Generator By Image
ReviewAudited by ClawScan on May 3, 2026.
Overview
This appears to be a purpose-aligned cloud video-generation skill, but it uses or creates a NemoVideo token and uploads user media to an external API.
Before installing, decide whether you are comfortable sending images, audio, video, and prompts to NemoVideo's cloud API. Use a dedicated token if available, avoid uploading sensitive personal or confidential media, and consider asking the agent to confirm before uploads or exports that may consume credits.
Findings (4)
Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.
The agent may create or use a NemoVideo token and perform actions tied to that token, including rendering jobs that may consume credits.
The skill uses or obtains a provider bearer token for NemoVideo. This is expected for a cloud-rendering integration, but it grants account/session access and may involve credits.
If `NEMO_TOKEN` environment variable is already set, use it... Free token: Generate a UUID... POST to `https://mega-api-prod.nemovideo.ai/api/auth/anonymous-token`... `data.token` becomes your NEMO_TOKEN
Use a dedicated token if possible, do not share it in chat, and monitor or revoke the token if you no longer use the skill.
Private or sensitive media uploaded through this skill may leave the local environment and be processed by NemoVideo's service.
User images, prompts, and possibly audio/video files are sent to an external cloud API for processing. This is central to the skill, but the visible artifact does not describe retention or privacy guarantees.
Drop your images in the chat... I'll handle the AI video creation on cloud GPUs... All calls go to `https://mega-api-prod.nemovideo.ai`... **Upload** — `POST /api/upload-video/nemo_agent/me/<sid>`
Only upload media you are comfortable sending to that provider, and review the provider's privacy/retention terms if the content is sensitive.
The agent may create sessions, upload files, poll status, or start export jobs after the skill is invoked, potentially using provider credits.
The skill directs the agent to make API calls automatically during setup and to translate backend/user workflow terms into provider actions. This is expected for the integration, but users should be aware that actions can be initiated as part of the workflow.
On first interaction, connect to the processing API before doing anything else... `Export` or `导出` → run the export workflow
If you want tighter control, ask the agent to confirm before uploads, exports, or other credit-consuming operations.
Users have less information for verifying who maintains the skill or whether the external service is the intended one.
The skill has limited provenance information. There is no local code or install script in the supplied artifacts, so this is not evidence of malicious behavior, but it makes independent verification harder.
Source: unknown; Homepage: none
Verify the NemoVideo domain and provider independently before uploading sensitive files or relying on the service for important work.
