Low Risk — Risk Score 10/100
Last scan:18 hr ago Rescan
10 /100
nemo-generate
AI Video Generator: Text to Video, Create Video from Text
Legitimate AI video generation skill with well-documented shell commands, network calls, and file operations. No hidden functionality or suspicious patterns detected.
Skill Namenemo-generate
Duration30.8s
Enginepi
Safe to install
Approve for use. All capabilities are documented and necessary for video generation functionality. Monitor external API calls to nemovideo.ai as a standard precaution.
ResourceDeclaredInferredStatusEvidence
Filesystem WRITE WRITE ✓ Aligned SKILL.md:59-65 - mkdir/mkdir, cat for ~/.config/nemovideo/client_id
Network READ READ ✓ Aligned SKILL.md:123-140 - curl GET/POST to mega-api-prod.nemovideo.ai
Shell WRITE WRITE ✓ Aligned SKILL.md:59-65 - explicit bash commands documented
Environment READ READ ✓ Aligned SKILL.md:27-34 - NEMO_TOKEN, NEMO_API_URL, NEMO_CLIENT_ID documented
Skill Invoke NONE NONE No skill_invoke declarations found
Clipboard NONE NONE No clipboard access documented
Browser NONE NONE No browser access documented
Database NONE NONE No database access documented
12 findings
🔗
Medium External URL 外部 URL
https://nemovideo.com
SKILL.md:22
🔗
Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai
SKILL.md:23
🔗
Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/auth/anonymous-token
SKILL.md:50
🔗
Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/tasks/me/with-session/nemo_agent
SKILL.md:123
🔗
Medium External URL 外部 URL
https://dev.nemovideo.ai
SKILL.md:130
🔗
Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai/run_sse
SKILL.md:135
🔗
Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/upload-video/nemo_agent/
SKILL.md:187
🔗
Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/credits/balance/simple
SKILL.md:203
🔗
Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/state/nemo_agent/
SKILL.md:215
🔗
Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/render/proxy/lambda
SKILL.md:238
🔗
Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/render/proxy/lambda/
SKILL.md:247
🔗
Medium External URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/render/proxy/
SKILL.md:253

File Tree

1 files · 13.7 KB · 343 lines
Markdown 1f · 343L
└─ 📝 SKILL.md Markdown 343L · 13.7 KB

Security Positives

✓ All shell commands explicitly documented in SKILL.md with clear, legitimate purpose
✓ All network endpoints declared and necessary for video generation service
✓ No base64 encoding, obfuscation, or anti-analysis patterns found
✓ No credential harvesting beyond necessary API tokens
✓ No sensitive paths (~/.ssh, ~/.aws, .env) accessed
✓ No remote script execution (curl|bash or wget|sh patterns)
✓ File operations limited to dedicated config directory ~/.config/nemovideo/
✓ Documentation accurately reflects all implemented functionality
✓ Single-file skill with no external dependencies or supply chain risks