacy policy, (2) consider providing your own NEMO_TOKEN rather than letting the skill obtain one, (3) confirm whether the skill will write tokens or session data to ~/.config/nemovideo/ (the manifest is inconsistent), and (4) avoid sending sensitive or private footage until you’re comfortable with remote processing and storage policies.

Like a lobster shell, security has layers — review code before you run it.

latestvk97akjgzmvjy2z5y8jkd504bmh84r9wf

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Runtime requirements

🎬 Clawdis
EnvNEMO_TOKEN
Primary envNEMO_TOKEN

Comments