Skill flagged — suspicious patterns detected

ClawHub Security flagged this skill as suspicious. Review the scan results before using.

Loop Video Maker Free

v1.0.0

convert video clips into looped MP4 videos with this skill. Works with MP4, MOV, AVI, WebM files up to 500MB. TikTok creators use it for creating seamlessly...

0· 21·0 current·0 all-time
Security Scan
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Suspicious
medium confidence
Purpose & Capability
The skill's purpose (remote video looping/export) matches the API calls and file uploads described. However the manifest declares NEMO_TOKEN as a required primary credential while the SKILL.md also documents an automatic anonymous-token acquisition flow when NEMO_TOKEN is not present. Additionally the SKILL.md metadata references a config path (~/.config/nemovideo/) while the registry metadata earlier listed no config paths — this mismatch should be resolved.
Instruction Scope
Runtime instructions stay within the stated task: creating sessions, uploading videos, running render jobs, polling SSE and returning download URLs. The agent is explicitly instructed to transmit user video files and to manage session tokens. There are no instructions to read unrelated system files or other credentials.
Install Mechanism
This is an instruction-only skill with no install spec or code files, so it does not write binaries to disk or run an installer. That lowers installation risk.
!
Credentials
Only NEMO_TOKEN is declared as required, which is appropriate for a cloud API. But the SKILL.md's onboarding instructs the agent to automatically request and treat an anonymous token as NEMO_TOKEN if none is set. Requiring NEMO_TOKEN while also auto-provisioning one is inconsistent and may affect how credentials are stored or used. The presence of a config path in the SKILL.md metadata implies the skill may persist tokens/session IDs to disk — this is not declared consistently in registry metadata.
Persistence & Privilege
always:false (normal). The instructions require storing a session_id and a token for subsequent API calls; the SKILL.md hints at persisting state (metadata config path) but does not specify where or how. Confirm whether tokens/session IDs are stored only in-memory, in agent-managed ephemeral storage, or written to ~/.config/nemovideo/ (or elsewhere).
What to consider before installing
This skill will upload your video files to https://mega-api-prod.nemovideo.ai and will obtain and store an API token/session for render jobs. Before installing, consider: (1) Privacy — your videos are sent to an external, unvetted service; check retention and sharing policies. (2) Credential handling — the skill declares NEMO_TOKEN required but also auto-generates anonymous tokens; ask the author where tokens and session IDs are stored (in-memory vs written to ~/.config/nemovideo/). (3) If you want control, provide your own NEMO_TOKEN from a trusted account or decline anonymous provisioning. (4) Ask the publisher for source code or a homepage to verify implementation and data handling. If these questions are unanswered, treat the skill cautiously or avoid uploading sensitive content.

Like a lobster shell, security has layers — review code before you run it.

Runtime requirements

🔁 Clawdis
EnvNEMO_TOKEN
Primary envNEMO_TOKEN
latestvk973bnanngpx82n3vs3c5z4zps858z3a
21downloads
0stars
1versions
Updated 7h ago
v1.0.0
MIT-0

Getting Started

Share your video clips and I'll get started on loop video creation. Or just tell me what you're thinking.

Try saying:

  • "convert my video clips"
  • "export 1080p MP4"
  • "loop this video 5 times and"

First-Time Connection

When a user first opens this skill, connect to the processing backend automatically. Briefly let them know (e.g. "Setting up...").

Authentication: Check if NEMO_TOKEN is set in the environment. If it is, skip to step 2.

  1. Obtain a free token: Generate a random UUID as client identifier. POST to https://mega-api-prod.nemovideo.ai/api/auth/anonymous-token with header X-Client-Id set to that UUID. The response data.token is your NEMO_TOKEN — 100 free credits, valid 7 days.
  2. Create a session: POST to https://mega-api-prod.nemovideo.ai/api/tasks/me/with-session/nemo_agent with Authorization: Bearer <token>, Content-Type: application/json, and body {"task_name":"project","language":"<detected>"}. Store the returned session_id for all subsequent requests.

Keep setup communication brief. Don't display raw API responses or token values to the user.

Loop Video Maker Free — Loop and Export Videos Online

Send me your video clips and describe the result you want. The loop video creation runs on remote GPU nodes — nothing to install on your machine.

A quick example: upload a 10-second product clip, type "loop this video 5 times and export as a seamless MP4", and you'll get a 1080p MP4 back in roughly 20-40 seconds. All rendering happens server-side.

Worth noting: shorter source clips create smoother loops with less processing time.

Matching Input to Actions

User prompts referencing loop video maker free, aspect ratio, text overlays, or audio tracks get routed to the corresponding action via keyword and intent classification.

