{"id":"2d45bcc5-f5fb-47ee-8032-827c19c6f0cd","entityType":"agent","slug":"clawhub-jlacroix82-clip-media","name":"Clip Media","canonicalUrl":"https://www.xpersona.co/agent/clawhub-jlacroix82-clip-media","canonicalPath":"/agent/clawhub-jlacroix82-clip-media","generatedAt":"2026-10-10T06:44:45.582Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"editorial-content","verified":true,"confidence":"high","updatedAt":"2026-10-09T23:52:27.504Z","emptyReason":null},"description":"Extract media (videos, photos, GIFs, audio) from social media URLs using yt-dlp. Supports 1,872+ platforms including YouTube, TikTok, Instagram, X/Twitter, F... Skill: Clip Media Owner: jlacroix82 Summary: Extract media (videos, photos, GIFs, audio) from social media URLs using yt-dlp. Supports 1,872+ platforms including YouTube, TikTok, Instagram, X/Twitter, F... Tags: latest:0.3.5 Version history: v0.3.5 | 2026-07-22T16:26:47.646Z | user Security: external URL fetch warnings, input validation notes v0.3.4 | 2026-07-22T16:04:54.784Z | user Security improvements: clarified d","descriptionLabel":"Technical summary","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 1.9K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s175p518b8g47fx6r9zyvs95ks876t4t:clip-media","sourceUrl":"https://clawhub.ai/jlacroix82/clip-media","homepage":"https://clawhub.ai/jlacroix82/skills/clip-media","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/jlacroix82/clip-media","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/jlacroix82/skills/clip-media","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":65,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"Extract media (videos, photos, GIFs, audio) from social media URLs using yt-dlp. Supports 1,872+ platforms including YouTube, TikTok, Instagram, X/Twitter, F..."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T23:52:27.504Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T23:52:27.504Z","emptyReason":null},"stars":null,"forks":null,"downloads":1867,"packageName":null,"latestVersion":"0.3.5","tractionLabel":"1.9K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T23:52:27.504Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T23:52:27.504Z","lastCrawledAt":"2026-10-09T23:52:27.504Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T23:52:27.504Z","lastVerifiedAt":null,"highlights":[{"version":"0.3.5","createdAt":"2026-07-22T16:26:47.646Z","changelog":"Security: external URL fetch warnings, input validation notes","fileCount":5,"zipByteSize":11638},{"version":"0.3.4","createdAt":"2026-07-22T16:04:54.784Z","changelog":"Security improvements: clarified data storage warnings, updated security documentation, fixed descriptions to match actual behavior.","fileCount":6,"zipByteSize":11863},{"version":"0.3.3","createdAt":"2026-07-21T18:52:09.937Z","changelog":"- Updated command paths and examples to use the simplified path format (e.g., node skills/clip/extract.js). - Removed the file skill-card.md. - No changes to core extraction or upload logic. - No changes to supported options or platform compatibility.","fileCount":5,"zipByteSize":11491},{"version":"0.3.2","createdAt":"2026-07-20T01:57:46.766Z","changelog":"Clean security scan (0 findings). Added clawhub.yaml for publish tracking.","fileCount":5,"zipByteSize":11602},{"version":"0.3.1","createdAt":"2026-06-12T19:57:58.807Z","changelog":"Security fix: require --confirm-upload flag for any public cloud upload (tmpfiles.org, transfer.sh). Without the flag, large files are saved locally only with a clear block message.","fileCount":4,"zipByteSize":11146},{"version":"0.1.1","createdAt":"2026-06-12T15:24:57.110Z","changelog":"Bug fix: removed dead ytDlpOpts variable with double-quoted URL that would break on URLs with spaces","fileCount":4,"zipByteSize":10985},{"version":"0.3.0","createdAt":"2026-06-05T03:02:07.648Z","changelog":"Critical: Fixed command injection — switched execSync to execFileSync with proper array args so user-controlled URLs can no longer be injected into shell commands. Added --no-upload flag to skip cloud upload entirely. Updated pre-upload warnings to appear before any transfer.","fileCount":4,"zipByteSize":10905},{"version":"0.2.0","createdAt":"2026-06-04T19:02:28.387Z","changelog":"Security audit fixes: (1) Eliminated command injection — all execSync calls now use array args with shell:false, no more URL interpolation. (2) Added explicit public-host warnings when uploading files >50MB. (3) Removed unsafe --cookies-from-browser suggestion from error messages.","fileCount":4,"zipByteSize":10833}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s175p518b8g47fx6r9zyvs95ks876t4t:clip-media","setupComplexity":"low","setupSteps":["Setup complexity is classified as HIGH. You must provision dedicated cloud infrastructure or an isolated VM. Do not run this directly on your local workstation.","Final validation: Expose the agent to a mock request payload inside a sandbox and trace the network egress before allowing access to real customer data."