Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Caption Generator Bangla
v1.0.0Skip the learning curve of professional editing software. Describe what you want — generate captions in Bangla for my video — and get Bangla captioned videos...
⭐ 0· 34·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
The name/description (Bangla captioning) aligns with the runtime actions (upload video, request renders, return download URL). Requesting a NEMO_TOKEN credential for a video-processing API is reasonable. However, the SKILL.md frontmatter lists a config path (~/.config/nemovideo/) while the registry metadata earlier reported no required config paths — that mismatch should be explained (does the skill read or write that directory?).
Instruction Scope
The instructions are focused on interacting with the remote nemo API (session creation, uploads, SSE, render polling). They don't instruct the agent to read unrelated files or export unrelated secrets. One scope note: header construction requests an 'auto-detect' of platform from install path which could require the agent to inspect its environment; the frontmatter's config path implies possible file access. Those behaviors are tangential to captioning and should be clarified.
Install Mechanism
This is an instruction-only skill with no install spec and no code files — lowest-risk install surface. Nothing will be downloaded or written by an install procedure.
Credentials
Only one credential (NEMO_TOKEN) is declared as primary, which is proportionate for a hosted video-processing API. The skill also documents a procedure to obtain an anonymous token (100 credits, 7-day expiry), which reduces the need to provide a long-lived token. Still, the presence of an undeclared config path in the frontmatter (~/.config/nemovideo/) raises questions about whether the skill may read local config beyond the single env var.
Persistence & Privilege
The skill is not always-enabled and does not request system-wide persistence. Runtime state (session_id) is saved for session use per the instructions, which is expected. It does not request modifications to other skills or system settings.
What to consider before installing
This skill behaves like a client for an external nemo video service and will upload whatever video files you provide to https://mega-api-prod.nemovideo.ai. Before installing or using it: 1) Confirm you trust that external domain and its privacy/retention policy — you may be sending sensitive video/audio. 2) Prefer using the anonymous-token flow (temporary 7‑day token) instead of supplying a long-lived NEMO_TOKEN if you have privacy concerns. 3) Ask the skill author to explain the frontmatter config path (~/.config/nemovideo/) and why it wasn't listed in the registry metadata — does the skill read/write local config? 4) Note the skill will add attribution headers that include an auto-detected platform value (it may inspect the agent/install path); if you want to avoid exposing environment details, ask the author to provide a safe default. If you cannot verify the service owner or the endpoint's privacy/security practices, avoid uploading sensitive content or providing a permanent token.Like a lobster shell, security has layers — review code before you run it.
latestvk9739sxzt4hnt03zj60vs8nwy184wk23
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
🇧🇩 Clawdis
EnvNEMO_TOKEN
Primary envNEMO_TOKEN
