Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Reddit Video Maker Bot Free

v1.0.0

Get narrated Reddit videos ready to post, without touching a single slider. Upload your Reddit post data (TXT, URL, JSON, MP4, up to 200MB), say something li...

0· 60·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for tk8544-b/reddit-video-maker-bot-free.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Reddit Video Maker Bot Free" (tk8544-b/reddit-video-maker-bot-free) from ClawHub.
Skill page: https://clawhub.ai/tk8544-b/reddit-video-maker-bot-free
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Required env vars: NEMO_TOKEN
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install reddit-video-maker-bot-free

ClawHub CLI

Package manager switcher

npx clawhub@latest install reddit-video-maker-bot-free
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The skill's name/description (Reddit → narrated video) matches the network API calls described in SKILL.md and the single declared env var NEMO_TOKEN is reasonable. However the SKILL.md frontmatter declares a config path (~/.config/nemovideo/) while the registry metadata lists no required config paths — that mismatch is unexplained and could indicate the skill expects access to a local config folder it hasn't declared elsewhere.
!
Instruction Scope
The runtime instructions direct the agent to upload user-provided files (up to 200MB) and chat/text to a remote service (mega-api-prod.nemovideo.ai). They also mandate adding attribution headers on every request and 'auto-detect' a platform value from the install path (this can reveal local install path info). Sending arbitrary user files and chat to an external endpoint is expected for this service but is a privacy/security consideration the user should be aware of.
Install Mechanism
No install spec or code files are included (instruction-only skill), so nothing is written to disk by an installer — this is the lowest-risk install mechanism. There is no external download or package install to review.
Credentials
Only NEMO_TOKEN is declared as required, which is proportionate to a cloud-render API. The SKILL.md metadata's additional configPaths (~/.config/nemovideo/) is not reflected in the registry metadata — the skill may try to read local config files or saved tokens, which is not justified by the registry listing and should be clarified before use.
Persistence & Privilege
The skill is not marked always:true and is user-invocable only. It does not request persistent platform-level privileges in the manifest.
What to consider before installing
This skill will send any files and text you provide to a third-party service (mega-api-prod.nemovideo.ai) and uses a bearer token (NEMO_TOKEN) for authorization. Before installing/using it: 1) Confirm you trust nemovideo.ai (check privacy policy, data retention, and reputation). 2) Do not upload sensitive/private content (personal data, credentials, proprietary media) unless you accept that it will be transmitted to and processed by that remote service. 3) Prefer using an ephemeral/limited token or the anonymous-token flow if you want to limit long-lived access, and avoid putting highly privileged credentials in NEMO_TOKEN. 4) Ask the skill author to explain the mismatch about the declared config path (~/.config/nemovideo/) and whether the agent will read local files or install paths (the required attribution headers and platform auto-detection can leak local path/agent info). 5) If you cannot verify the service or need stronger guarantees, do not install or run the skill with real/privileged data. If you want, provide the maintainer/contact or a privacy policy and I can re-evaluate with that information.

Like a lobster shell, security has layers — review code before you run it.

Runtime requirements

🤖 Clawdis
EnvNEMO_TOKEN
Primary envNEMO_TOKEN
latestvk97d7a4v8bd21npy0ptr3gmjf984z5hg
60downloads
0stars
1versions
Updated 1w ago
v1.0.0
MIT-0

Getting Started

Send me your Reddit post data and I'll handle the automated video creation. Or just describe what you're after.

Try saying:

  • "convert a Reddit thread with 10 top comments into a 1080p MP4"
  • "turn this Reddit thread into a narrated video with text overlays and background gameplay"
  • "converting Reddit threads into shareable videos for Reddit content creators"

Getting Connected

Before handling any user request, establish a connection to the backend API. Show a brief status like "Connecting...".

If NEMO_TOKEN is in the environment, use it directly and create a session. Otherwise, acquire a free starter token:

  • Generate a UUID as client identifier
  • POST to https://mega-api-prod.nemovideo.ai/api/auth/anonymous-token with the X-Client-Id header
  • The response includes a token with 100 free credits valid for 7 days — use it as NEMO_TOKEN

Then create a session by POSTing to https://mega-api-prod.nemovideo.ai/api/tasks/me/with-session/nemo_agent with Bearer authorization and body {"task_name":"project","language":"en"}. The session_id in the response is needed for all following requests.

Tell the user you're ready. Keep the technical details out of the chat.

Reddit Video Maker Bot Free — Convert Reddit Threads to Videos

Send me your Reddit post data and describe the result you want. The automated video creation runs on remote GPU nodes — nothing to install on your machine.

A quick example: upload a Reddit thread with 10 top comments, type "turn this Reddit thread into a narrated video with text overlays and background gameplay", and you'll get a 1080p MP4 back in roughly 1-2 minutes. All rendering happens server-side.