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-clip-media/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-clip-media/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-clip-media/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-clip-media/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-clip-media/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-clip-media/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-10T06:44:45.579Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-clip-media/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-clip-media/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-clip-media/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-jlacroix82-clip-media/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"high","updatedAt":"2026-10-09T23:52:27.504Z","emptyReason":null},"readme":"Skill: Clip Media\n\nOwner: jlacroix82\n\nSummary: Extract media (videos, photos, GIFs, audio) from social media URLs using yt-dlp. Supports 1,872+ platforms including YouTube, TikTok, Instagram, X/Twitter, F...\n\nTags: latest:0.3.5\n\nVersion history:\n\nv0.3.5 | 2026-07-22T16:26:47.646Z | user\n\nSecurity: external URL fetch warnings, input validation notes\n\nv0.3.4 | 2026-07-22T16:04:54.784Z | user\n\nSecurity improvements: clarified data storage warnings, updated security documentation, fixed descriptions to match actual behavior.\n\nv0.3.3 | 2026-07-21T18:52:09.937Z | auto\n\n- Updated command paths and examples to use the simplified path format (e.g., node skills/clip/extract.js).\n- Removed the file skill-card.md.\n- No changes to core extraction or upload logic.\n- No changes to supported options or platform compatibility.\n\nv0.3.2 | 2026-07-20T01:57:46.766Z | user\n\nClean security scan (0 findings). Added clawhub.yaml for publish tracking.\n\nv0.3.1 | 2026-06-12T19:57:58.807Z | user\n\nSecurity fix: require --confirm-upload flag for any public cloud upload (tmpfiles.org, transfer.sh). Without the flag, large files are saved locally only with a clear block message.\n\nv0.1.1 | 2026-06-12T15:24:57.110Z | user\n\nBug fix: removed dead ytDlpOpts variable with double-quoted URL that would break on URLs with spaces\n\nv0.3.0 | 2026-06-05T03:02:07.648Z | user\n\nCritical: Fixed command injection — switched execSync to execFileSync with proper array args so user-controlled URLs can no longer be injected into shell commands. Added --no-upload flag to skip cloud upload entirely. Updated pre-upload warnings to appear before any transfer.\n\nv0.2.0 | 2026-06-04T19:02:28.387Z | user\n\nSecurity audit fixes: (1) Eliminated command injection — all execSync calls now use array args with shell:false, no more URL interpolation. (2) Added explicit public-host warnings when uploading files >50MB. (3) Removed unsafe --cookies-from-browser suggestion from error messages.\n\nv0.1.2 | 2026-06-04T03:32:50.048Z | user\n\nAdded prominent security warnings for public third-party uploads and browser cookie exposure. Clarified data handling risks.\n\nv0.1.0 | 2026-05-25T03:23:25.261Z | user\n\nInitial release\n\nArchive index:\n\nArchive v0.3.5: 5 files, 11638 bytes\n\nFiles: _meta.json (129b), clawhub.yaml (396b), extract.js (23046b), skill-card.md (2399b), SKILL.md (6009b)\n\nFile v0.3.5:SKILL.md\n\n---\nname: clip\ndescription: Extract media (videos, photos, GIFs, audio) from social media URLs using yt-dlp. Supports 1,872+ platforms. WARNING: files over 50 MB require --confirm-upload for public cloud upload. Browser cookie access exposes authentication material. Only use with non-sensitive content.