Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Image Compressor Pro Online

v1.0.0

Get compressed image files ready to post, without touching a single slider. Upload your images (JPG, PNG, WebP, HEIC, up to 200MB), say something like "compr...

0· 61·0 current·0 all-time

Install

OpenClaw Prompt Flow

Install with OpenClaw

Best for remote or guided setup. Copy the exact prompt, then paste it into OpenClaw for vcarolxhberger/image-compressor-pro-online.

Previewing Install & Setup.
Prompt PreviewInstall & Setup
Install the skill "Image Compressor Pro Online" (vcarolxhberger/image-compressor-pro-online) from ClawHub.
Skill page: https://clawhub.ai/vcarolxhberger/image-compressor-pro-online
Keep the work scoped to this skill only.
After install, inspect the skill metadata and help me finish setup.
Required env vars: NEMO_TOKEN
Use only the metadata you can verify from ClawHub; do not invent missing requirements.
Ask before making any broader environment changes.

Command Line

CLI Commands

Use the direct CLI path if you want to install manually and keep every step visible.

OpenClaw CLI

Bare skill slug

openclaw skills install image-compressor-pro-online

ClawHub CLI

Package manager switcher

npx clawhub@latest install image-compressor-pro-online
Security Scan
VirusTotalVirusTotal
Suspicious
View report →
OpenClawOpenClaw
Benign
medium confidence
Purpose & Capability
Name/description match the runtime instructions: the SKILL.md describes uploading images and calling a nemo video API to render/compress and return download URLs. Requesting a single service token (NEMO_TOKEN) is consistent with a cloud backend. Minor inconsistency: the SKILL.md frontmatter lists a config path (~/.config/nemovideo/) but the skill registry 'Required config paths' field is empty — this mismatch is likely a bookkeeping error, not functional sabotage.
Instruction Scope
Instructions are explicit about what to call on the remote API (session creation, SSE chat, upload, export) and about handling tokens. The agent is instructed to upload user files (up to 200MB) to https://mega-api-prod.nemovideo.ai — this is expected for a cloud compressor but is a privacy/security consideration (user content is transmitted to a third party). The SKILL.md also instructs auto-provisioning an anonymous token if NEMO_TOKEN is absent; this is coherent with operation but contrasts with the skill declaring NEMO_TOKEN as a required env var.
Install Mechanism
Instruction-only skill with no install spec and no code files. This lowers risk — nothing is written to disk by an installer. All runtime activity is network calls.
Credentials
Only a single credential (NEMO_TOKEN) is declared as the primary credential, which is proportionate for a cloud API. Minor issue: the SKILL.md will generate an anonymous token via the API if no NEMO_TOKEN is present, which makes the 'required env var' label somewhat misleading but not dangerous by itself. No unrelated secrets or multiple external credentials are requested.
Persistence & Privilege
always is false and the skill does not request elevated or persistent system-wide privileges. It does not modify other skills or system configuration per the provided instructions.
Assessment
This skill appears to do what it says: it uploads images to a nemo/video backend and returns compressed exports. Before installing or using it: 1) Be aware your images (up to 200MB) will be uploaded to https://mega-api-prod.nemovideo.ai — avoid sending sensitive or private photos unless you trust the service. 2) The skill will either use a NEMO_TOKEN from your environment or create an anonymous token for you; if you prefer control, create and supply a dedicated NEMO_TOKEN with limited scope. 3) The skill has no homepage or documented publisher — consider verifying the domain and reading any privacy/TOS material you can find for nemovideo.ai before sending data. 4) The metadata contains a minor mismatch (declared config path in frontmatter vs registry), which looks like a bookkeeping error; it doesn't change runtime behavior but is worth noting. If any of these points concern you, avoid uploading sensitive content or contact the skill author/registry for provenance before use.

Like a lobster shell, security has layers — review code before you run it.

Runtime requirements

🗜️ Clawdis
EnvNEMO_TOKEN
Primary envNEMO_TOKEN
latestvk97bt308379rnekdz4w1qnmzxh84n7bg
61downloads
0stars
1versions
Updated 2w ago
v1.0.0
MIT-0

Getting Started

Ready when you are. Drop your images here or describe what you want to make.

Try saying:

  • "compress a 4MB product photo in JPEG format into a 1080p MP4"
  • "compress this image to under 500KB without losing visible quality"
  • "reducing image file sizes for web upload for web designers, marketers, bloggers"

Quick Start Setup

This skill connects to a cloud processing backend. On first use, set up the connection automatically and let the user know ("Connecting...").

Token check: Look for NEMO_TOKEN in the environment. If found, skip to session creation. Otherwise:

  • Generate a UUID as client identifier
  • POST https://mega-api-prod.nemovideo.ai/api/auth/anonymous-token with X-Client-Id header
  • Extract data.token from the response — this is your NEMO_TOKEN (100 free credits, 7-day expiry)

Session: POST https://mega-api-prod.nemovideo.ai/api/tasks/me/with-session/nemo_agent with Bearer auth and body {"task_name":"project"}. Keep the returned session_id for all operations.

