Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Hd Editor Ai

v1.0.0

edit raw video footage into HD edited videos with this hd-editor-ai skill. Works with MP4, MOV, AVI, WebM files up to 500MB. content creators use it for upsc...

0· 63·0 current·0 all-time
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The name/description align with making API calls to a cloud video-processing backend and needing a NEMO_TOKEN credential. However the skill's frontmatter mentions a config path (~/.config/nemovideo/) that is not declared elsewhere in the registry metadata, which is unexpected for a simple instruction-only connector.
Instruction Scope
The SKILL.md primarily instructs the agent to authenticate (optionally generating an anonymous token), create a session, upload video files, run SSE-based edit commands, poll for renders, and download results — actions consistent with a remote HD editing service. Notable points: it tells the agent to auto-generate/store session tokens, to include several custom headers on every request, and to auto-connect on first use. The doc also instructs reading local file paths for multipart uploads (expected for file upload) but is vague about where session tokens should be stored (memory vs disk) and about any use of the declared config path.
Install Mechanism
No install spec and no code files are present (instruction-only). That minimizes on-disk changes and external code execution risk.
!
Credentials
Only NEMO_TOKEN is required which fits the described cloud API integration. But the frontmatter requests a config path (~/.config/nemovideo/) while the registry metadata lists no required config paths — this mismatch is unexplained and could imply unnecessary filesystem access. Also the skill will auto-generate and persist anonymous tokens/sessions unless clarified.
Persistence & Privilege
always:false and no install means the skill doesn't request elevated or permanent presence. The only persistence behavior described is storing a session_id/token for API calls, which is normal but unspecified (where/how).
What to consider before installing
This skill appears to call an external cloud service to process videos (uploads your files to https://mega-api-prod.nemovideo.ai). Before installing: (1) Confirm you trust that domain and are comfortable uploading potentially sensitive video content to it. (2) Ask the publisher to clarify why the frontmatter lists ~/.config/nemovideo/ (will the skill read/write that directory?) and where session tokens are stored (in-memory vs written to disk). (3) If you already have a NEMO_TOKEN, prefer providing it explicitly rather than relying on automatic anonymous-token creation. (4) Verify the privacy/retention policy for uploaded videos and generated tokens (tokens expire in 7 days per docs). (5) If you need stronger assurance, request an explanation of the required headers/attribution behavior and a signed source/homepage for the skill — the package currently has no homepage and an unknown source, which reduces accountability.

Like a lobster shell, security has layers — review code before you run it.

Runtime requirements

🎬 Clawdis
EnvNEMO_TOKEN
Primary envNEMO_TOKEN
latestvk97drwcecvd6qrrzgqqzdc67jx84k0e8
63downloads
0stars
1versions
Updated 1w ago
v1.0.0
MIT-0

Getting Started

Share your raw video footage and I'll get started on AI HD editing. Or just tell me what you're thinking.

Try saying:

  • "edit my raw video footage"
  • "export 1080p MP4"
  • "enhance video quality to HD, cut"

First-Time Connection

When a user first opens this skill, connect to the processing backend automatically. Briefly let them know (e.g. "Setting up...").

Authentication: Check if NEMO_TOKEN is set in the environment. If it is, skip to step 2.

  1. Obtain a free token: Generate a random UUID as client identifier. POST to https://mega-api-prod.nemovideo.ai/api/auth/anonymous-token with header X-Client-Id set to that UUID. The response data.token is your NEMO_TOKEN — 100 free credits, valid 7 days.
  2. Create a session: POST to https://mega-api-prod.nemovideo.ai/api/tasks/me/with-session/nemo_agent with Authorization: Bearer <token>, Content-Type: application/json, and body {"task_name":"project","language":"<detected>"}. Store the returned session_id for all subsequent requests.

Keep setup communication brief. Don't display raw API responses or token values to the user.

HD Editor AI — Edit and Export HD Videos

Send me your raw video footage and describe the result you want. The AI HD editing runs on remote GPU nodes — nothing to install on your machine.

A quick example: upload a 2-minute 1080p phone recording, type "enhance video quality to HD, cut dead air, and add smooth transitions", and you'll get a 1080p MP4 back in roughly 1-2 minutes. All rendering happens server-side.

Worth noting: shorter clips under 60 seconds process faster and yield sharper HD results.

Matching Input to Actions

User prompts referencing hd editor ai, aspect ratio, text overlays, or audio tracks get routed to the corresponding action via keyword and intent classification.

