Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Free App To Add Music To Video
v1.0.0TikTok creators add video clips into music-backed videos using this skill. Accepts MP4, MOV, AVI, WebM up to 500MB, renders on cloud GPUs at 1080p, and retur...
⭐ 0· 11·0 current·0 all-time
by@udnerc
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
The skill claims cloud GPU rendering and adding background music and then instructs the agent to call a remote render API, upload video files, use SSE for edits, and return download URLs. Requesting an API token (NEMO_TOKEN) aligns with using a third‑party service to perform rendering.
Instruction Scope
Instructions direct the agent to automatically obtain an anonymous token if NEMO_TOKEN is not set, create sessions, upload user media to https://mega-api-prod.nemovideo.ai, stream SSE events, and poll render status. This is expected for cloud rendering, but the skill also tells the agent to hide raw API responses and token values and does not specify persistent storage semantics for tokens/session_ids — that ambiguity can affect auditability and user consent.
Install Mechanism
No install spec and no code files — instruction-only — so nothing is written to disk by an installer. Network calls are the primary runtime action.
Credentials
Only one credential (NEMO_TOKEN) is required, which is proportionate. However, the frontmatter references a config path (~/.config/nemovideo/) while registry metadata lists no required config paths — a metadata mismatch worth clarifying. Also, the skill will auto-generate and use an anonymous token if none is provided, which enables network activity without an explicit user-supplied credential.
Persistence & Privilege
always:false and no indications the skill writes or modifies other skills or system-wide settings. It asks to store session_id for requests, which is normal for a session-based API.
What to consider before installing
This skill behaves like a cloud render client: it will upload your videos to an external service (mega-api-prod.nemovideo.ai) and may automatically obtain an anonymous token if you don't provide one. Before installing, verify the service owner and privacy policy (there's no homepage/source listed), and consider: (1) only use non‑sensitive videos, (2) prefer manually supplying a NEMO_TOKEN you trust instead of allowing automatic anonymous token creation, (3) ask how and where tokens/session_ids are stored and whether they persist beyond the session, (4) confirm retention/processing policies for uploaded media, and (5) refuse installation if you cannot confirm the vendor identity or accept the privacy/risk tradeoffs.Like a lobster shell, security has layers — review code before you run it.
latestvk97c13yf8jm7hrz4qxemvxavfn84j07s
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
🎵 Clawdis
EnvNEMO_TOKEN
Primary envNEMO_TOKEN
