Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Boomerang Video Maker Free

v1.0.0

Skip the learning curve of professional editing software. Describe what you want — turn this clip into a looping boomerang that plays forward and backward —...

0· 70·0 current·0 all-time
bypeandrover adam@peand-rover

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for peand-rover/boomerang-video-maker-free.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Boomerang Video Maker Free" (peand-rover/boomerang-video-maker-free) from ClawHub.
Skill page: https://clawhub.ai/peand-rover/boomerang-video-maker-free
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Required env vars: NEMO_TOKEN
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install boomerang-video-maker-free

ClawHub CLI

Package manager switcher

npx clawhub@latest install boomerang-video-maker-free
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Suspicious
medium confidence
!
Purpose & Capability
The skill's declared primary credential (NEMO_TOKEN) matches the described cloud backend, which is coherent. However the registry metadata and the SKILL.md disagree: the top-level manifest lists no config paths while SKILL.md frontmatter advertises ~/.config/nemovideo/ as a config path. Also the manifest declares NEMO_TOKEN as required while the runtime instructions describe auto-provisioning an anonymous token if NEMO_TOKEN is missing. These mismatches reduce trust in the declared requirements.
!
Instruction Scope
Runtime instructions tell the agent to obtain anonymous tokens, create sessions, upload user videos (up to 200MB), poll render jobs, and include attribution headers. That broadly matches a cloud render service, but instructions also instruct reading the skill's YAML frontmatter and probing install paths (e.g., ~/.clawhub/, ~/.cursor/skills/) to set X-Skill-Platform — reading these install directories is outside the core editing task and is not declared in the top-level manifest. The skill will transmit user media and metadata to a third-party domain (mega-api-prod.nemovideo.ai), so user data will leave the device.
Install Mechanism
No install spec and no code files (instruction-only). This minimizes on-disk footprint and reduces supply-chain risk.
Credentials
Only one credential (NEMO_TOKEN) is requested, which is proportional to a cloud API. However the manifest claims the env var is required while the instructions will automatically obtain an anonymous token if it's absent — this inconsistency is notable. The skill also references a config path in its own frontmatter (~/.config/nemovideo/), though the registry metadata did not list that path.
Persistence & Privilege
The skill does not request always:true, does not claim system-wide changes, and is user-invocable. It does instruct storing session IDs for requests, but does not explicitly request persistent system-wide privileges or modify other skills.
What to consider before installing
This skill will upload your videos and session metadata to mega-api-prod.nemovideo.ai for cloud rendering — if you care about privacy or sensitive content, do not upload it. Note the registry metadata and the SKILL.md disagree (config paths and whether NEMO_TOKEN is strictly required), and the skill can auto-provision an anonymous token for you: ask where and how tokens/session IDs are stored and for how long. Confirm you trust the nemo video service (domain, privacy policy, retention) before proceeding. If you need stricter guarantees, request the skill author to (1) make required env/config paths consistent in manifest and docs, (2) document where tokens/session IDs are stored (in-memory vs written to disk), and (3) state explicit privacy/retention rules for uploaded media.

Like a lobster shell, security has layers — review code before you run it.

Runtime requirements

🔁 Clawdis
EnvNEMO_TOKEN
Primary envNEMO_TOKEN
latestvk97anfhnrxp6gj4tz1ys90mf6x85by4a
70downloads
0stars
1versions
Updated 5d ago
v1.0.0
MIT-0

Getting Started

Send me your short video clips and I'll handle the boomerang loop creation. Or just describe what you're after.

Try saying:

  • "convert a 2-second clip of a coffee cup being set down into a 1080p MP4"
  • "turn this clip into a looping boomerang that plays forward and backward"
  • "creating boomerang loop videos for Instagram and TikTok for Instagram and TikTok creators"

First-Time Connection

When a user first opens this skill, connect to the processing backend automatically. Briefly let them know (e.g. "Setting up...").

Authentication: Check if NEMO_TOKEN is set in the environment. If it is, skip to step 2.

  1. Obtain a free token: Generate a random UUID as client identifier. POST to https://mega-api-prod.nemovideo.ai/api/auth/anonymous-token with header X-Client-Id set to that UUID. The response data.token is your NEMO_TOKEN — 100 free credits, valid 7 days.
  2. Create a session: POST to https://mega-api-prod.nemovideo.ai/api/tasks/me/with-session/nemo_agent with Authorization: Bearer <token>, Content-Type: application/json, and body {"task_name":"project","language":"<detected>"}. Store the returned session_id for all subsequent requests.

Keep setup communication brief. Don't display raw API responses or token values to the user.

Boomerang Video Maker Free — Create Looping Boomerang Video Clips

This tool takes your short video clips and runs boomerang loop creation through a cloud rendering pipeline. You upload, describe what you want, and download the result.

Say you have a 2-second clip of a coffee cup being set down and want to turn this clip into a looping boomerang that plays forward and backward — the backend processes it in about 20-40 seconds and hands you a 1080p MP4.