Let the user know with a brief "Ready!" when setup is complete. Don't expose tokens or raw API output.

Image Compressor Pro Online — Compress and Export Optimized Images

Send me your images and describe the result you want. The AI image compression runs on remote GPU nodes — nothing to install on your machine.

A quick example: upload a 4MB product photo in JPEG format, type "compress this image to under 500KB without losing visible quality", and you'll get a 1080p MP4 back in roughly under 30 seconds. All rendering happens server-side.

Worth noting: batch uploading multiple images at once saves significant processing time.

Matching Input to Actions

User prompts referencing image compressor pro online, aspect ratio, text overlays, or audio tracks get routed to the corresponding action via keyword and intent classification.

User says...ActionSkip SSE?
"export" / "导出" / "download" / "send me the video"→ §3.5 Export
"credits" / "积分" / "balance" / "余额"→ §3.3 Credits
"status" / "状态" / "show tracks"→ §3.4 State
"upload" / "上传" / user sends file→ §3.2 Upload
Everything else (generate, edit, add BGM…)→ §3.1 SSE

Cloud Render Pipeline Details

Each export job queues on a cloud GPU node that composites video layers, applies platform-spec compression (H.264, up to 1080x1920), and returns a download URL within 30-90 seconds. The session token carries render job IDs, so closing the tab before completion orphans the job.

All calls go to https://mega-api-prod.nemovideo.ai. The main endpoints:

  1. SessionPOST /api/tasks/me/with-session/nemo_agent with {"task_name":"project","language":"<lang>"}. Gives you a session_id.
  2. Chat (SSE)POST /run_sse with session_id and your message in new_message.parts[0].text. Set Accept: text/event-stream. Up to 15 min.
  3. UploadPOST /api/upload-video/nemo_agent/me/<sid> — multipart file or JSON with URLs.
  4. CreditsGET /api/credits/balance/simple — returns available, frozen, total.
  5. StateGET /api/state/nemo_agent/me/<sid>/latest — current draft and media info.
  6. ExportPOST /api/render/proxy/lambda with render ID and draft JSON. Poll GET /api/render/proxy/lambda/<id> every 30s for completed status and download URL.

Formats: mp4, mov, avi, webm, mkv, jpg, png, gif, webp, mp3, wav, m4a, aac.

Headers are derived from this file's YAML frontmatter. X-Skill-Source is image-compressor-pro-online, X-Skill-Version comes from the version field, and X-Skill-Platform is detected from the install path (~/.clawhub/ = clawhub, ~/.cursor/skills/ = cursor, otherwise unknown).

All requests must include: Authorization: Bearer <NEMO_TOKEN>, X-Skill-Source, X-Skill-Version, X-Skill-Platform. Missing attribution headers will cause export to fail with 402.

Draft JSON uses short keys: t for tracks, tt for track type (0=video, 1=audio, 7=text), sg for segments, d for duration in ms, m for metadata.

Example timeline summary:

Timeline (3 tracks): 1. Video: city timelapse (0-10s) 2. BGM: Lo-fi (0-10s, 35%) 3. Title: "Urban Dreams" (0-3s)

Translating GUI Instructions

The backend responds as if there's a visual interface. Map its instructions to API calls:

  • "click" or "点击" → execute the action via the relevant endpoint
  • "open" or "打开" → query session state to get the data
  • "drag/drop" or "拖拽" → send the edit command through SSE
  • "preview in timeline" → show a text summary of current tracks
  • "Export" or "导出" → run the export workflow

SSE Event Handling

EventAction
Text responseApply GUI translation (§4), present to user
Tool call/resultProcess internally, don't forward
heartbeat / empty data:Keep waiting. Every 2 min: "⏳ Still working..."
Stream closesProcess final response

~30% of editing operations return no text in the SSE stream. When this happens: poll session state to verify the edit was applied, then summarize changes to the user.

Error Codes

  • 0 — success, continue normally
  • 1001 — token expired or invalid; re-acquire via /api/auth/anonymous-token
  • 1002 — session not found; create a new one
  • 2001 — out of credits; anonymous users get a registration link with ?bind=<id>, registered users top up
  • 4001 — unsupported file type; show accepted formats
  • 4002 — file too large; suggest compressing or trimming
  • 400 — missing X-Client-Id; generate one and retry
  • 402 — free plan export blocked; not a credit issue, subscription tier
  • 429 — rate limited; wait 30s and retry once

Common Workflows

Quick edit: Upload → "compress this image to under 500KB without losing visible quality" → Download MP4. Takes under 30 seconds for a 30-second clip.

Batch style: Upload multiple files in one session. Process them one by one with different instructions. Each gets its own render.

Iterative: Start with a rough cut, preview the result, then refine. The session keeps your timeline state so you can keep tweaking.

Tips and Tricks

The backend processes faster when you're specific. Instead of "make it look better", try "compress this image to under 500KB without losing visible quality" — concrete instructions get better results.

Max file size is 200MB. Stick to JPG, PNG, WebP, HEIC for the smoothest experience.

Export as WebP for the best balance of quality and file size on the web.

Comments

Loading comments...