\n---\n\n# Clip\n\n⚠️ **Security warnings before use:**\n- Files over 50 MB **require `--confirm-upload`** to upload to public third-party hosts (tmpfiles.org, transfer.sh)\n- Browser cookie access (`--cookies-from-browser`) exposes **active session tokens** for any platform you're logged into\n- **Never** use with private, paid, confidential, copyrighted, or regulated content unless you explicitly intend external transmission\n\n## How It Works\n\n1. User shares a URL from any supported platform\n2. Run the extraction script\n3. Script downloads the media (or just analyzes it)\n4. Returns the file path (under 50 MB) or a cloud link (over 50 MB)\n5. Agent sends the media to the user\n\n⚠️ **Before any extraction:** Confirm the content is not private, paid, or sensitive. Files over 50 MB are uploaded to public temp hosts — the script now shows a pre-upload warning and supports `--no-upload` to skip it entirely.\n\n## Command\n\n```bash\nnode skills/clip/extract.js <url> [options]\n```\n\n### Options\n\n| Flag | Description |\n|------|-------------|\n| `--output-dir <dir>` | Save location (default: `/tmp/media-share`) |\n| `--title` | Return title/description only, no download |\n| `--info` | Return full metadata as JSON |\n| `--test` | Validate URL without downloading |\n| `--upload` | Force cloud upload even for small files |\n| `--confirm-upload` | **Required for any public cloud upload** — explicit opt-in |\n| `--cloud=<provider>` | Cloud provider: `tmpfiles` or `transfer` |\n| `--no-direct-send` | Always return path, never auto-send |\n| `--no-upload` | **Skip cloud upload entirely** — always return local path |\n| `--list-sites` | Show supported platforms |\n| `--list-types` | Show what media a URL contains |\n\n### Examples\n\n```bash\n# Download media (fastest path)\nnode skills/clip/extract.js \"https://www.youtube.com/watch?v=dQw4w9WgXcQ\"\n\n# Get title only (no download, instant)\nnode skills/clip/extract.js \"https://www.instagram.com/p/abc123/\" --title\n\n# Check what's in a URL before downloading\nnode skills/clip/extract.js \"https://www.tiktok.com/@user/video/123\" --list-types\n\n# Show supported sites\nnode skills/clip/extract.js --list-sites\n```\n\n## Supported Platforms\n\n**yt-dlp: 1,872 extractors** — covers essentially every major media platform on the internet.\n\n### Quick reference (most common):\nYouTube, TikTok, Instagram, X/Twitter, Facebook, Reddit, Twitch, Vimeo, Dailymotion, Rumble, Peertube, Bilibili, Niconico, SoundCloud, Bandcamp, Pinterest, Imgur, Tumblr, Flickr, Bluesky, Telegram, Kick, Odysee, CNN, BBC, Al Jazeera, TED, Khan Academy, Udemy, Crunchyroll, HiDive, and 1,800+ more.\n\n## File Size Handling\n\n- **Under 50 MB** → Returns local file path (agent sends via chat)\n- **Over 50 MB** → Requires `--confirm-upload` to upload to temp cloud storage, returns download link\n- **Over 50 MB without `--confirm-upload`** → Returns local path only, blocks upload with clear message\n- **Over 50 MB + `--upload`** → Forces cloud upload even for smaller files (still requires `--confirm-upload`)\n\n### Cloud Providers\n\n⚠️ **Both providers are public and third-party.** Uploaded files are accessible to anyone with the link.\n\n| Provider | Max Size | Notes |\n|----------|----------|-------|\n| `tmpfiles` | 50 MB | Simple, no signup, auto-delete |\n| `transfer` | Unlimited | transfer.sh, 30-day retention |\n\n**Pre-upload warning:** Files over 50 MB require `--confirm-upload` for any public cloud upload. Without it, the script returns the local path only and blocks the upload with a clear message. Use `--no-upload` to always save locally without prompts.\n\n## Authentication\n\n⚠️ **Browser cookie access exposes active session tokens for every platform you're logged into.**\n\nSome platforms require cookies for full access:\n\n| Platform | Needs cookies? |\n|----------|---------------|\n| Instagram | Sometimes (private content, full resolution) |\n| X / Twitter | Sometimes (rate limits, some content) |\n| Patreon | Yes (paid content) |\n| OnlyFans | Yes |\n| Fanvue / Fansly | Yes |\n| Netflix / HBO / Disney+ | Via browser cookies |\n| YouTube | Rarely (age-restricted content) |\n\n**If cookies are needed:**\n- Use `--cookies-from-browser chrome` as a **last resort** — it exposes ALL platform session tokens in that browser\n- Warn the user that this could enable unauthorized account access if the machine is compromised\n- Prefer manual cookie paste or API keys when available\n- Never use `--cookies-from-browser` with paid/sensitive platforms unless the user explicitly consents to the risk\n- Consider exporting cookies from only the specific browser/profile needed, not the default one\n\n## How It Works (Under the Hood)\n\n1. **Analyze**: `yt-dlp --dump-json` detects the platform and media type\n2. **Download**: `yt-dlp -o <path>` grabs the highest quality version\n3. **Route**: Under 50 MB → return path. Over 50 MB → upload to