agentCLAWHUBUnverified

mediaproc

Process media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. Use when the user wants to transcode video, process audio, manipulate images, or work with media files.

OpenClaw

Rank

62

Safety

84

Downloads

3.2k

Updated

Oct 9, 2026

Version

2.0.12

Source

CLAWHUB

About

What it does, and when to use it.

Capability contract not published. No trust telemetry is available yet. 3.2K downloads reported by the source. Last updated 10/9/2026.

Avoid when

  • Contract metadata is missing or unavailable for deterministic execution.

Risk flags: missing_or_unavailable_contract, trust_data_unavailable, schema_references_missing

Public facts

Every fact links back to the source it came from.

Vendor
Clawhubvendor · observed Oct 9, 2026
Protocol compatibility
OpenClawcompatibility · observed Oct 9, 2026
Adoption signal
3.2K downloadsadoption · observed Oct 9, 2026
Latest release
2.0.12release · observed Aug 1, 2026
Handshake status
UNKNOWNsecurity

Install and run

Setup complexity: low.

clawhub skill install s17fq93tmpky791n7516jcn08n83sfn2:mediaproc
  1. Install using `clawhub skill install s17fq93tmpky791n7516jcn08n83sfn2:mediaproc` in an isolated environment before connecting it to live workloads.
  2. No published capability contract is available yet, so validate auth and request/response behavior manually.
  3. Review the upstream CLAWHUB listing at https://clawhub.ai/psyb0t/mediaproc before using production credentials.

Contract: missing

curl -s "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-mediaproc/snapshot"

Documentation

CLAWHUB

133,394 characters of source documentation, loaded on request.

Extracted files

4 files captured from the source.

SKILL.md

---
name: mediaproc
description: Process media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. Use when the user wants to transcode video, process audio, manipulate images, or work with media files.
compatibility: Requires ssh and a running mediaproc instance. MEDIAPROC_HOST and MEDIAPROC_PORT env vars must be set.
metadata:
  author: psyb0t
  homepage: https://github.com/psyb0t/docker-mediaproc
---

# mediaproc

Locked-down media processing over SSH. Built on [lockbox](https://github.com/psyb0t/docker-lockbox) — no shell access, no injection, no bullshit.

For installation and deployment, see [references/setup.md](references/setup.md).

## Security model

mediaproc is **not** a general-purpose shell, and `scripts/mediaproc.sh` is **not**
arbitrary remote code execution even though it forwards a free-form-looking command
string. The instance runs inside a [lockbox](https://github.com/psyb0t/docker-lockbox)-
hardened container, and this skill only ever talks to an instance you (or your
operator) already run and trust:

- **Key-auth only** — SSH accepts public-key auth only (no passwords), connecting
  as a restricted user. There is no interactive shell and no PTY.
- **Server-side enforced allow-list, not documentation** — `scripts/mediaproc.sh`
  passes its argument through to the SSH channel as-is, but the *remote* lockbox
  dispatcher is what decides what runs, and it only ever executes the fixed set
  documented below: `ffmpeg`, `ffprobe`, `sox`, `soxi`, `convert`, `identify`,
  `magick`, plus lockbox's built-in, scoped file operations. This is an enforced
  allow-list on the server, not a client-side convention — the wrapper cannot be
  used to run anything outside that set. Any other command name is refused before
  execution; the remote never spawns a shell, so there is no shell-injection
  surface and no way to chain (`;`, `|`, `&&`, backticks, etc.) into a second
  command.
- **Work-dir confined** — every path resolves under the instance work directory
  (`/work`); traversal is blocked. The sandbox cannot read or write your host
  filesystem.
- **Consumer-only** — this skill moves files to/from a running instance and runs
  the whitelisted media tools on them. It never provisions, escalates, or installs
  anything on your machine (server setup is a separate, operator-side step — see
  setup.md).
- **You must still trust the configured host** — `MEDIAPROC_HOST`/`MEDIAPROC_PORT`
  point at a specific instance. The allow-list constrains *what* runs, not *where*;
  if `MEDIAPROC_HOST` is pointed at an instance you don't control, that operator
  still sees every file you `put`/`get` and every command you send. Only point
  this skill at a mediaproc instance you or a trusted operator run.

