扫描报告
10 /100
nemo-generate
AI Video Generator: Text to Video, Create Video from Text
Legitimate AI video generation skill with well-documented shell commands, network calls, and file operations. No hidden functionality or suspicious patterns detected.
可以安装
Approve for use. All capabilities are documented and necessary for video generation functionality. Monitor external API calls to nemovideo.ai as a standard precaution.
| 资源类型 | 声明权限 | 推断权限 | 状态 | 证据 |
|---|---|---|---|---|
| 文件系统 | WRITE | WRITE | ✓ 一致 | SKILL.md:59-65 - mkdir/mkdir, cat for ~/.config/nemovideo/client_id |
| 网络访问 | READ | READ | ✓ 一致 | SKILL.md:123-140 - curl GET/POST to mega-api-prod.nemovideo.ai |
| 命令执行 | WRITE | WRITE | ✓ 一致 | SKILL.md:59-65 - explicit bash commands documented |
| 环境变量 | READ | READ | ✓ 一致 | SKILL.md:27-34 - NEMO_TOKEN, NEMO_API_URL, NEMO_CLIENT_ID documented |
| 技能调用 | NONE | NONE | — | No skill_invoke declarations found |
| 剪贴板 | NONE | NONE | — | No clipboard access documented |
| 浏览器 | NONE | NONE | — | No browser access documented |
| 数据库 | NONE | NONE | — | No database access documented |
12 项发现
中危 外部 URL 外部 URL
https://nemovideo.com SKILL.md:22 中危 外部 URL 外部 URL
https://mega-api-prod.nemovideo.ai SKILL.md:23 中危 外部 URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/auth/anonymous-token SKILL.md:50 中危 外部 URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/tasks/me/with-session/nemo_agent SKILL.md:123 中危 外部 URL 外部 URL
https://dev.nemovideo.ai SKILL.md:130 中危 外部 URL 外部 URL
https://mega-api-prod.nemovideo.ai/run_sse SKILL.md:135 中危 外部 URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/upload-video/nemo_agent/ SKILL.md:187 中危 外部 URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/credits/balance/simple SKILL.md:203 中危 外部 URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/state/nemo_agent/ SKILL.md:215 中危 外部 URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/render/proxy/lambda SKILL.md:238 中危 外部 URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/render/proxy/lambda/ SKILL.md:247 中危 外部 URL 外部 URL
https://mega-api-prod.nemovideo.ai/api/render/proxy/ SKILL.md:253 目录结构
1 文件 · 13.7 KB · 343 行 Markdown 1f · 343L
└─
SKILL.md
Markdown
安全亮点
✓ All shell commands explicitly documented in SKILL.md with clear, legitimate purpose
✓ All network endpoints declared and necessary for video generation service
✓ No base64 encoding, obfuscation, or anti-analysis patterns found
✓ No credential harvesting beyond necessary API tokens
✓ No sensitive paths (~/.ssh, ~/.aws, .env) accessed
✓ No remote script execution (curl|bash or wget|sh patterns)
✓ File operations limited to dedicated config directory ~/.config/nemovideo/
✓ Documentation accurately reflects all implemented functionality
✓ Single-file skill with no external dependencies or supply chain risks