安全扫描
OpenClaw
可疑
medium confidenceThe skill's stated purpose (AI video generation) aligns with its runtime instructions, but there are inconsistencies and privacy/operational concerns (unknown backend, metadata mismatches, automatic token issuance and file uploads) that warrant caution before installing.
评估建议
This skill appears to do what it says (generate/upload/render videos) but you should be cautious before installing because: 1) the backend domain (mega-api-prod.nemovideo.ai) and skill source are unknown — verify the service and its privacy/terms before sending content; 2) the skill will upload your files and session info to that external service, so do not use it with sensitive or private video/audio without checking retention and access controls; 3) metadata is inconsistent (SKILL.md reference...详细分析 ▾
ℹ 用途与能力
The skill claims to convert text prompts into AI-generated videos and its instructions describe upload, SSE streaming, render, and export endpoints that match that purpose. However, registry metadata lists no required config paths while the SKILL.md frontmatter declares a config path (~/.config/nemovideo/), and the skill's source/homepage are unknown — an inconsistency in metadata provenance.
⚠ 指令范围
Runtime instructions tell the agent to contact an external API (mega-api-prod.nemovideo.ai), obtain or use a NEMO_TOKEN, create sessions, upload user files (multipart @/path or URLs), and detect an install path (~/.clawhub/, ~/.cursor/skills/) to set an X-Skill-Platform header. These are within a video-service scope, but they require network access and reading user-supplied file paths and some local path detection — which has privacy implications. The doc also instructs to 'not display raw API responses or token values' (oddly prescriptive).
✓ 安装机制
No install spec or code files are included — the skill is instruction-only, which reduces filesystem risk. However, it will make outbound HTTPS calls to an external API host that is not a well-known vendor; that's an operational/trust consideration rather than an install risk.
ℹ 凭证需求
Only one environment variable is declared (NEMO_TOKEN) which is coherent for an external API. But the instructions say the skill will auto-obtain an anonymous token if NEMO_TOKEN is absent, making the declared required-env somewhat inconsistent with behavior. No other unrelated credentials are requested.
✓ 持久化与权限
always is false and the skill does not request permanent platform presence. It does instruct storing a session_id for requests, which is normal for session-based APIs and not an elevated privilege.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/4/17
Free Video Generator Chat GPT 1.0.0 — Initial Release - Generate 1080p AI videos from text prompts in 1-2 minutes; supports MP4, MOV, WebM, AVI (up to 500MB). - Automated backend connection, free anonymous authentication (100 credits, 7-day token). - Simple workflows for upload, edit, export, credits check, and session state. - Organized input routing: handles prompt-based generation, export, credits, file upload, and timeline preview. - Session-based edits support iterative refinement and quick batch processing. - Seamless error handling for authentication, session, credits, file type/size, and rate limits.
● Pending
安装命令 点击复制
官方npx clawhub@latest install free-video-generator-chat-gpt
镜像加速npx clawhub@latest install free-video-generator-chat-gpt --registry https://cn.clawhub-mirror.com
数据来源:ClawHub ↗ · 中文优化:龙虾技能库
OpenClaw 技能定制 / 插件定制 / 私有工作流定制
免费技能或插件可能存在安全风险,如需更匹配、更安全的方案,建议联系付费定制