## SSH Wrapper

Use `scripts/mediaproc.sh` for all commands. It handles host, port, and host key acceptance via `MEDIAPROC_HOST` and `MEDIAPROC_PORT` env vars.

The `<command>` argument looks free-form but is not

_meta.json

{
  "ownerId": "kn79dhvmpjng4rp2jjk8k0v5xx80ccbk",
  "slug": "mediaproc",
  "version": "2.0.12",
  "publishedAt": 1785616167655
}

references/setup.md

# mediaproc setup

## Quick Install

The installer creates `~/.mediaproc/` (docker-compose, authorized_keys, work
directory) and drops a `mediaproc` command into `/usr/local/bin`. The container
it stands up is a [lockbox](https://github.com/psyb0t/docker-lockbox)-hardened
SSH sandbox (key-auth, whitelisted commands only — see the Security model in
SKILL.md).

Because the installer runs as **root**, pin it to a released tag and read it
before running — don't pipe a mutable `main` branch straight into a root shell:

```bash
# Pick a released tag: https://github.com/psyb0t/docker-mediaproc/releases
REF=vX.Y.Z
curl -fsSL "https://raw.githubusercontent.com/psyb0t/docker-mediaproc/${REF}/install.sh" -o install.sh
less install.sh            # review exactly what runs as root
sudo bash install.sh
```

## Starting

```bash
# Add your SSH key
cat ~/.ssh/id_rsa.pub >> ~/.mediaproc/authorized_keys

# Basic start (detached)
mediaproc start -d

# With resource limits
mediaproc start -d -c 4 -r 4g -s 2g

# Custom port
mediaproc start -d -p 2223

# Custom fonts directory
mediaproc start -d -f /path/to/fonts
```

All flags persist to `~/.mediaproc/.env` — next `start` reuses the last values.

## Management

```bash
mediaproc stop                # stop
mediaproc upgrade             # pull latest image, asks to stop/restart
mediaproc uninstall           # stop and remove everything
mediaproc status              # show status
mediaproc logs                # show container logs
```

## Configuration

| Flag | Env var            | Default    | Description           |
| ---- | ------------------ | ---------- | --------------------- |
| `-p` | `MEDIAPROC_PORT`   | `2222`     | SSH port              |
| `-f` | `MEDIAPROC_FONTS_DIR` | `./fonts` | Custom fonts directory |
| `-c` | `MEDIAPROC_CPUS`   | `0`        | CPU limit (0 = unlimited) |
| `-r` | `MEDIAPROC_MEMORY` | `0`        | RAM limit (0 = unlimited) |
| `-s` | `MEDIAPROC_SWAP`   | `0`        | Swap limit (0 = no swap)  |

The skill's client side (`scripts/mediaproc.sh`) connects using `MEDIAPROC_HOST` /
`MEDIAPROC_PORT`, pointing at an instance set up as above. The server-side
allow-list constrains which commands run, but not who you're trusting — only
point `MEDIAPROC_HOST` at a mediaproc instance you or a trusted operator control;
whoever runs that instance can see every file transferred through it.

`MEDIAPROC_HOST` is read from the environment at call time with no validation
beyond "does SSH connect" — treat it like any other trusted config value, not
untrusted runtime input. Provision it the same way you'd provision a secret or
a connection string (your shell profile, an env file under your control, your
deployment config), not from a value an untrusted caller can set. If something
else can inject `MEDIAPROC_HOST` into the environment the skill runs in, it can
redirect every `put`/`get` and command to a host of its choosing.

skill-card.md

## Description:

Process media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick.

This skill is ready for commercial/non-commercial use.

## Publisher:

[psyb0t](https://clawhub.ai/user/psyb0t)

### License/Terms of Use:

MIT-0

## Use Case:

Developers and media-processing operators use this skill to upload media to a trusted mediaproc SSH instance, run allow-listed video, audio, image, and file operations, and retrieve processed outputs.

### Deployment Geography for Use:

Global

## Known Risks and Mitigations:

Risk: A remotely downloaded installer runs with root privileges during setup.

Mitigation: Pin the installer to a released tag or commit, inspect it before execution, and prefer checksum or signature verification before running it with sudo.

Risk: Media files and commands are visible to the operator of the configured MEDIAPROC_HOST.

