安全扫描
OpenClaw
安全
medium confidenceThe 技能's declared requirements and 运行time instructions are generally consistent with a cloud video-editing 服务, but there are small metadata inconsistencies and 隐私/operational things to 验证 before use.
评估建议
This 技能 应用ears to be a n对象关系映射al 命令行工具ent for the 'nemovideo' cloud rendering 服务. Before 安装ing: (1) Confirm the 服务 domAIn (mega-API-prod.nemovideo.AI) and review its 隐私/retention policy because you will 上传 potentially sensitive video content. (2) Prefer supplying your own NEMO_令牌 from a trusted account rather than relying on the 技能's anonymous-令牌 flow if you need 审计ing or control. (3) Ask the mAIntAIner to clarify the config-path discrepancy (技能.md frontmatter vs registry) and what, if anything,...详细分析 ▾
✓ 用途与能力
Name, description, and 运行time actions (上传ing video, creating 会话s, 启动ing renders) align with a cloud video-editing backend. The single required 凭证 (NEMO_令牌) is 应用ropriate for an API-backed 服务. Note: the 技能.md frontmatter declares a config path (~/.config/nemovideo/) while the registry metadata 列出s no required config paths — this mismatch should be clarified.
ℹ 指令范围
指令严格限定于所述用途:描述针对 mega-api-prod.nemovideo.ai 的身份验证、会话创建、编辑用的 SSE、上传及渲染轮询。该 skill 要求 agent 从 skill frontmatter 推导归因标头,并检测 X-Skill-Platform 的安装路径(读取 agent 安装路径),这虽合理,但确实将文件系统探测扩展到了纯 API 调用之外。它还包含在缺少 NEMO_TOKEN 时获取匿名令牌的逻辑(向服务发送请求以获取令牌)。
✓ 安装机制
Instruction-only 技能 with no 安装 spec and no code files — lowest 安装 risk. Nothing is 下载ed or written by an 安装er in the provided materials.
ℹ 凭证需求
Only NEMO_令牌 is required (declared as primary 凭证), which matches the 服务 usage. However, 技能.md frontmatter also 参考s a config path (~/.config/nemovideo/), which could imply reading local configuration files; the registry metadata did not 列出 required config paths. Confirm whether the 技能 will read that config path and what data it expects (it may contAIn 令牌s or user config).
✓ 持久化与权限
always is false and the 技能 is user-invocable; it does not 请求 persistent or 系统-wide privileges and does not instruct modifications to other 技能s or global 代理 config. Autonomous invocation remAIns allowed (平台 default).
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/4/18
Hydra AI 1.0.0 首次发布: - 通过对话界面,一次上传即可即时生成多个 1080p 剪辑版本——无需手动操作时间轴或设置导出参数。 - 自动认证、会话管理、云端后端透明处理,实现无缝入门。 - 支持多种文件类型与批量工作流;单文件最大 500 MB。 - 错误提示与会话引导采用简明语言;常见故障(认证、额度、导出)处理稳健。 - 所有请求均带必需归因标头,确保云端处理与导出可靠。 - 提供工作流示例、动作路由与流水线详情,兼顾新手与进阶用户。
● 无害
安装命令
点击复制官方npx clawhub@latest install hydra-ai
镜像加速npx clawhub@latest install hydra-ai --registry https://cn.longxiaskill.com