Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Video Editing Ai Gratis

v1.0.0

Turn a 2-minute phone-recorded vlog clip into 1080p edited MP4 videos just by typing what you need. Whether it's editing raw footage into polished videos wit...

0· 94·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for dsewell-583h0/video-editing-ai-gratis.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Video Editing Ai Gratis" (dsewell-583h0/video-editing-ai-gratis) from ClawHub.
Skill page: https://clawhub.ai/dsewell-583h0/video-editing-ai-gratis
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Required env vars: NEMO_TOKEN
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install video-editing-ai-gratis

ClawHub CLI

Package manager switcher

npx clawhub@latest install video-editing-ai-gratis
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The skill's described purpose (remote AI video editing) matches the network calls and token usage in SKILL.md — a service token (NEMO_TOKEN) and uploads to mega-api-prod.nemovideo.ai are expected for that purpose. However, the registry metadata and the skill frontmatter disagree: the registry summary lists no config paths while the SKILL.md frontmatter and metadata reference ~/.config/nemovideo/ and mark NEMO_TOKEN as required even though the instructions provide an anonymous-token fallback. That mismatch is inconsistent.
!
Instruction Scope
Instructions direct the agent to upload user video files and poll/render on a remote API (expected). But they also instruct hiding technical details from users ('Keep the technical details out of the chat'), require specific attribution headers, and imply auto-detection of an install path for X-Skill-Platform — which could cause the agent to inspect local install paths or config locations. The SKILL.md's metadata includes a config path (~/.config/nemovideo/) that the agent may probe for tokens; that local-file access is not fully declared in the registry and is a scope/transparency concern.
Install Mechanism
This is an instruction-only skill with no install spec and no code files — nothing is written to disk by an installer. That is the lowest-risk install mechanism.
!
Credentials
Only one credential (NEMO_TOKEN) is declared as primary, which is reasonable for a remote editing API. However, the registry declares NEMO_TOKEN as required while the runtime instructions explicitly support acquiring an anonymous token if none is present. Also the frontmatter includes a config path (~/.config/nemovideo/) which the registry metadata did not list; this inconsistency about which local credentials/config paths will be accessed is disproportionate and unclear.
Persistence & Privilege
The skill does not request always:true and has no install-time persistency. It does require network calls and session tokens for remote rendering, but it does not request system-wide privileges or to modify other skills.
What to consider before installing
This skill appears to be a thin client for a remote video-rendering service: it will upload your videos to mega-api-prod.nemovideo.ai and require a service token (NEMO_TOKEN) or will request an anonymous token on your behalf. Before installing or using it, consider: 1) Privacy: any footage you upload goes to an external service — avoid sensitive material unless you trust the provider and have their privacy/retention policy. 2) Inconsistencies: the registry metadata and the SKILL.md disagree about required config paths and whether the token is mandatory; ask the publisher to clarify where tokens/config are read from and why the registry differs. 3) Transparency: the skill explicitly tells the agent to hide technical details from users — ask for clearer, user-facing descriptions of what data is sent and stored. 4) Domain & provenance: no homepage or source is provided — request the service's website, documentation, and privacy/security contact before trusting API credentials. If you proceed, prefer using a limited/ephemeral token, test with non-sensitive videos, and be prepared to revoke tokens/credits after use.

Like a lobster shell, security has layers — review code before you run it.

Runtime requirements

🎬 Clawdis
EnvNEMO_TOKEN
Primary envNEMO_TOKEN
latestvk97fsnj9hrpfxkw57fdjsfdgv5858era
94downloads
0stars
1versions
Updated 1w ago
v1.0.0
MIT-0

Getting Started

Got raw video clips to work with? Send it over and tell me what you need — I'll take care of the AI video editing.

Try saying:

  • "edit a 2-minute phone-recorded vlog clip into a 1080p MP4"
  • "cut the silences, add transitions, and export a clean final video"
  • "editing raw footage into polished videos without paid software for content creators and students"

Getting Connected

Before handling any user request, establish a connection to the backend API. Show a brief status like "Connecting...".

If NEMO_TOKEN is in the environment, use it directly and create a session. Otherwise, acquire a free starter token:

  • Generate a UUID as client identifier
  • POST to https://mega-api-prod.nemovideo.ai/api/auth/anonymous-token with the X-Client-Id header
  • The response includes a token with 100 free credits valid for 7 days — use it as NEMO_TOKEN

Then create a session by POSTing to https://mega-api-prod.nemovideo.ai/api/tasks/me/with-session/nemo_agent with Bearer authorization and body {"task_name":"project","language":"en"}. The session_id in the response is needed for all following requests.

Tell the user you're ready. Keep the technical details out of the chat.

Video Editing AI Gratis — Edit and Export Videos Free

Send me your raw video clips and describe the result you want. The AI video editing runs on remote GPU nodes — nothing to install on your machine.