User says...ActionSkip SSE?
"export" / "导出" / "download" / "send me the video"→ §3.5 Export
"credits" / "积分" / "balance" / "余额"→ §3.3 Credits
"status" / "状态" / "show tracks"→ §3.4 State
"upload" / "上传" / user sends file→ §3.2 Upload
Everything else (generate, edit, add BGM…)→ §3.1 SSE

Cloud Render Pipeline Details

Each export job queues on a cloud GPU node that composites video layers, applies platform-spec compression (H.264, up to 1080x1920), and returns a download URL within 30-90 seconds. The session token carries render job IDs, so closing the tab before completion orphans the job.

Every API call needs Authorization: Bearer <NEMO_TOKEN> plus the three attribution headers above. If any header is missing, exports return 402.

Three attribution headers are required on every request and must match this file's frontmatter:

HeaderValue
X-Skill-Sourceloop-video-maker-free
X-Skill-Versionfrontmatter version
X-Skill-Platformauto-detect: clawhub / cursor / unknown from install path

API base: https://mega-api-prod.nemovideo.ai

Create session: POST /api/tasks/me/with-session/nemo_agent — body {"task_name":"project","language":"<lang>"} — returns task_id, session_id.

Send message (SSE): POST /run_sse — body {"app_name":"nemo_agent","user_id":"me","session_id":"<sid>","new_message":{"parts":[{"text":"<msg>"}]}} with Accept: text/event-stream. Max timeout: 15 minutes.

Upload: POST /api/upload-video/nemo_agent/me/<sid> — file: multipart -F "files=@/path", or URL: {"urls":["<url>"],"source_type":"url"}

Credits: GET /api/credits/balance/simple — returns available, frozen, total

Session state: GET /api/state/nemo_agent/me/<sid>/latest — key fields: data.state.draft, data.state.video_infos, data.state.generated_media

Export (free, no credits): POST /api/render/proxy/lambda — body {"id":"render_<ts>","sessionId":"<sid>","draft":<json>,"output":{"format":"mp4","quality":"high"}}. Poll GET /api/render/proxy/lambda/<id> every 30s until status = completed. Download URL at output.url.

Supported formats: mp4, mov, avi, webm, mkv, jpg, png, gif, webp, mp3, wav, m4a, aac.

Error Codes

  • 0 — success, continue normally
  • 1001 — token expired or invalid; re-acquire via /api/auth/anonymous-token
  • 1002 — session not found; create a new one
  • 2001 — out of credits; anonymous users get a registration link with ?bind=<id>, registered users top up
  • 4001 — unsupported file type; show accepted formats
  • 4002 — file too large; suggest compressing or trimming
  • 400 — missing X-Client-Id; generate one and retry
  • 402 — free plan export blocked; not a credit issue, subscription tier
  • 429 — rate limited; wait 30s and retry once

Backend Response Translation

The backend assumes a GUI exists. Translate these into API actions:

Backend saysYou do
"click [button]" / "点击"Execute via API
"open [panel]" / "打开"Query session state
"drag/drop" / "拖拽"Send edit via SSE
"preview in timeline"Show track summary
"Export button" / "导出"Execute export workflow

Reading the SSE Stream

Text events go straight to the user (after GUI translation). Tool calls stay internal. Heartbeats and empty data: lines mean the backend is still working — show "⏳ Still working..." every 2 minutes.

About 30% of edit operations close the stream without any text. When that happens, poll /api/state to confirm the timeline changed, then tell the user what was updated.

Draft JSON uses short keys: t for tracks, tt for track type (0=video, 1=audio, 7=text), sg for segments, d for duration in ms, m for metadata.

Example timeline summary:

Timeline (3 tracks): 1. Video: city timelapse (0-10s) 2. BGM: Lo-fi (0-10s, 35%) 3. Title: "Urban Dreams" (0-3s)

Common Workflows

Quick edit: Upload → "loop this video 5 times and export as a seamless MP4" → Download MP4. Takes 20-40 seconds for a 30-second clip.

Batch style: Upload multiple files in one session. Process them one by one with different instructions. Each gets its own render.

Iterative: Start with a rough cut, preview the result, then refine. The session keeps your timeline state so you can keep tweaking.

Tips and Tricks

The backend processes faster when you're specific. Instead of "make it look better", try "loop this video 5 times and export as a seamless MP4" — concrete instructions get better results.

Max file size is 500MB. Stick to MP4, MOV, AVI, WebM for the smoothest experience.

Export as MP4 for widest compatibility across platforms and devices.

Comments

Loading comments...