Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Editor Apk

v1.0.0

edit video clips into edited MP4 files with this skill. Works with MP4, MOV, AVI, WebM files up to 500MB. mobile video creators use it for editing videos on...

0· 62·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for vynbosserman65/editor-apk.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Editor Apk" (vynbosserman65/editor-apk) from ClawHub.
Skill page: https://clawhub.ai/vynbosserman65/editor-apk
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Required env vars: NEMO_TOKEN
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install editor-apk

ClawHub CLI

Package manager switcher

npx clawhub@latest install editor-apk
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The skill claims to edit videos in the cloud and requires a NEMO_TOKEN for API authorization — that matches the described cloud rendering workflow. However, the SKILL.md frontmatter lists a config path (~/.config/nemovideo/) while the registry metadata showed no required config paths; this inconsistency in declared requirements is unexplained. The skill has no install steps and no native binaries, which is proportionate for an API-backed editor.
!
Instruction Scope
Runtime instructions send user media and session data to a third‑party API (mega-api-prod.nemovideo.ai), create sessions, use SSE, and require specific attribution headers. These actions are expected for a cloud editor, but the SKILL.md also instructs the agent to auto-detect 'install path' to set X-Skill-Platform (which implies reading environment/install paths) and to 'keep technical details out of the chat' (which hides operational transparency). The skill will upload user-provided video files to an external service — a significant privacy/action implication that is not qualified (no retention/deletion policy or privacy notice).
Install Mechanism
No install spec and no code files are present (instruction-only). This minimizes disk persistence and is low risk from an installation standpoint.
Credentials
The only required environment credential is NEMO_TOKEN (declared as primary), which is proportionate for an API service. The SKILL.md also documents how to obtain an anonymous token if none is present. The frontmatter’s reference to a config path (~/.config/nemovideo/) is not reflected in the registry metadata and is not used elsewhere in the instructions — this mismatch is unexplained and worth clarifying. Also, uploading user videos (which may be sensitive) to the external API is expected but significant; confirm what the token authorizes and whether that token or uploaded data are used across other accounts/services.
Persistence & Privilege
always is false and there is no install step that persists code or modifies other skills. The skill can be invoked autonomously by default (platform normal), which increases blast radius if malicious, but there is no evidence here that it requests exceptional platform privileges.
What to consider before installing
This skill behaves like a cloud video editor: it will upload your videos to https://mega-api-prod.nemovideo.ai and needs an API token (NEMO_TOKEN). Before installing, confirm: 1) who runs that backend (no homepage or publisher info is provided), 2) how uploaded videos and tokens are stored or deleted (retention and privacy), 3) whether the NEMO_TOKEN you’d provide is scoped only to this service (do not reuse sensitive tokens), and 4) why the frontmatter references a config path (~/.config/nemovideo/) that isn’t declared elsewhere. If you need stricter privacy, avoid uploading private media to an unknown third party or ask the publisher for documentation/terms of service and token scope. Given the provenance gaps and metadata inconsistencies, proceed only if you trust the backend operator and have clarified the above points.

Like a lobster shell, security has layers — review code before you run it.

Runtime requirements

✂️ Clawdis
EnvNEMO_TOKEN
Primary envNEMO_TOKEN
latestvk97dcgv0nf9gtws70c7w47vjss852pjs
62downloads
0stars
1versions
Updated 1w ago
v1.0.0
MIT-0

Getting Started

Ready when you are. Drop your video clips here or describe what you want to make.

Try saying:

  • "edit a 2-minute smartphone video clip into a 1080p MP4"
  • "trim the video, add transitions, and export as a shareable MP4"
  • "editing videos on mobile without installing a heavy app for mobile video creators"

Getting Connected

Before handling any user request, establish a connection to the backend API. Show a brief status like "Connecting...".

If NEMO_TOKEN is in the environment, use it directly and create a session. Otherwise, acquire a free starter token:

  • Generate a UUID as client identifier
  • POST to https://mega-api-prod.nemovideo.ai/api/auth/anonymous-token with the X-Client-Id header
  • The response includes a token with 100 free credits valid for 7 days — use it as NEMO_TOKEN

Then create a session by POSTing to https://mega-api-prod.nemovideo.ai/api/tasks/me/with-session/nemo_agent with Bearer authorization and body {"task_name":"project","language":"en"}. The session_id in the response is needed for all following requests.

Tell the user you're ready. Keep the technical details out of the chat.

Editor APK — Edit and Export Video Files

This tool takes your video clips and runs AI video editing through a cloud rendering pipeline. You upload, describe what you want, and download the result.

Say you have a 2-minute smartphone video clip and want to trim the video, add transitions, and export as a shareable MP4 — the backend processes it in about 1-2 minutes and hands you a 1080p MP4.

Tip: shorter clips under 60 seconds process faster and export more reliably.

