Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
Ai Video Travel Vlog Tips
v1.0.0Film, edit, and publish engaging travel vlogs that build an audience with AI — generate travel vlog tips videos covering camera gear selection, on-location f...
⭐ 0· 47·0 current·0 all-time
by@udnerc
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Suspicious
medium confidencePurpose & Capability
The name/description promise AI-generated travel-vlog guidance and references 'NemoVideo' in the SKILL.md. Declaring a primary credential named NEMO_TOKEN and a NemoVideo config path (~/.config/nemovideo/) is consistent with an integration that calls an external video service. However, the registry metadata lists required.env as an empty array while also listing primaryEnv=NEMO_TOKEN and configPaths — that mismatch is inconsistent and should be clarified by the author.
Instruction Scope
The SKILL.md is instruction-only and the visible content is focused on generating filming, storytelling, and editing guidance. There are no explicit runtime commands or instructions to read unrelated system files in the visible text. However, the skill metadata declares a config path (~/.config/nemovideo/) — so the skill may expect to read that config at runtime. The SKILL.md does not explicitly document what will be read from that config or how NEMO_TOKEN will be used, which is an omission worth clarifying.
Install Mechanism
No install spec and no code files are present (instruction-only). This reduces installation risk because nothing is downloaded or written to disk by an installer.
Credentials
Requesting a single primary credential (NEMO_TOKEN) and a NemoVideo config path is proportionate if the skill integrates with a NemoVideo service. But the required.env array is empty while primaryEnv lists NEMO_TOKEN — an inconsistency. The skill does not request unrelated credentials, but you should confirm whether the token is mandatory and what permissions it grants.
Persistence & Privilege
always is false and the skill is user-invocable; it does not request elevated persistence. There is no install step that would grant long-lived system presence.
What to consider before installing
This skill appears to be a content-generation assistant that may call a NemoVideo service. Before installing or supplying any secrets: (1) Confirm the skill author/source and that 'NemoVideo' is a legitimate service you trust. (2) Ask the author to correct the metadata inconsistency (primaryEnv=NEMO_TOKEN should appear in requires.env) and to document exactly how NEMO_TOKEN and ~/.config/nemovideo/ will be used. (3) If you must provide a token, prefer an account/token with limited scope or an ephemeral credential you can revoke. (4) Inspect the ~/.config/nemovideo/ files (if present) to see what they contain before allowing the skill to read them. (5) If provenance cannot be established, avoid supplying credentials.Like a lobster shell, security has layers — review code before you run it.
latestvk97djmqv4e6m7s2ha2ht0fz50x83v0cn
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
🎬 Clawdis
Primary envNEMO_TOKEN
