安全扫描
OpenClaw
可疑
medium confidence该技能行为主要与云视频编辑器一致,但自动创建/存储匿名令牌、缺乏发布者/主页以及未指定数据保留政策,使其在使用前值得更仔细审查。
评估建议
["确认是否信任 `mega-api-prod.nemovideo.ai`(该技能无主页或发布者信息)","询问令牌/会话 ID 的存储位置(文件系统 vs 内存)和是否其他进程可以读取它们","避免提供其他凭据;不要重用敏感令牌为 `NEMO_TOKEN`","检查数据保留/隐私政策以及上传视频是否存储、共享或用于模型训练","对于敏感视频,优先使用短期或一次性账户/令牌","如果需要更高的保证,请请求技能的源代码或官方文档,或者先在隔离环境中测试"]...详细分析 ▾
✓ 用途与能力
Name/description, endpoints, and required NEMO_TOKEN line up with a cloud video editing service. Supported file types and API actions (upload, render, export) are consistent with the declared purpose.
⚠ 指令范围
Runtime instructions direct the agent to obtain an anonymous token automatically, create and persist sessions, and upload user video files to an external domain (mega-api-prod.nemovideo.ai). Automatically generating and storing credentials/session IDs without explicit user consent or a documented storage location is scope creep and a privacy concern.
✓ 安装机制
No install spec or code files are present (instruction-only), so nothing is written to disk by the skill itself. This is lower risk from an installation perspective.
ℹ 凭证需求
Only a single credential (NEMO_TOKEN) is required, which is appropriate for a remote API. However metadata requests a config path (~/.config/nemovideo/) and the instructions ask to store tokens/session IDs; it's not clear where/how these are stored or who can read them, which raises proportionality/privacy questions.
ℹ 持久化与权限
Skill is not 'always' installed and uses normal autonomous invocation. It does instruct the agent to persist tokens/session IDs and warns jobs may be orphaned; persistent credentials combined with autonomous network calls increases blast radius if the endpoint or token handling is abused.
安全有层次,运行前请审查代码。
运行时依赖
无特殊依赖
版本
latestv1.0.02026/4/10
最佳 AI 视频编辑器 — 初始发布 - 启动 `editor-ai-best`:一款面向创作者和营销人员的 AI 云视频编辑器。 - 支持上传和编辑原始视频素材(MP4、MOV、AVI、WebM,最大 500MB)。 - 自动化工作流:编辑、预览和导出 1080p MP4 视频,仅需 1-2 分钟。 - 集成云渲染,具有 GPU 加速和直观的会话/令牌管理。 - 用户请求到动作的清晰映射(编辑、导出、上传、检查信用/状态)。 - 有用的错误处理、使用提示和简化的入门流程,支持免费匿名令牌。
● 可疑
安装命令
点击复制官方npx clawhub@latest install editor-ai-best
镜像加速npx clawhub@latest install editor-ai-best --registry https://cn.longxiaskill.com
技能文档
分享您的原始视频素材,我将开始 AI 驱动的视频编辑。或者,只需告诉我您在想什么。 尝试说:
- "编辑我的原始视频素材"
- "导出 1080p MP4"
- "剪去无趣的部分,添加过渡..."
... (中间部分与原文相同,仅示例开始) ...