Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Youtube Creator Studio

v1.0.0

Cloud-based youtube-creator-studio tool that handles editing and optimizing videos for YouTube channel publishing. Upload MP4, MOV, AVI, WebM files (up to 50...

0· 104·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for mhogan2013-9/youtube-creator-studio.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Youtube Creator Studio" (mhogan2013-9/youtube-creator-studio) from ClawHub.
Skill page: https://clawhub.ai/mhogan2013-9/youtube-creator-studio
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Required env vars: NEMO_TOKEN
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install youtube-creator-studio

ClawHub CLI

Package manager switcher

npx clawhub@latest install youtube-creator-studio
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
medium confidence
Purpose & Capability
The skill is a cloud video editing/export tool and only requests a single service credential (NEMO_TOKEN) and network calls to nemovideo.ai endpoints, which is coherent with the stated purpose. Minor inconsistency: the SKILL.md frontmatter references a config path (~/.config/nemovideo/) while the registry metadata earlier listed no required config paths.
Instruction Scope
Instructions are focused on establishing a session, uploading video files, streaming SSE responses, and starting exports to the stated API. They instruct saving session_id and using or obtaining a NEMO_TOKEN. The runtime also asks the agent to detect an install path (e.g., ~/.clawhub/ or ~/.cursor/skills/) to set an X-Skill-Platform header — this requires inspecting filesystem paths and is broader than purely sending the uploaded files, but not obviously unrelated to attribution.
Install Mechanism
Instruction-only skill with no install spec or code files, so nothing is downloaded or written by an installer — lowest risk for install mechanism.
Credentials
Only NEMO_TOKEN is declared as required, which fits the service. However the frontmatter's metadata references a config directory (~/.config/nemovideo/) and the attribution logic asks the agent to inspect common skill-install locations — these could lead the skill to read or write local config/token files. Confirm whether the skill will persist tokens and where.
Persistence & Privilege
The skill is not always-enabled and does not request system-wide privileges. It does instruct saving a session_id and using/storing a NEMO_TOKEN (including generating an anonymous token), which implies some persistence of credentials, but it does not modify other skills or request elevated platform-wide permissions.
Assessment
This skill appears to do what it says (cloud video editing) and only asks for a NEMO_TOKEN, but you should: 1) confirm you trust the endpoint domain (mega-api-prod.nemovideo.ai) and the unknown publisher before sending video files (avoid uploading sensitive content), 2) ask where the skill stores the generated or provided NEMO_TOKEN and session_id (environment variable vs a file under ~/.config/nemovideo/), 3) be aware it may inspect install paths (~/.clawhub, ~/.cursor/skills) to set an attribution header, 4) verify billing/credit behavior (anonymous tokens are limited) and privacy/data-retention terms, and 5) prefer a skill with a visible homepage/source or request the source code if you need higher assurance.

Like a lobster shell, security has layers — review code before you run it.

Runtime requirements

🎬 Clawdis
EnvNEMO_TOKEN
Primary envNEMO_TOKEN
latestvk975zdm2vjswnkb32z8ngtqj6h84jwah
104downloads
0stars
1versions
Updated 2w ago
v1.0.0
MIT-0

Getting Started

Got uploaded video files to work with? Send it over and tell me what you need — I'll take care of the AI video management editing.

Try saying:

  • "edit a 10-minute YouTube vlog in MP4 format into a 1080p MP4"
  • "trim the intro, add end screen elements, and export for YouTube upload"
  • "editing and optimizing videos for YouTube channel publishing for YouTubers"

Automatic Setup

On first interaction, connect to the processing API before doing anything else. Show a brief status like "Setting things up...".

Token: If NEMO_TOKEN environment variable is already set, use it and skip to Session below.

Free token: Generate a UUID as client identifier, then POST to https://mega-api-prod.nemovideo.ai/api/auth/anonymous-token with header X-Client-Id: <uuid>. The response field data.token becomes your NEMO_TOKEN (100 credits, 7-day expiry).

Session: POST to https://mega-api-prod.nemovideo.ai/api/tasks/me/with-session/nemo_agent with Bearer auth and body {"task_name":"project"}. Save session_id from the response.

Confirm to the user you're connected and ready. Don't print tokens or raw JSON.

YouTube Creator Studio — Edit and Export YouTube Videos

This tool takes your uploaded video files and runs AI video management editing through a cloud rendering pipeline. You upload, describe what you want, and download the result.

Say you have a 10-minute YouTube vlog in MP4 format and want to trim the intro, add end screen elements, and export for YouTube upload — the backend processes it in about 1-2 minutes and hands you a 1080p MP4.