A quick example: upload a 2-minute phone-recorded vlog clip, type "cut the silences, add transitions, and export a clean final video", and you'll get a 1080p MP4 back in roughly 1-2 minutes. All rendering happens server-side.

Worth noting: shorter clips under 60 seconds process significantly faster.

Matching Input to Actions

User prompts referencing video editing ai gratis, aspect ratio, text overlays, or audio tracks get routed to the corresponding action via keyword and intent classification.

User says...ActionSkip SSE?
"export" / "导出" / "download" / "send me the video"→ §3.5 Export
"credits" / "积分" / "balance" / "余额"→ §3.3 Credits
"status" / "状态" / "show tracks"→ §3.4 State
"upload" / "上传" / user sends file→ §3.2 Upload
Everything else (generate, edit, add BGM…)→ §3.1 SSE

Cloud Render Pipeline Details

Each export job queues on a cloud GPU node that composites video layers, applies platform-spec compression (H.264, up to 1080x1920), and returns a download URL within 30-90 seconds. The session token carries render job IDs, so closing the tab before completion orphans the job.

All calls go to https://mega-api-prod.nemovideo.ai. The main endpoints:

  1. SessionPOST /api/tasks/me/with-session/nemo_agent with {"task_name":"project","language":"<lang>"}. Gives you a session_id.
  2. Chat (SSE)POST /run_sse with session_id and your message in new_message.parts[0].text. Set Accept: text/event-stream. Up to 15 min.
  3. UploadPOST /api/upload-video/nemo_agent/me/<sid> — multipart file or JSON with URLs.
  4. CreditsGET /api/credits/balance/simple — returns available, frozen, total.
  5. StateGET /api/state/nemo_agent/me/<sid>/latest — current draft and media info.
  6. ExportPOST /api/render/proxy/lambda with render ID and draft JSON. Poll GET /api/render/proxy/lambda/<id> every 30s for completed status and download URL.

Formats: mp4, mov, avi, webm, mkv, jpg, png, gif, webp, mp3, wav, m4a, aac.

Three attribution headers are required on every request and must match this file's frontmatter:

HeaderValue
X-Skill-Sourcevideo-editing-ai-gratis
X-Skill-Versionfrontmatter version
X-Skill-Platformauto-detect: clawhub / cursor / unknown from install path

All requests must include: Authorization: Bearer <NEMO_TOKEN>, X-Skill-Source, X-Skill-Version, X-Skill-Platform. Missing attribution headers will cause export to fail with 402.

Draft JSON uses short keys: t for tracks, tt for track type (0=video, 1=audio, 7=text), sg for segments, d for duration in ms, m for metadata.

Example timeline summary:

Timeline (3 tracks): 1. Video: city timelapse (0-10s) 2. BGM: Lo-fi (0-10s, 35%) 3. Title: "Urban Dreams" (0-3s)

Backend Response Translation

The backend assumes a GUI exists. Translate these into API actions:

Backend saysYou do
"click [button]" / "点击"Execute via API
"open [panel]" / "打开"Query session state
"drag/drop" / "拖拽"Send edit via SSE
"preview in timeline"Show track summary
"Export button" / "导出"Execute export workflow

Reading the SSE Stream

Text events go straight to the user (after GUI translation). Tool calls stay internal. Heartbeats and empty data: lines mean the backend is still working — show "⏳ Still working..." every 2 minutes.

About 30% of edit operations close the stream without any text. When that happens, poll /api/state to confirm the timeline changed, then tell the user what was updated.

Error Handling

CodeMeaningAction
0SuccessContinue
1001Bad/expired tokenRe-auth via anonymous-token (tokens expire after 7 days)
1002Session not foundNew session §3.0
2001No creditsAnonymous: show registration URL with ?bind=<id> (get <id> from create-session or state response when needed). Registered: "Top up credits in your account"
4001Unsupported fileShow supported formats
4002File too largeSuggest compress/trim
400Missing X-Client-IdGenerate Client-Id and retry (see §1)
402Free plan export blockedSubscription tier issue, NOT credits. "Register or upgrade your plan to unlock export."
429Rate limit (1 token/client/7 days)Retry in 30s once

Tips and Tricks

The backend processes faster when you're specific. Instead of "make it look better", try "cut the silences, add transitions, and export a clean final video" — concrete instructions get better results.

Max file size is 500MB. Stick to MP4, MOV, AVI, WebM for the smoothest experience.

Export as MP4 for widest compatibility across platforms and devices.

Common Workflows

Quick edit: Upload → "cut the silences, add transitions, and export a clean final video" → Download MP4. Takes 1-2 minutes for a 30-second clip.

Batch style: Upload multiple files in one session. Process them one by one with different instructions. Each gets its own render.

Iterative: Start with a rough cut, preview the result, then refine. The session keeps your timeline state so you can keep tweaking.

Comments

Loading comments...