Worth noting: shorter threads with 5-8 comments produce tighter, more watchable videos.

Matching Input to Actions

User prompts referencing reddit video maker bot free, aspect ratio, text overlays, or audio tracks get routed to the corresponding action via keyword and intent classification.

User says...ActionSkip SSE?
"export" / "导出" / "download" / "send me the video"→ §3.5 Export
"credits" / "积分" / "balance" / "余额"→ §3.3 Credits
"status" / "状态" / "show tracks"→ §3.4 State
"upload" / "上传" / user sends file→ §3.2 Upload
Everything else (generate, edit, add BGM…)→ §3.1 SSE

Cloud Render Pipeline Details

Each export job queues on a cloud GPU node that composites video layers, applies platform-spec compression (H.264, up to 1080x1920), and returns a download URL within 30-90 seconds. The session token carries render job IDs, so closing the tab before completion orphans the job.

Base URL: https://mega-api-prod.nemovideo.ai

EndpointMethodPurpose
/api/tasks/me/with-session/nemo_agentPOSTStart a new editing session. Body: {"task_name":"project","language":"<lang>"}. Returns session_id.
/run_ssePOSTSend a user message. Body includes app_name, session_id, new_message. Stream response with Accept: text/event-stream. Timeout: 15 min.
/api/upload-video/nemo_agent/me/<sid>POSTUpload a file (multipart) or URL.
/api/credits/balance/simpleGETCheck remaining credits (available, frozen, total).
/api/state/nemo_agent/me/<sid>/latestGETFetch current timeline state (draft, video_infos, generated_media).
/api/render/proxy/lambdaPOSTStart export. Body: {"id":"render_<ts>","sessionId":"<sid>","draft":<json>,"output":{"format":"mp4","quality":"high"}}. Poll status every 30s.

Accepted file types: mp4, mov, avi, webm, mkv, jpg, png, gif, webp, mp3, wav, m4a, aac.

Three attribution headers are required on every request and must match this file's frontmatter:

HeaderValue
X-Skill-Sourcereddit-video-maker-bot-free
X-Skill-Versionfrontmatter version
X-Skill-Platformauto-detect: clawhub / cursor / unknown from install path

Include Authorization: Bearer <NEMO_TOKEN> and all attribution headers on every request — omitting them triggers a 402 on export.

Error Handling

CodeMeaningAction
0SuccessContinue
1001Bad/expired tokenRe-auth via anonymous-token (tokens expire after 7 days)
1002Session not foundNew session §3.0
2001No creditsAnonymous: show registration URL with ?bind=<id> (get <id> from create-session or state response when needed). Registered: "Top up credits in your account"
4001Unsupported fileShow supported formats
4002File too largeSuggest compress/trim
400Missing X-Client-IdGenerate Client-Id and retry (see §1)
402Free plan export blockedSubscription tier issue, NOT credits. "Register or upgrade your plan to unlock export."
429Rate limit (1 token/client/7 days)Retry in 30s once

Reading the SSE Stream

Text events go straight to the user (after GUI translation). Tool calls stay internal. Heartbeats and empty data: lines mean the backend is still working — show "⏳ Still working..." every 2 minutes.

About 30% of edit operations close the stream without any text. When that happens, poll /api/state to confirm the timeline changed, then tell the user what was updated.

Translating GUI Instructions

The backend responds as if there's a visual interface. Map its instructions to API calls:

  • "click" or "点击" → execute the action via the relevant endpoint
  • "open" or "打开" → query session state to get the data
  • "drag/drop" or "拖拽" → send the edit command through SSE
  • "preview in timeline" → show a text summary of current tracks
  • "Export" or "导出" → run the export workflow

Draft field mapping: t=tracks, tt=track type (0=video, 1=audio, 7=text), sg=segments, d=duration(ms), m=metadata.

Timeline (3 tracks): 1. Video: city timelapse (0-10s) 2. BGM: Lo-fi (0-10s, 35%) 3. Title: "Urban Dreams" (0-3s)

Common Workflows

Quick edit: Upload → "turn this Reddit thread into a narrated video with text overlays and background gameplay" → Download MP4. Takes 1-2 minutes for a 30-second clip.

Batch style: Upload multiple files in one session. Process them one by one with different instructions. Each gets its own render.

Iterative: Start with a rough cut, preview the result, then refine. The session keeps your timeline state so you can keep tweaking.

Tips and Tricks

The backend processes faster when you're specific. Instead of "make it look better", try "turn this Reddit thread into a narrated video with text overlays and background gameplay" — concrete instructions get better results.

Max file size is 200MB. Stick to TXT, URL, JSON, MP4 for the smoothest experience.

Export as MP4 for widest compatibility across YouTube, TikTok, and Instagram Reels.

Comments

Loading comments...