Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Ai Video Editor Kiss

v1.0.0

edit raw video clips into edited romantic clips with this skill. Works with MP4, MOV, AVI, WebM files up to 500MB. short film creators, TikTok creators, coup...

0· 23·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
Name and description match the instructions: the skill uploads user video, requests a session token, and calls a remote rendering API. Requiring a single service token (NEMO_TOKEN) is coherent with a third‑party cloud editor.
Instruction Scope
SKILL.md instructs the agent to create sessions, upload user-provided video files, stream SSE messages, and poll render status on mega-api-prod.nemovideo.ai — all expected. It also instructs agents to 'keep technical details out of the chat,' which reduces transparency. The runtime instructions do not ask the agent to read unrelated system files or unrelated environment variables, aside from a suggested config path in the frontmatter.
Install Mechanism
This is an instruction-only skill with no install steps or code download, which minimizes install-time risk.
!
Credentials
The skill declares a single required credential (NEMO_TOKEN), which is appropriate. However, the SKILL.md frontmatter references a config path (~/.config/nemovideo/) that would give the skill local file access; the registry metadata shown earlier listed no required config paths — this mismatch is unexplained and could grant broader local access than the registry suggests.
Persistence & Privilege
The skill is not marked always:true and does not request permanent system-wide presence. Autonomous invocation is allowed by default (normal); there is no evidence it modifies other skills or system-wide settings.
What to consider before installing
This skill appears to be a cloud-based video editor that uploads your clips to mega-api-prod.nemovideo.ai and requires a NEMO_TOKEN. Before installing: (1) confirm whether the skill really needs access to the local config path (~/.config/nemovideo/) — the registry metadata and the SKILL.md disagree; if unnecessary, deny that access; (2) understand that your video files will be sent to an external service (read that service's privacy/terms and ensure it meets your confidentiality needs); (3) prefer supplying your own NEMO_TOKEN from a trusted account rather than letting the skill obtain an anonymous token for you; (4) ask the publisher to remove the 'keep technical details out of the chat' instruction or explain it, because it reduces transparency about API activity. If the author clarifies the config-path discrepancy and provides a trustworthy privacy policy, the concerns are largely addressed.

Like a lobster shell, security has layers — review code before you run it.

latestvk971pv3vp3knkdwye4pkgra2cd84s9s0

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Runtime requirements

💋 Clawdis
EnvNEMO_TOKEN
Primary envNEMO_TOKEN

Comments