Mitigation: Use only a mediaproc instance you control or fully trust, and avoid processing sensitive media on untrusted hosts.

Risk: The SSH wrapper accepts new host keys automatically on first connection.

Mitigation: Verify the SSH host key before processing sensitive media or connecting in higher-risk environments.

Risk: Destructive file operations can permanently delete data in the remote work directory.

Mitigation: Require explicit confirmation of exact remote paths before remove-file, remove-dir, or remove-dir-recursive commands.

## Reference(s):

- [mediaproc setup](references/setup.md)
- [docker-mediaproc](https://github.com/psyb0t/docker-mediaproc)
- [docker-lockbox](https://github.com/psyb0t/docker-lockbox)
- [docker-mediaproc releases](https://github.com/psyb0t/docker-mediaproc/releases)

## Skill Output:

**Output Type(s):** [Markdown, Shell commands, Configuration, Guidance]

**Output Format:** [Markdown with inline shell commands and command examples]

**Output Parameters:** [1D]

**Other Properties Related to Output:** [Commands require ssh plus MEDIAPROC_HOST and MEDIAPROC_PORT pointing to a trusted running mediaproc instance.]

## Skill Version(s):

2.0.12 (source: ClawHub release metadata)

## Ethical Considerations:

Users should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.
Github ReposUpdated 4h agoRank 70

AionUi

Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!

MCPOPENCLAW
Github ReposUpdated 6mo agoRank 70

activepieces

AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents

OPENCLAW
Github ReposUpdated 6mo agoRank 70

cherry-studio

AI productivity studio with smart chat, autonomous agents, and 300+ assistants.

MCPOPENCLAW
Github ReposUpdated 7mo agoRank 70

CopilotKit

The Frontend for Agents & Generative UI. React + Angular

OPENCLAW

Machine-readable data

The same record, as JSON, for agents and crawlers.

{
  "facts": [
    {
      "factKey": "vendor",
      "category": "vendor",
      "label": "Vendor",
      "value": "Clawhub",
      "href": "https://clawhub.ai/psyb0t/skills/mediaproc",
      "sourceUrl": "https://clawhub.ai/psyb0t/skills/mediaproc",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T09:28:53.471Z",
      "isPublic": true
    },
    {
      "factKey": "protocols",
      "category": "compatibility",
      "label": "Protocol compatibility",
      "value": "OpenClaw",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-mediaproc/contract",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-mediaproc/contract",
      "sourceType": "contract",
      "confidence": "medium",
      "observedAt": "2026-10-09T09:28:53.471Z",
      "isPublic": true
    },
    {
      "factKey": "traction",
      "category": "adoption",
      "label": "Adoption signal",
      "value": "3.2K downloads",
      "href": "https://clawhub.ai/psyb0t/mediaproc",
      "sourceUrl": "https://clawhub.ai/psyb0t/mediaproc",
      "sourceType": "profile",
      "confidence": "medium",
      "observedAt": "2026-10-09T09:28:53.471Z",
      "isPublic": true
    },
    {
      "factKey": "latest_release",
      "category": "release",
      "label": "Latest release",
      "value": "2.0.12",
      "href": "https://clawhub.ai/psyb0t/mediaproc",
      "sourceUrl": "https://clawhub.ai/psyb0t/mediaproc",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-08-01T20:29:27.655Z",
      "isPublic": true
    },
    {
      "factKey": "handshake_status",
      "category": "security",
      "label": "Handshake status",
      "value": "UNKNOWN",
      "href": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-mediaproc/trust",
      "sourceUrl": "https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-mediaproc/trust",
      "sourceType": "trust",
      "confidence": "medium",
      "observedAt": null,
      "isPublic": true
    }
  ],
  "events": [
    {
      "eventType": "release",
      "title": "Release 2.0.12",
      "description": "- Removed the skill-card.md file. - No changes to functionality or documentation content.",
      "href": "https://clawhub.ai/psyb0t/mediaproc",
      "sourceUrl": "https://clawhub.ai/psyb0t/mediaproc",
      "sourceType": "release",
      "confidence": "medium",
      "observedAt": "2026-08-01T20:29:27.655Z",
      "isPublic": true
    }
  ]
}

Record generated Oct 9, 2026.

Sponsored

Ads related to mediaproc and adjacent AI workflows.