Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Car Wash Promo Video
v1.0.0Car wash businesses and auto detailing services that publish video content showcasing their facilities and results attract 3x more new customers than busines...
⭐ 0· 22·0 current·0 all-time
bypeandrover adam@peand-rover
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
The declared requirement (NEMO_TOKEN and ~/.config/nemovideo/) is consistent with a third‑party video service named 'NemoVideo' and is plausible for a video-exporting skill, but the skill has no homepage or source details to validate that dependency.
Instruction Scope
SKILL.md contains only marketing/use-case prose and a single high-level instruction ('Specify your service menu and target customer'); it does not document what runtime actions the agent will take, what APIs will be called, or what files will be read/written — this vagueness grants the agent broad discretion and could hide unexpected data access or network calls (e.g., exporting to Google Business Profile) without indicating how credentials for those exports are handled.
Install Mechanism
Instruction-only skill with no install spec and no code files; nothing is written to disk by an installer — lowest install risk.
Credentials
Only one credential (NEMO_TOKEN) and one config path are declared, which is proportionate if the skill calls a NemoVideo API. However, the SKILL.md does not explain what NEMO_TOKEN is, why the config path is needed, or what permissions the token requires; the lack of documentation and unknown vendor reduces confidence.
Persistence & Privilege
always is false and the skill does not request persistent/system-wide modification; autonomous invocation is allowed by default but is not combined with other high privileges here.
What to consider before installing
This skill is plausible for generating/exporting marketing videos, but it lacks technical details and has no homepage or known publisher. Before installing: (1) verify what 'NEMO_TOKEN' is and whether it is scoped to only video creation/upload; do not provide broad or long‑lived credentials without confirming scope; (2) ask the publisher for documentation or a homepage describing the NemoVideo service and exact runtime behavior (what APIs are called, what data is uploaded, and whether Google Business Profile exports require additional credentials); (3) be cautious about placing a config path in the skill metadata — confirm whether the skill will read sensitive local config; and (4) if you cannot validate the vendor or token usage, avoid installing or test in an isolated environment/account first.Like a lobster shell, security has layers — review code before you run it.
latestvk974cb6baahzypztb92235fjg5849jdn
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
🚗 Clawdis
EnvNEMO_TOKEN
Primary envNEMO_TOKEN