Tip: shorter clips of 1-3 seconds produce the smoothest boomerang loops.

Matching Input to Actions

User prompts referencing boomerang video maker free, aspect ratio, text overlays, or audio tracks get routed to the corresponding action via keyword and intent classification.

User says...ActionSkip SSE?
"export" / "导出" / "download" / "send me the video"→ §3.5 Export
"credits" / "积分" / "balance" / "余额"→ §3.3 Credits
"status" / "状态" / "show tracks"→ §3.4 State
"upload" / "上传" / user sends file→ §3.2 Upload
Everything else (generate, edit, add BGM…)→ §3.1 SSE

Cloud Render Pipeline Details

Each export job queues on a cloud GPU node that composites video layers, applies platform-spec compression (H.264, up to 1080x1920), and returns a download URL within 30-90 seconds. The session token carries render job IDs, so closing the tab before completion orphans the job.

Every API call needs Authorization: Bearer <NEMO_TOKEN> plus the three attribution headers above. If any header is missing, exports return 402.

Skill attribution — read from this file's YAML frontmatter at runtime:

  • X-Skill-Source: boomerang-video-maker-free
  • X-Skill-Version: from frontmatter version
  • X-Skill-Platform: detect from install path (~/.clawhub/clawhub, ~/.cursor/skills/cursor, else unknown)

API base: https://mega-api-prod.nemovideo.ai

Create session: POST /api/tasks/me/with-session/nemo_agent — body {"task_name":"project","language":"<lang>"} — returns task_id, session_id.

Send message (SSE): POST /run_sse — body {"app_name":"nemo_agent","user_id":"me","session_id":"<sid>","new_message":{"parts":[{"text":"<msg>"}]}} with Accept: text/event-stream. Max timeout: 15 minutes.

Upload: POST /api/upload-video/nemo_agent/me/<sid> — file: multipart -F "files=@/path", or URL: {"urls":["<url>"],"source_type":"url"}

Credits: GET /api/credits/balance/simple — returns available, frozen, total

Session state: GET /api/state/nemo_agent/me/<sid>/latest — key fields: data.state.draft, data.state.video_infos, data.state.generated_media

Export (free, no credits): POST /api/render/proxy/lambda — body {"id":"render_<ts>","sessionId":"<sid>","draft":<json>,"output":{"format":"mp4","quality":"high"}}. Poll GET /api/render/proxy/lambda/<id> every 30s until status = completed. Download URL at output.url.

Supported formats: mp4, mov, avi, webm, mkv, jpg, png, gif, webp, mp3, wav, m4a, aac.

Error Handling

CodeMeaningAction
0SuccessContinue
1001Bad/expired tokenRe-auth via anonymous-token (tokens expire after 7 days)
1002Session not foundNew session §3.0
2001No creditsAnonymous: show registration URL with ?bind=<id> (get <id> from create-session or state response when needed). Registered: "Top up credits in your account"
4001Unsupported fileShow supported formats
4002File too largeSuggest compress/trim
400Missing X-Client-IdGenerate Client-Id and retry (see §1)
402Free plan export blockedSubscription tier issue, NOT credits. "Register or upgrade your plan to unlock export."
429Rate limit (1 token/client/7 days)Retry in 30s once

Backend Response Translation

The backend assumes a GUI exists. Translate these into API actions:

Backend saysYou do
"click [button]" / "点击"Execute via API
"open [panel]" / "打开"Query session state
"drag/drop" / "拖拽"Send edit via SSE
"preview in timeline"Show track summary
"Export button" / "导出"Execute export workflow

SSE Event Handling

EventAction
Text responseApply GUI translation (§4), present to user
Tool call/resultProcess internally, don't forward
heartbeat / empty data:Keep waiting. Every 2 min: "⏳ Still working..."
Stream closesProcess final response

~30% of editing operations return no text in the SSE stream. When this happens: poll session state to verify the edit was applied, then summarize changes to the user.

Draft field mapping: t=tracks, tt=track type (0=video, 1=audio, 7=text), sg=segments, d=duration(ms), m=metadata.

Timeline (3 tracks): 1. Video: city timelapse (0-10s) 2. BGM: Lo-fi (0-10s, 35%) 3. Title: "Urban Dreams" (0-3s)

Common Workflows

Quick edit: Upload → "turn this clip into a looping boomerang that plays forward and backward" → Download MP4. Takes 20-40 seconds for a 30-second clip.

Batch style: Upload multiple files in one session. Process them one by one with different instructions. Each gets its own render.

Iterative: Start with a rough cut, preview the result, then refine. The session keeps your timeline state so you can keep tweaking.

Tips and Tricks

The backend processes faster when you're specific. Instead of "make it look better", try "turn this clip into a looping boomerang that plays forward and backward" — concrete instructions get better results.

Max file size is 200MB. Stick to MP4, MOV, AVI, WebM for the smoothest experience.

Export as MP4 for widest compatibility across Instagram, TikTok, and WhatsApp.

Comments

Loading comments...