← 返回 Skills 市场
dsewell-583h0

Text To Video By Canva

作者 dsewell-583h0 · GitHub ↗ · v1.0.0 · MIT-0
cross-platform ⚠ suspicious
72
总下载
0
收藏
0
当前安装
1
版本数
在 OpenClaw 中安装
/install text-to-video-by-canva
功能描述
Get text-based videos ready to post, without touching a single slider. Upload your text prompts (TXT, DOCX, PDF, copied text, up to 200MB), say something lik...
安全使用建议
This skill will send your text and any uploaded files to a third-party backend (mega-api-prod.nemovideo.ai). Before installing: 1) Verify the publisher/source — the skill claims 'By Canva' but the API host is 'nemovideo.ai' and no homepage/source is provided. 2) Do not upload sensitive or private files unless you trust the service and its privacy terms. 3) Prefer creating a scoped, low-privilege NEMO_TOKEN (or review what the anonymous token grants) rather than supplying a long-lived credential. 4) Ask the publisher why the registry lists NEMO_TOKEN as required when the SKILL.md describes creating an anonymous token and why a config path (~/.config/nemovideo/) appears in metadata. 5) Consider refusing installation if provenance cannot be confirmed or if you cannot accept that the agent will transmit files and environment/installation metadata to the nemovideo.ai service.
功能分析
Type: OpenClaw Skill Name: text-to-video-by-canva Version: 1.0.0 The skill exhibits misleading branding by claiming to be an official Canva tool ('text-to-video-by-canva') while routing all data and API calls to an unrelated third-party domain (nemovideo.ai). While the instructions in SKILL.md are technically consistent with the stated purpose of AI video generation, the use of brand impersonation is a significant indicator of potential deception. It also instructs the agent to automatically generate and manage tokens from an external backend (mega-api-prod.nemovideo.ai) without clear affiliation to the impersonated brand.
能力评估
Purpose & Capability
The skill is named 'Text To Video By Canva' but all runtime endpoints point to mega-api-prod.nemovideo.ai and there is no homepage or source provenance. The declared primary credential (NEMO_TOKEN) is consistent with the API, but the mismatch between the Canva branding and the actual API host plus missing publisher information is a red flag for origin/legitimacy. The SKILL.md metadata also lists a config path (~/.config/nemovideo/) even though the registry shows 'required config paths: none' — this inconsistency suggests sloppy or conflicting configuration.
Instruction Scope
Instructions will upload user-provided files (multipart upload or URL) and create sessions/tokens on a third-party backend; they instruct the agent to check NEMO_TOKEN and, if missing, obtain an anonymous token via an API call. The skill also specifies headers derived from the agent's install path (X-Skill-Platform), which could reveal environment/installation details. Overall the actions are consistent with a cloud-render service, but the instructions permit automatic token creation and reference local config paths — both broaden the agent's runtime behavior beyond a simple conversion tool.
Install Mechanism
No install specification or code files are present; this is instruction-only, which reduces disk-write risk. There is no download/extract/install of third-party binaries described.
Credentials
Only one environment variable (NEMO_TOKEN) is declared, which is appropriate for an API-backed service. However the SKILL.md states that if NEMO_TOKEN is missing the agent should obtain an 'anonymous' token by calling the API — yet the registry listed NEMO_TOKEN as required. That conflict (required vs optional) is incoherent. The metadata's config path (~/.config/nemovideo/) is also present in the SKILL.md, which could result in reading local configuration/config files not declared in the registry. The skill also requires inclusion of attribution headers that may leak install-path-derived info.
Persistence & Privilege
The skill is not set to always:true and uses default autonomous invocation settings (normal). There is no install-time persistent agent modification described. However, the skill's header rules (X-Skill-Platform derived from install path) could cause the agent to expose its installation path; this is a privacy consideration rather than a privilege escalation.
如何使用
  1. 确保已安装 OpenClaw(本地或 Docker 部署)
  2. 在对话框中输入安装命令:/install text-to-video-by-canva
  3. 安装完成后,直接呼叫该 Skill 的名称或使用 /text-to-video-by-canva 触发
  4. 根据 Skill 的参数说明提供必要输入,即可获得结构化输出
版本历史
v1.0.0
- Initial release of Text to Video by Canva, enabling users to convert text prompts (TXT, DOCX, PDF, or copied text, up to 200MB) into shareable 1080p MP4 videos with visuals and music. - Automated setup process checks for environment tokens, creates sessions, and connects to the cloud backend with up to 100 free credits. - Supports file upload, text prompt processing, video preview, export, and credit/status checking via clear API-driven actions. - Integrated error handling and simple workflows for fast video generation without any filming or editing experience required. - Optimized for marketers needing quick, post-ready social videos from their written content.
元数据
Slug text-to-video-by-canva
版本 1.0.0
许可证 MIT-0
累计安装 0
当前安装数 0
历史版本数 1
常见问题

Text To Video By Canva 是什么?

Get text-based videos ready to post, without touching a single slider. Upload your text prompts (TXT, DOCX, PDF, copied text, up to 200MB), say something lik... 它是一个面向 Claude Code / OpenClaw 的 AI Agent Skill 插件,目前累计下载 72 次。

如何安装 Text To Video By Canva?

在 OpenClaw 或 Claude Code 对话框中运行命令「/install text-to-video-by-canva」即可一键安装,无需额外配置。

Text To Video By Canva 是免费的吗?

是的,Text To Video By Canva 完全免费,采用 MIT-0 许可证,可自由下载、安装和使用。

Text To Video By Canva 支持哪些平台?

Text To Video By Canva 跨平台运行,可在任意部署了 OpenClaw / Claude Code 的环境中使用(cross-platform)。

谁开发了 Text To Video By Canva?

由 dsewell-583h0(@dsewell-583h0)开发并维护,当前版本 v1.0.0。

💬 留言讨论