cloud → return link\n4. **Fallback**: If download fails, returns title/description so the agent can inform the user\n\n## Dependencies\n\n- `yt-dlp` (installed) — 1,872 extractors\n- `ffmpeg` (installed) — format conversion\n- `curl` (installed) — cloud uploads\n\n## Error Handling\n\nWhen a URL returns no media, the script returns the title/description. The agent should:\n- Inform the user what was found\n- Suggest trying `--cookies-from-browser chrome` if the platform may require auth\n- Note that geo-blocked content cannot be bypassed\n\n## Notes\n\n- Rate limits may apply on some platforms — add delays between calls\n- Some platforms (Instagram, X) work better with cookies\n- If a URL returns no media, return the title/description to the user instead\n- The `generic` extractor handles many embedded video players not explicitly listed\n\nFile v0.3.5:_meta.json\n\n{\n  \"ownerId\": \"kn7b6eyf5vc7khg5fr63pjm8xd82qvw5\",\n  \"slug\": \"clip-media\",\n  \"version\": \"0.3.5\",\n  \"publishedAt\": 1784737607646\n}\n\nFile v0.3.5:skill-card.md\n\n## Description:\n\nExtract media such as videos, photos, GIFs, and audio from social media URLs using yt-dlp, returning local files, metadata, or an explicitly confirmed public upload link.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jlacroix82](https://clawhub.ai/user/jlacroix82)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agents use Clip Media to inspect or retrieve media from supported URLs and return metadata, local file paths, or temporary public links after explicit upload consent. It is intended for non-sensitive media where downloading and any external transmission are permitted.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Public upload paths can expose media through third-party temporary hosts and may not use the upload host the user selected.\n\nMitigation: Use --no-upload for sensitive files, require --confirm-upload for any public upload, and verify the actual returned host before sharing the link.\n\nRisk: Browser-wide cookie access can expose active authenticated sessions.\n\nMitigation: Avoid --cookies-from-browser unless the user explicitly accepts the risk; prefer non-sensitive public URLs or narrowly scoped manual credentials.\n\nRisk: Private, paid, copyrighted, regulated, or confidential media can create legal, privacy, or policy exposure if downloaded or transmitted.\n\nMitigation: Confirm the content is permitted for download and sharing before extraction, and keep regulated or confidential content local.\n\n## Reference(s):\n\n- [ClawHub Skill Page](https://clawhub.ai/jlacroix82/skills/clip-media)\n- [Publisher Profile](https://clawhub.ai/user/jlacroix82)\n\n## Skill Output:\n\n**Output Type(s):** [text, JSON, files, shell commands, guidance]\n\n**Output Format:** [Plain text, JSON metadata, local file paths, and temporary public URLs]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Downloads are saved locally by default; public uploads require explicit confirmation and may use third-party temporary hosts.]\n\n## Skill Version(s):\n\n0.3.5 (source: server release metadata and clawhub.yaml)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nFile v0.3.5:clawhub.yaml\n\nslug: clip-media\nname: Clip Media\nowner: jlacroix82\ndescription: Extract and download media from URLs using yt-dlp. ⚠️ Files over 50MB require explicit opt-in for public cloud upload. Browser cookie access exposes session tokens.\nversion: 0.3.5\ntype: skill\nauthor: OpenClaw\nlicense: MIT\nkeywords:\n  - media\n  - download\n  - yt-dlp\n  - video\n  - agent\nentry: SKILL.md\ndependencies:\n  - yt-dlp\n\nArchive v0.3.4: 6 files, 11863 bytes\n\nFiles: _meta.json (129b), .clawhub/origin.json (227b), clawhub.yaml (396b), extract.js (23046b), skill-card.md (2309b), SKILL.md (6009b)\n\nFile v0.3.4:SKILL.md\n\n---\nname: clip\ndescription: Extract media (videos, photos, GIFs, audio) from social media URLs using yt-dlp. Supports 1,872+ platforms. WARNING: files over 50 MB require --confirm-upload for public cloud upload. Browser cookie access exposes authentication material. Only use with non-sensitive content.