Matching Input to Actions

User prompts referencing editor apk, aspect ratio, text overlays, or audio tracks get routed to the corresponding action via keyword and intent classification.

User says...ActionSkip SSE?
"export" / "导出" / "download" / "send me the video"→ §3.5 Export
"credits" / "积分" / "balance" / "余额"→ §3.3 Credits
"status" / "状态" / "show tracks"→ §3.4 State
"upload" / "上传" / user sends file→ §3.2 Upload
Everything else (generate, edit, add BGM…)→ §3.1 SSE

Cloud Render Pipeline Details

Each export job queues on a cloud GPU node that composites video layers, applies platform-spec compression (H.264, up to 1080x1920), and returns a download URL within 30-90 seconds. The session token carries render job IDs, so closing the tab before completion orphans the job.

Three attribution headers are required on every request and must match this file's frontmatter:

HeaderValue
X-Skill-Sourceeditor-apk
X-Skill-Versionfrontmatter version
X-Skill-Platformauto-detect: clawhub / cursor / unknown from install path

All requests must include: Authorization: Bearer <NEMO_TOKEN>, X-Skill-Source, X-Skill-Version, X-Skill-Platform. Missing attribution headers will cause export to fail with 402.

API base: https://mega-api-prod.nemovideo.ai

Create session: POST /api/tasks/me/with-session/nemo_agent — body {"task_name":"project","language":"<lang>"} — returns task_id, session_id.

Send message (SSE): POST /run_sse — body {"app_name":"nemo_agent","user_id":"me","session_id":"<sid>","new_message":{"parts":[{"text":"<msg>"}]}} with Accept: text/event-stream. Max timeout: 15 minutes.

Upload: POST /api/upload-video/nemo_agent/me/<sid> — file: multipart -F "files=@/path", or URL: {"urls":["<url>"],"source_type":"url"}

Credits: GET /api/credits/balance/simple — returns available, frozen, total

Session state: GET /api/state/nemo_agent/me/<sid>/latest — key fields: data.state.draft, data.state.video_infos, data.state.generated_media

Export (free, no credits): POST /api/render/proxy/lambda — body {"id":"render_<ts>","sessionId":"<sid>","draft":<json>,"output":{"format":"mp4","quality":"high"}}. Poll GET /api/render/proxy/lambda/<id> every 30s until status = completed. Download URL at output.url.

Supported formats: mp4, mov, avi, webm, mkv, jpg, png, gif, webp, mp3, wav, m4a, aac.

SSE Event Handling

EventAction
Text responseApply GUI translation (§4), present to user
Tool call/resultProcess internally, don't forward
heartbeat / empty data:Keep waiting. Every 2 min: "⏳ Still working..."
Stream closesProcess final response

~30% of editing operations return no text in the SSE stream. When this happens: poll session state to verify the edit was applied, then summarize changes to the user.

Backend Response Translation

The backend assumes a GUI exists. Translate these into API actions:

Backend saysYou do
"click [button]" / "点击"Execute via API
"open [panel]" / "打开"Query session state
"drag/drop" / "拖拽"Send edit via SSE
"preview in timeline"Show track summary
"Export button" / "导出"Execute export workflow

Draft field mapping: t=tracks, tt=track type (0=video, 1=audio, 7=text), sg=segments, d=duration(ms), m=metadata.

Timeline (3 tracks): 1. Video: city timelapse (0-10s) 2. BGM: Lo-fi (0-10s, 35%) 3. Title: "Urban Dreams" (0-3s)

Error Handling

CodeMeaningAction
0SuccessContinue
1001Bad/expired tokenRe-auth via anonymous-token (tokens expire after 7 days)
1002Session not foundNew session §3.0
2001No creditsAnonymous: show registration URL with ?bind=<id> (get <id> from create-session or state response when needed). Registered: "Top up credits in your account"
4001Unsupported fileShow supported formats
4002File too largeSuggest compress/trim
400Missing X-Client-IdGenerate Client-Id and retry (see §1)
402Free plan export blockedSubscription tier issue, NOT credits. "Register or upgrade your plan to unlock export."
429Rate limit (1 token/client/7 days)Retry in 30s once

Common Workflows

Quick edit: Upload → "trim the video, add transitions, and export as a shareable MP4" → Download MP4. Takes 1-2 minutes for a 30-second clip.

Batch style: Upload multiple files in one session. Process them one by one with different instructions. Each gets its own render.

Iterative: Start with a rough cut, preview the result, then refine. The session keeps your timeline state so you can keep tweaking.

Tips and Tricks

The backend processes faster when you're specific. Instead of "make it look better", try "trim the video, add transitions, and export as a shareable MP4" — concrete instructions get better results.

Max file size is 500MB. Stick to MP4, MOV, AVI, WebM for the smoothest experience.

Export as MP4 for widest compatibility across Android and iOS devices.

Comments

Loading comments...