Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Scene Video
v1.0.0Turn a 3-minute raw footage file with multiple locations into 1080p scene-cut video just by typing what you need. Whether it's splitting footage into scenes...
⭐ 0· 56·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
The skill's name/description and required NEMO_TOKEN align with a cloud video-rendering service. However the SKILL.md frontmatter claims it will read a config path (~/.config/nemovideo/) and detect install paths to set X-Skill-Platform, while the registry metadata provided to you lists no required config paths — this mismatch is incoherent and could hide filesystem access not declared to the registry.
Instruction Scope
Runtime instructions involve network calls to mega-api-prod.nemovideo.ai for auth, session creation, uploads, SSE, and rendering (expected), but they also instruct the agent to read the skill file's YAML frontmatter and to detect install paths (e.g., ~/.clawhub, ~/.cursor/skills) to set attribution headers. Detecting install path may require reading local filesystem or environment and is not clearly justified for the core video-editing task.
Install Mechanism
Instruction-only skill with no install spec or code files — lowest install risk. There is no downloadable archive or third-party package to fetch.
Credentials
Only one credential (NEMO_TOKEN) is declared and used, which is appropriate for a remote API. The skill can also mint an anonymous starter token via the public anonymous-token endpoint if NEMO_TOKEN is absent. The frontmatter's mention of configPaths (~/.config/nemovideo/) is not reflected in the registry metadata you were shown, creating an unexplained access claim.
Persistence & Privilege
The skill is not marked always:true and uses normal autonomous invocation. It does not request persistent system-wide privileges in the provided instructions.
What to consider before installing
This skill looks like a legitimate cloud video-editing integrator, but there are red flags: (1) the SKILL.md claims it will read local config/install paths (to set an X-Skill-Platform header) while the published registry metadata you received does not list those config path requirements — ask the publisher to clarify and update registry metadata. (2) The skill will call an external API domain and can mint anonymous tokens; prefer using a limited-scope or throwaway NEMO_TOKEN if you want to test. (3) Don't provide unrelated secrets; verify what the token can access (account/credits). If you must try it, test with non-sensitive files and an anonymous token first, monitor network activity if possible, and request the publisher's homepage or source to confirm provenance before granting broader access.Like a lobster shell, security has layers — review code before you run it.
latestvk97epv6m0b6swjp8s7zn105vcs84qsnm
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
🎬 Clawdis
EnvNEMO_TOKEN
Primary envNEMO_TOKEN