User says...ActionSkip SSE?
"export" / "导出" / "download" / "send me the video"→ §3.5 Export
"credits" / "积分" / "balance" / "余额"→ §3.3 Credits
"status" / "状态" / "show tracks"→ §3.4 State
"upload" / "上传" / user sends file→ §3.2 Upload
Everything else (generate, edit, add BGM…)→ §3.1 SSE

Cloud Render Pipeline Details

Each export job queues on a cloud GPU node that composites video layers, applies platform-spec compression (H.264, up to 1080x1920), and returns a download URL within 30-90 seconds. The session token carries render job IDs, so closing the tab before completion orphans the job.

Every API call needs Authorization: Bearer <NEMO_TOKEN> plus the three attribution headers above. If any header is missing, exports return 402.

Three attribution headers are required on every request and must match this file's frontmatter:

HeaderValue
X-Skill-Sourcehd-editor-ai
X-Skill-Versionfrontmatter version
X-Skill-Platformauto-detect: clawhub / cursor / unknown from install path

API base: https://mega-api-prod.nemovideo.ai

Create session: POST /api/tasks/me/with-session/nemo_agent — body {"task_name":"project","language":"<lang>"} — returns task_id, session_id.

Send message (SSE): POST /run_sse — body {"app_name":"nemo_agent","user_id":"me","session_id":"<sid>","new_message":{"parts":[{"text":"<msg>"}]}} with Accept: text/event-stream. Max timeout: 15 minutes.

Upload: POST /api/upload-video/nemo_agent/me/<sid> — file: multipart -F "files=@/path", or URL: {"urls":["<url>"],"source_type":"url"}

Credits: GET /api/credits/balance/simple — returns available, frozen, total

Session state: GET /api/state/nemo_agent/me/<sid>/latest — key fields: data.state.draft, data.state.video_infos, data.state.generated_media

Export (free, no credits): POST /api/render/proxy/lambda — body {"id":"render_<ts>","sessionId":"<sid>","draft":<json>,"output":{"format":"mp4","quality":"high"}}. Poll GET /api/render/proxy/lambda/<id> every 30s until status = completed. Download URL at output.url.

Supported formats: mp4, mov, avi, webm, mkv, jpg, png, gif, webp, mp3, wav, m4a, aac.

Error Handling

CodeMeaningAction
0SuccessContinue
1001Bad/expired tokenRe-auth via anonymous-token (tokens expire after 7 days)
1002Session not foundNew session §3.0
2001No creditsAnonymous: show registration URL with ?bind=<id> (get <id> from create-session or state response when needed). Registered: "Top up credits in your account"
4001Unsupported fileShow supported formats
4002File too largeSuggest compress/trim
400Missing X-Client-IdGenerate Client-Id and retry (see §1)
402Free plan export blockedSubscription tier issue, NOT credits. "Register or upgrade your plan to unlock export."
429Rate limit (1 token/client/7 days)Retry in 30s once

Translating GUI Instructions

The backend responds as if there's a visual interface. Map its instructions to API calls:

  • "click" or "点击" → execute the action via the relevant endpoint
  • "open" or "打开" → query session state to get the data
  • "drag/drop" or "拖拽" → send the edit command through SSE
  • "preview in timeline" → show a text summary of current tracks
  • "Export" or "导出" → run the export workflow

Reading the SSE Stream

Text events go straight to the user (after GUI translation). Tool calls stay internal. Heartbeats and empty data: lines mean the backend is still working — show "⏳ Still working..." every 2 minutes.

About 30% of edit operations close the stream without any text. When that happens, poll /api/state to confirm the timeline changed, then tell the user what was updated.

Draft field mapping: t=tracks, tt=track type (0=video, 1=audio, 7=text), sg=segments, d=duration(ms), m=metadata.

Timeline (3 tracks): 1. Video: city timelapse (0-10s) 2. BGM: Lo-fi (0-10s, 35%) 3. Title: "Urban Dreams" (0-3s)

Common Workflows

Quick edit: Upload → "enhance video quality to HD, cut dead air, and add smooth transitions" → Download MP4. Takes 1-2 minutes for a 30-second clip.

Batch style: Upload multiple files in one session. Process them one by one with different instructions. Each gets its own render.

Iterative: Start with a rough cut, preview the result, then refine. The session keeps your timeline state so you can keep tweaking.

Tips and Tricks

The backend processes faster when you're specific. Instead of "make it look better", try "enhance video quality to HD, cut dead air, and add smooth transitions" — concrete instructions get better results.

Max file size is 500MB. Stick to MP4, MOV, AVI, WebM for the smoothest experience.

Export as MP4 with H.264 codec for the best balance of HD quality and file size.

Comments

Loading comments...