安全扫描
OpenClaw
可疑
medium confidenceThe skill's declared purpose (cloud video editing) largely matches what it does (upload user videos to a third‑party API using NEMO_TOKEN), but there are inconsistent metadata fields, opaque runtime instructions, and a few odd/incoherent instruction fragments that warrant caution before installing.
评估建议
This skill appears to be a legitimate cloud video editor that uploads your footage to a third‑party API and needs a NEMO_TOKEN. Before installing or using it: (1) Confirm you are comfortable uploading potentially sensitive video to https://mega-api-prod.nemovideo.ai and ask for the provider's privacy/retention policy; (2) Prefer using an ephemeral / limited-scope token rather than a long-lived high-privilege secret; (3) Ask the publisher to explain the apparent metadata inconsistency (the SKILL....详细分析 ▾
ℹ 用途与能力
Name/description (video editing) aligns with required credential NEMO_TOKEN and the documented API endpoints for uploads and renders. However, the SKILL.md frontmatter declares a config path (~/.config/nemovideo/) that is not present in the registry metadata, and the instructions ask the agent to detect an install path (to set X-Skill-Platform). These filesystem checks are not obviously required for editing and introduce a small mismatch between claimed requirements and runtime behavior.
⚠ 指令范围
The instructions tell the agent to read NEMO_TOKEN (expected) or obtain an anonymous token via an external POST (reasonable). They further instruct streaming SSE handling, polling, and uploading user media to https://mega-api-prod.nemovideo.ai — all expected for a cloud editor. Concerns: (1) SKILL.md says to 'keep the technical details out of the chat' which hides transmission/authorization steps from users; (2) the doc instructs the agent to detect install paths and include derived headers (requires filesystem awareness); (3) there's an odd truncated mapping ('click [button]' → 'Execute vi…') which looks incoherent and may indicate incomplete or incorrect instructions. The skill will upload user media to a third party — that is central to its function but requires explicit user consent and clear privacy/retention terms.
✓ 安装机制
Instruction-only skill with no install spec and no code files — lowest filesystem/write risk. Nothing is downloaded or written by an installer according to the manifest.
ℹ 凭证需求
Only one credential is required (NEMO_TOKEN), which is appropriate for a cloud API. The SKILL.md also includes a mechanism to mint anonymous tokens if none are present. The frontmatter's configPaths entry (~/.config/nemovideo/) is declared in the skill file but not in registry metadata — this inconsistency suggests the skill may attempt to read a local config path even though the registry reported none.
✓ 持久化与权限
always:false and no install operations. The skill does not request permanent presence or modifications to other skills. Note: the skill can be invoked autonomously by the agent (platform default) — combine that with the opaque 'keep technical details out of the chat' instruction and automated uploads to an external service, and you should consider whether you want the agent to run this skill without explicit per-use confirmation.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/4/19
Initial release of Video News — Edit News Clips for Broadcast. - Instantly edit raw news footage into 1080p MP4 broadcast-ready segments with AI-powered cloud rendering. - Upload video files (MP4, MOV, MXF, AVI up to 500MB) and use natural language to trim, caption, and edit. - Connects automatically to the backend; obtains a free token if needed for easy first-time setup. - Supports essential workflows: quick edits, iterative changes, and batch processing. - Handles video uploads, editing commands, export, credits checking, and timeline status. - Fast cloud GPU processing returns downloadable news clips, with clear feedback throughout.
● 无害
安装命令
点击复制官方npx clawhub@latest install video-news
镜像加速npx clawhub@latest install video-news --registry https://cn.longxiaskill.com