\n---\n\n# Clip\n\n⚠️ **Security warnings before use:**\n- Files over 50 MB **require `--confirm-upload`** to upload to public third-party hosts (tmpfiles.org, transfer.sh)\n- Browser cookie access (`--cookies-from-browser`) exposes **active session tokens** for any platform you're logged into\n- **Never** use with private, paid, confidential, copyrighted, or regulated content unless you explicitly intend external transmission\n\n## How It Works\n\n1. User shares a URL from any supported platform\n2. Run the extraction script\n3. Script downloads the media (or just analyzes it)\n4. Returns the file path (under 50 MB) or a cloud link (over 50 MB)\n5. Agent sends the media to the user\n\n⚠️ **Before any extraction:** Confirm the content is not private, paid, or sensitive. Files over 50 MB are uploaded to public temp hosts — the script now shows a pre-upload warning and supports `--no-upload` to skip it entirely.\n\n## Command\n\n```bash\nnode skills/clip/extract.js <url> [options]\n```\n\n### Options\n\n| Flag | Description |\n|------|-------------|\n| `--output-dir <dir>` | Save location (default: `/tmp/media-share`) |\n| `--title` | Return title/description only, no download |\n| `--info` | Return full metadata as JSON |\n| `--test` | Validate URL without downloading |\n| `--upload` | Force cloud upload even for small files |\n| `--confirm-upload` | **Required for any public cloud upload** — explicit opt-in |\n| `--cloud=<provider>` | Cloud provider: `tmpfiles` or `transfer` |\n| `--no-direct-send` | Always return path, never auto-send |\n| `--no-upload` | **Skip cloud upload entirely** — always return local path |\n| `--list-sites` | Show supported platforms |\n| `--list-types` | Show what media a URL contains |\n\n### Examples\n\n```bash\n# Download media (fastest path)\nnode skills/clip/extract.js \"https://www.youtube.com/watch?v=dQw4w9WgXcQ\"\n\n# Get title only (no download, instant)\nnode skills/clip/extract.js \"https://www.instagram.com/p/abc123/\" --title\n\n# Check what's in a URL before downloading\nnode skills/clip/extract.js \"https://www.tiktok.com/@user/video/123\" --list-types\n\n# Show supported sites\nnode skills/clip/extract.js --list-sites\n```\n\n## Supported Platforms\n\n**yt-dlp: 1,872 extractors** — covers essentially every major media platform on the internet.\n\n### Quick reference (most common):\nYouTube, TikTok, Instagram, X/Twitter, Facebook, Reddit, Twitch, Vimeo, Dailymotion, Rumble, Peertube, Bilibili, Niconico, SoundCloud, Bandcamp, Pinterest, Imgur, Tumblr, Flickr, Bluesky, Telegram, Kick, Odysee, CNN, BBC, Al Jazeera, TED, Khan Academy, Udemy, Crunchyroll, HiDive, and 1,800+ more.\n\n## File Size Handling\n\n- **Under 50 MB** → Returns local file path (agent sends via chat)\n- **Over 50 MB** → Requires `--confirm-upload` to upload to temp cloud storage, returns download link\n- **Over 50 MB without `--confirm-upload`** → Returns local path only, blocks upload with clear message\n- **Over 50 MB + `--upload`** → Forces cloud upload even for smaller files (still requires `--confirm-upload`)\n\n### Cloud Providers\n\n⚠️ **Both providers are public and third-party.** Uploaded files are accessible to anyone with the link.\n\n| Provider | Max Size | Notes |\n|----------|----------|-------|\n| `tmpfiles` | 50 MB | Simple, no signup, auto-delete |\n| `transfer` | Unlimited | transfer.sh, 30-day retention |\n\n**Pre-upload warning:** Files over 50 MB require `--confirm-upload` for any public cloud upload. Without it, the script returns the local path only and blocks the upload with a clear message. Use `--no-upload` to always save locally without prompts.\n\n## Authentication\n\n⚠️ **Browser cookie access exposes active session tokens for every platform you're logged into.**\n\nSome platforms require cookies for full access:\n\n| Platform | Needs cookies? |\n|----------|---------------|\n| Instagram | Sometimes (private content, full resolution) |\n| X / Twitter | Sometimes (rate limits, some content) |\n| Patreon | Yes (paid content) |\n| OnlyFans | Yes |\n| Fanvue / Fansly | Yes |\n| Netflix / HBO / Disney+ | Via browser cookies |\n| YouTube | Rarely (age-restricted content) |\n\n**If cookies are needed:**\n- Use `--cookies-from-browser chrome` as a **last resort** — it exposes ALL platform session tokens in that browser\n- Warn the user that this could enable unauthorized account access if the machine is compromised\n- Prefer manual cookie paste or API keys when available\n- Never use `--cookies-from-browser` with paid/sensitive platforms unless the user explicitly consents to the risk\n- Consider exporting cookies from only the specific browser/profile needed, not the default one\n\n## How It Works (Under the Hood)\n\n1. **Analyze**: `yt-dlp --dump-json` detects the platform and media type\n2. **Download**: `yt-dlp -o <path>` grabs the highest quality version\n3. **Route**: Under 50 