Tip: keeping clips under 5 minutes speeds up processing and lets you iterate faster.

Matching Input to Actions

User prompts referencing youtube creator studio, aspect ratio, text overlays, or audio tracks get routed to the corresponding action via keyword and intent classification.

User says...ActionSkip SSE?
"export" / "导出" / "download" / "send me the video"→ §3.5 Export
"credits" / "积分" / "balance" / "余额"→ §3.3 Credits
"status" / "状态" / "show tracks"→ §3.4 State
"upload" / "上传" / user sends file→ §3.2 Upload
Everything else (generate, edit, add BGM…)→ §3.1 SSE

Cloud Render Pipeline Details

Each export job queues on a cloud GPU node that composites video layers, applies platform-spec compression (H.264, up to 1080x1920), and returns a download URL within 30-90 seconds. The session token carries render job IDs, so closing the tab before completion orphans the job.

Base URL: https://mega-api-prod.nemovideo.ai

EndpointMethodPurpose
/api/tasks/me/with-session/nemo_agentPOSTStart a new editing session. Body: {"task_name":"project","language":"<lang>"}. Returns session_id.
/run_ssePOSTSend a user message. Body includes app_name, session_id, new_message. Stream response with Accept: text/event-stream. Timeout: 15 min.
/api/upload-video/nemo_agent/me/<sid>POSTUpload a file (multipart) or URL.
/api/credits/balance/simpleGETCheck remaining credits (available, frozen, total).
/api/state/nemo_agent/me/<sid>/latestGETFetch current timeline state (draft, video_infos, generated_media).
/api/render/proxy/lambdaPOSTStart export. Body: {"id":"render_<ts>","sessionId":"<sid>","draft":<json>,"output":{"format":"mp4","quality":"high"}}. Poll status every 30s.

Accepted file types: mp4, mov, avi, webm, mkv, jpg, png, gif, webp, mp3, wav, m4a, aac.

Skill attribution — read from this file's YAML frontmatter at runtime:

  • X-Skill-Source: youtube-creator-studio
  • X-Skill-Version: from frontmatter version
  • X-Skill-Platform: detect from install path (~/.clawhub/clawhub, ~/.cursor/skills/cursor, else unknown)

All requests must include: Authorization: Bearer <NEMO_TOKEN>, X-Skill-Source, X-Skill-Version, X-Skill-Platform. Missing attribution headers will cause export to fail with 402.

Error Codes

  • 0 — success, continue normally
  • 1001 — token expired or invalid; re-acquire via /api/auth/anonymous-token
  • 1002 — session not found; create a new one
  • 2001 — out of credits; anonymous users get a registration link with ?bind=<id>, registered users top up
  • 4001 — unsupported file type; show accepted formats
  • 4002 — file too large; suggest compressing or trimming
  • 400 — missing X-Client-Id; generate one and retry
  • 402 — free plan export blocked; not a credit issue, subscription tier
  • 429 — rate limited; wait 30s and retry once

Reading the SSE Stream

Text events go straight to the user (after GUI translation). Tool calls stay internal. Heartbeats and empty data: lines mean the backend is still working — show "⏳ Still working..." every 2 minutes.

About 30% of edit operations close the stream without any text. When that happens, poll /api/state to confirm the timeline changed, then tell the user what was updated.

Backend Response Translation

The backend assumes a GUI exists. Translate these into API actions:

Backend saysYou do
"click [button]" / "点击"Execute via API
"open [panel]" / "打开"Query session state
"drag/drop" / "拖拽"Send edit via SSE
"preview in timeline"Show track summary
"Export button" / "导出"Execute export workflow

Draft field mapping: t=tracks, tt=track type (0=video, 1=audio, 7=text), sg=segments, d=duration(ms), m=metadata.

Timeline (3 tracks): 1. Video: city timelapse (0-10s) 2. BGM: Lo-fi (0-10s, 35%) 3. Title: "Urban Dreams" (0-3s)

Common Workflows

Quick edit: Upload → "trim the intro, add end screen elements, and export for YouTube upload" → Download MP4. Takes 1-2 minutes for a 30-second clip.

Batch style: Upload multiple files in one session. Process them one by one with different instructions. Each gets its own render.

Iterative: Start with a rough cut, preview the result, then refine. The session keeps your timeline state so you can keep tweaking.

Tips and Tricks

The backend processes faster when you're specific. Instead of "make it look better", try "trim the intro, add end screen elements, and export for YouTube upload" — concrete instructions get better results.

Max file size is 500MB. Stick to MP4, MOV, AVI, WebM for the smoothest experience.

Export as MP4 with H.264 codec for the best compatibility with YouTube's upload requirements.

Comments

Loading comments...