安全扫描
OpenClaw
可疑
medium confidenceThe skill's functionality (cloud video/title generation) mostly matches its requirements, but there are inconsistencies and privacy concerns — it will obtain/use tokens and upload user videos to an external API whose provenance is unclear and the SKILL.md asks the agent to hide token values and may reference a user config path that wasn't declared.
评估建议
This skill appears to be what it claims (cloud title/video processing) but has ambiguous and potentially privacy-sensitive behaviors you should confirm before installing: 1) It uploads your video files to https://mega-api-prod.nemovideo.ai — only use it for content you are comfortable sending to a third party. 2) The SKILL.md will auto-create an anonymous token if you don't provide one; ask whether that token and any session_id are stored on disk (and where) and for how long jobs/files are retai...详细分析 ▾
ℹ 用途与能力
The stated purpose (generate viral titles and render/export videos) aligns with calls to a video-processing backend and the single required credential NEMO_TOKEN. However: (1) the registry metadata shown earlier states no required config paths, while the SKILL.md frontmatter lists ~/.config/nemovideo/ (inconsistency), and (2) the skill's source and homepage are unknown, so the external endpoint (mega-api-prod.nemovideo.ai) cannot be validated from the registry data.
⚠ 指令范围
Runtime instructions tell the agent to automatically obtain an anonymous token, create sessions, upload user video files (up to 500MB), and keep token values hidden from users. Uploading user videos to a third-party API is expected for this service, but the instructions also instruct the agent not to show raw API responses or tokens (which reduces transparency) and reference storing session_id for subsequent requests without specifying where/how (in-memory vs disk). The SKILL.md frontmatter requires attribution headers and detection of install path, which implies the agent may inspect its environment/paths.
✓ 安装机制
There is no install spec and no code files — this instruction-only skill does not install packages or write archives to disk by itself, which is low-risk from an install perspective.
ℹ 凭证需求
The skill declares a single required credential (NEMO_TOKEN), which is proportionate to a hosted video-processing service. Caveats: the SKILL.md instructs the agent to auto-generate and use an anonymous token if NEMO_TOKEN isn't provided (so the agent can operate without user-supplied credentials), and the frontmatter's configPaths (~/.config/nemovideo/) introduces potential access to user config files that wasn't reflected in the registry summary — this mismatch should be clarified.
ℹ 持久化与权限
always:false (normal). The skill may persist a session token/session_id for ongoing uploads/exports; the SKILL.md doesn't explicitly say whether those are stored only in memory or written to ~/.config/nemovideo/ (frontmatter suggests that path). Persisting tokens to disk or modifying user config would increase privilege and privacy impact — clarify where session data and tokens are stored and how long they are retained.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/4/19
Initial release of Viral Title Generator Free — a tool for instantly generating click-worthy video titles. - Upload your video (MP4, MOV, AVI, WebM, up to 500MB) and receive viral title suggestions in under 20 seconds. - Automatic setup with free 7-day, 100-credit token; no manual installation required. - Seamless integration with cloud GPU rendering, exporting 1080p MP4 files. - Simple command prompts and auto-session management for YouTubers and content creators. - Robust support for multiple file formats and error handling for common issues.
● 无害
安装命令
点击复制官方npx clawhub@latest install viral-title-generator-free
镜像加速npx clawhub@latest install viral-title-generator-free --registry https://cn.longxiaskill.com