MB → return path. Over 50 MB → upload to cloud → return link\n4. **Fallback**: If download fails, returns title/description so the agent can inform the user\n\n## Dependencies\n\n- `yt-dlp` (installed) — 1,872 extractors\n- `ffmpeg` (installed) — format conversion\n- `curl` (installed) — cloud uploads\n\n## Error Handling\n\nWhen a URL returns no media, the script returns the title/description. The agent should:\n- Inform the user what was found\n- Suggest trying `--cookies-from-browser chrome` if the platform may require auth\n- Note that geo-blocked content cannot be bypassed\n\n## Notes\n\n- Rate limits may apply on some platforms — add delays between calls\n- Some platforms (Instagram, X) work better with cookies\n- If a URL returns no media, return the title/description to the user instead\n- The `generic` extractor handles many embedded video players not explicitly listed\n\nFile v0.3.4:_meta.json\n\n{\n  \"ownerId\": \"kn7b6eyf5vc7khg5fr63pjm8xd82qvw5\",\n  \"slug\": \"clip-media\",\n  \"version\": \"0.3.4\",\n  \"publishedAt\": 1784736294784\n}\n\nFile v0.3.4:skill-card.md\n\n## Description: <br>\nClip Media helps agents analyze and extract videos, photos, GIFs, and audio from supported media URLs using yt-dlp. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jlacroix82](https://clawhub.ai/user/jlacroix82) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users and developers use this skill through an agent to inspect media URLs, download supported media to a local path, or return metadata and title information. Public upload links and browser-cookie access should be used only with explicit user consent and non-sensitive content. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Public upload links can expose downloaded media to anyone with the URL. <br>\nMitigation: Use local paths or --no-upload by default; use --confirm-upload only when the user explicitly accepts public third-party hosting. <br>\nRisk: Browser-cookie access can expose active session tokens. <br>\nMitigation: Avoid browser cookies unless the user deliberately accepts the session-token risk, and do not use them for private, paid, confidential, copyrighted, or regulated content. <br>\nRisk: Downloading media can involve private, paid, confidential, copyrighted, or regulated content. <br>\nMitigation: Confirm the content is appropriate to process before extraction and decline use cases that require unauthorized or sensitive access. <br>\n\n\n## Reference(s): <br>\n- [Clip Media on ClawHub](https://clawhub.ai/jlacroix82/skills/clip-media) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, json, files, shell commands, guidance] <br>\n**Output Format:** [Plain text, JSON metadata, local file paths, public download URLs, and shell command guidance] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Media downloads are saved locally by default; public cloud uploads require explicit confirmation.] <br>\n\n## Skill Version(s): <br>\n0.3.4 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v0.3.4:.clawhub/origin.json\n\n{\n  \"version\": 1,\n  \"registry\": \"https://clawhub.ai\",\n  \"slug\": \"clip-media\",\n  \"installedVersion\": \"0.3.1\",\n  \"installedAt\": 1779717617960,\n  \"fingerprint\": \"8b0e53b6586b7787149625f96a9831bbd74357e76491887869c947b37062b183\"\n}\n\nFile v0.3.4:clawhub.yaml\n\nslug: clip-media\nname: Clip Media\nowner: jlacroix82\ndescription: Extract and download media from URLs using yt-dlp. ⚠️ Files over 50MB require explicit opt-in for public cloud upload. Browser cookie access exposes session tokens.\nversion: 0.3.3\ntype: skill\nauthor: OpenClaw\nlicense: MIT\nkeywords:\n  - media\n  - download\n  - yt-dlp\n  - video\n  - agent\nentry: SKILL.md\ndependencies:\n  - yt-dlp\n\nArchive v0.3.3: 5 files, 11491 bytes\n\nFiles: _meta.json (129b), clawhub.yaml (306b), extract.js (23046b), skill-card.md (2315b), SKILL.md (6009b)\n\nFile v0.3.3:SKILL.md\n\n---\nname: clip\ndescription: Extract media (videos, photos, GIFs, audio) from social media URLs using yt-dlp. Supports 1,872+ platforms. WARNING: files over 50 MB require --confirm-upload for public cloud upload. Browser cookie access exposes authentication material. Only use with non-sensitive content.