Scan Report
10 /100
nemo-generate
AI Video Generator: Text to Video, Create Video from Text
Legitimate AI video generation skill with well-documented shell commands, network calls, and file operations. No hidden functionality or suspicious patterns detected.
Safe to install
Approve for use. All capabilities are documented and necessary for video generation functionality. Monitor external API calls to nemovideo.ai as a standard precaution.
| Resource | Declared | Inferred | Status | Evidence |
|---|---|---|---|---|
| Filesystem | WRITE | WRITE | ✓ Aligned | SKILL.md:59-65 - mkdir/mkdir, cat for ~/.config/nemovideo/client_id |
| Network | READ | READ | ✓ Aligned | SKILL.md:123-140 - curl GET/POST to mega-api-prod.nemovideo.ai |
| Shell | WRITE | WRITE | ✓ Aligned | SKILL.md:59-65 - explicit bash commands documented |
| Environment | READ | READ | ✓ Aligned | SKILL.md:27-34 - NEMO_TOKEN, NEMO_API_URL, NEMO_CLIENT_ID documented |
| Skill Invoke | NONE | NONE | — | No skill_invoke declarations found |
| Clipboard | NONE | NONE | — | No clipboard access documented |
| Browser | NONE | NONE | — | No browser access documented |
| Database | NONE | NONE | — | No database access documented |
12 findings
Medium External URL 外部 URL
https://nemovideo.com SKILL.md:22 Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai SKILL.md:23 Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/auth/anonymous-token SKILL.md:50 Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/tasks/me/with-session/nemo_agent SKILL.md:123 Medium External URL 外部 URL
https://dev.nemovideo.ai SKILL.md:130 Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai/run_sse SKILL.md:135 Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/upload-video/nemo_agent/ SKILL.md:187 Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/credits/balance/simple SKILL.md:203 Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/state/nemo_agent/ SKILL.md:215 Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/render/proxy/lambda SKILL.md:238 Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/render/proxy/lambda/ SKILL.md:247 Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/render/proxy/ SKILL.md:253 File Tree
1 files · 13.7 KB · 343 lines Markdown 1f · 343L
└─
SKILL.md
Markdown
Security Positives
✓ All shell commands explicitly documented in SKILL.md with clear, legitimate purpose
✓ All network endpoints declared and necessary for video generation service
✓ No base64 encoding, obfuscation, or anti-analysis patterns found
✓ No credential harvesting beyond necessary API tokens
✓ No sensitive paths (~/.ssh, ~/.aws, .env) accessed
✓ No remote script execution (curl|bash or wget|sh patterns)
✓ File operations limited to dedicated config directory ~/.config/nemovideo/
✓ Documentation accurately reflects all implemented functionality
✓ Single-file skill with no external dependencies or supply chain risks