\n---\n\n# Clip\n\n⚠️ **Security warnings before use:**\n- Files over 50 MB **require `--confirm-upload`** to upload to public third-party hosts (tmpfiles.org, transfer.sh)\n- Browser cookie access (`--cookies-from-browser`) exposes **active session tokens** for any platform you're logged into\n- **Never** use with private, paid, confidential, copyrighted, or regulated content unless you explicitly intend external transmission\n\n## How It Works\n\n1. User shares a URL from any supported platform\n2. Run the extraction script\n3. Script downloads the media (or just analyzes it)\n4. Returns the file path (under 50 MB) or a cloud link (over 50 MB)\n5. Agent sends the media to the user\n\n⚠️ **Before any extraction:** Confirm the content is not private, paid, or sensitive. Files over 50 MB are uploaded to public temp hosts — the script now shows a pre-upload warning and supports `--no-upload` to skip it entirely.\n\n## Command\n\n```bash\nnode skills/clip/extract.js <url> [options]\n```\n\n### Options\n\n| Flag | Description |\n|------|-------------|\n| `--output-dir <dir>` | Save location (default: `/tmp/media-share`) |\n| `--title` | Return title/description only, no download |\n| `--info` | Return full metadata as JSON |\n| `--test` | Validate URL without downloading |\n| `--upload` | Force cloud upload even for small files |\n| `--confirm-upload` | **Required for any public cloud upload** — explicit opt-in |\n| `--cloud=<provider>` | Cloud provider: `tmpfiles` or `transfer` |\n| `--no-direct-send` | Always return path, never auto-send |\n| `--no-upload` | **Skip cloud upload entirely** — always return local path |\n| `--list-sites` | Show supported platforms |\n| `--list-types` | Show what media a URL contains |\n\n### Examples\n\n```bash\n# Download media (fastest path)\nnode skills/clip/extract.js \"https://www.youtube.com/watch?v=dQw4w9WgXcQ\"\n\n# Get title only (no download, instant)\nnode skills/clip/extract.js \"https://www.instagram.com/p/abc123/\" --title\n\n# Check what's in a URL before downloading\nnode skills/clip/extract.js \"https://www.tiktok.com/@user/video/123\" --list-types\n\n# Show supported sites\nnode skills/clip/extract.js --list-sites\n```\n\n## Supported Platforms\n\n**yt-dlp: 1,872 extractors** — covers essentially every major media platform on the internet.\n\n### Quick reference (most common):\nYouTube, TikTok, Instagram, X/Twitter, Facebook, Reddit, Twitch, Vimeo, Dailymotion, Rumble, Peertube, Bilibili, Niconico, SoundCloud, Bandcamp, Pinterest, Imgur, Tumblr, Flickr, Bluesky, Telegram, Kick, Odysee, CNN, BBC, Al Jazeera, TED, Khan Academy, Udemy, Crunchyroll, HiDive, and 1,800+ more.\n\n## File Size Handling\n\n- **Under 50 MB** → Returns local file path (agent sends via chat)\n- **Over 50 MB** → Requires `--confirm-upload` to upload to temp cloud storage, returns download link\n- **Over 50 MB without `--confirm-upload`** → Returns local path only, blocks upload with clear message\n- **Over 50 MB + `--upload`** → Forces cloud upload even for smaller files (still requires `--confirm-upload`)\n\n### Cloud Providers\n\n⚠️ **Both providers are public and third-party.** Uploaded files are accessible to anyone with the link.\n\n| Provider | Max Size | Notes |\n|----------|----------|-------|\n| `tmpfiles` | 50 MB | Simple, no signup, auto-delete |\n| `transfer` | Unlimited | transfer.sh, 30-day retention |\n\n**Pre-upload warning:** Files over 50 MB require `--confirm-upload` for any public cloud upload. Without it, the script returns the local path only and blocks the upload with a clear message. Use `--no-upload` to always save locally without prompts.\n\n## Authentication\n\n⚠️ **Browser cookie access exposes active session tokens for every platform you're logged into.**\n\nSome platforms require cookies for full access:\n\n| Platform | Needs cookies? |\n|----------|---------------|\n| Instagram | Sometimes (private content, full resolution) |\n| X / Twitter | Sometimes (rate limits, some content) |\n| Patreon | Yes (paid content) |\n| OnlyFans | Yes |\n| Fanvue / Fansly | Yes |\n| Netflix / HBO / Disney+ | Via browser cookies |\n| YouTube | Rarely (age-restricted content) |\n\n**If cookies are needed:**\n- Use `--cookies-from-browser chrome` as a **last resort** — it exposes ALL platform session tokens in that browser\n- Warn the user that this could enable unauthorized account access if the machine is compromised\n- Prefer manual cookie paste or API keys when available\n- Never use `--cookies-from-browser` with paid/sensitive platforms unless the user explicitly consents to the risk\n- Consider exporting cookies from only the specific browser/profile needed, not the default one\n\n## How It Works (Under the Hood)\n\n1. **Analyze**: `yt-dlp --dump-json` detects the platform and media type\n2. **Download**: `yt-dlp -o <path>` grabs the highest quality version\n3. **Route**: Under 50 MB → return path. Over 50 MB → upload to cloud → return link\n4. **Fallback**: If download fails, returns title/description so the agent can inform the user\n\n## Dependencies\n\n- `yt-dlp` (installed) — 1,872 extractors\n- `ffmpeg` (installed) — format conversion\n- `curl` (installed) — cloud uploads\n\n## Error Handling\n\nWhen a URL returns no media, the script returns the title/description. The agent should:\n- Inform the user what was found\n- Suggest trying `--cookies-from-browser chrome` if the platform may require auth\n- Note that geo-blocked content cannot be bypassed\n\n## Notes\n\n- Rate limits may apply on some platforms — add delays between calls\n- Some platforms (Instagram, X) work better with cookies\n- If a URL returns no media, return the title/description to the user instead\n- The `generic` extractor handles many embedded video players not explicitly listed\n\nFile v0.3.3:_meta.json\n\n{\n  \"ownerId\": \"kn7b6eyf5vc7khg5fr63pjm8xd82qvw5\",\n  \"slug\": \"clip-media\",\n  \"version\": \"0.3.3\",\n  \"publishedAt\": 1784659929937\n}\n\nFile v0.3.3:skill-card.md\n\n## Description: <br>\nExtract media from social media URLs using yt-dlp, with support for metadata checks, local downloads, and explicitly confirmed public temporary uploads. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jlacroix82](https://clawhub.ai/user/jlacroix82) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agent operators use Clip Media to fetch or inspect media from supported URLs and return a local path, metadata, title summary, or temporary public download link to the user. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Public temporary uploads may expose downloaded files to anyone with the link. <br>\nMitigation: Use local paths or --no-upload for sensitive content, and pass --confirm-upload only when public sharing is intended. <br>\nRisk: Browser cookie access can expose active session tokens. <br>\nMitigation: Avoid --cookies-from-browser unless the user explicitly accepts the risk; prefer non-sensitive content and limited browser profiles. <br>\nRisk: Downloading media can violate content rights or platform terms when used on unauthorized material. <br>\nMitigation: Use the skill only for content the user has rights to download and avoid private, paid, confidential, copyrighted, or regulated content unless authorized. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jlacroix82/skills/clip-media) <br>\n- [Publisher profile](https://clawhub.ai/user/jlacroix82) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, Shell commands, Metadata, File paths, Download links] <br>\n**Output Format:** [Plain text command output, JSON metadata, local file paths, or public temporary download links.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Downloaded files are saved locally by default; public temporary uploads require explicit --confirm-upload.] <br>\n\n## Skill Version(s): <br>\n0.3.3 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v0.3.3:clawhub.yaml\n\nslug: clip-media\nname: Clip Media\nowner: jlacroix82\ndescription: Extract and download media from URLs using yt-dlp with optional upload support\nversion: 0.3.2\ntype: skill\nauthor: OpenClaw\nlicense: MIT\nkeywords:\n  - media\n  - download\n  - yt-dlp\n  - video\n  - agent\nentry: SKILL.md\ndependencies:\n  - yt-dlp\n\nArchive v0.3.2: 5 files, 11602 bytes\n\nFiles: _meta.json (129b), clawhub.yaml (306b), extract.js (23366b), skill-card.md (2343b), SKILL.md (6174b)\n\nFile v0.3.2:SKILL.md\n\n---\nname: clip\ndescription: Extract media (videos, photos, GIFs, audio) from social media URLs using yt-dlp. Supports 1,872+ platforms. WARNING: files over 50 MB require --confirm-upload for public cloud upload. Browser cookie access exposes authentication material. Only use with non-sensitive content.\n---\n\n# Clip\n\n⚠️ **Security warnings before use:**\n- Files over 50 MB **require `--confirm-upload`** to upload to public third-party hosts (tmpfiles.org, transfer.sh)\n- Browser cookie access (`--cookies-from-browser`) exposes **active session tokens** for any platform you're logged into\n- **Never** use with private, paid, confidential, copyrighted, or regulated content unless you explicitly intend external transmission\n\n## How It Works\n\n1. User shares a URL from any supported platform\n2. Run the extraction script\n3. Script downloads the media (or just analyzes it)\n4. Returns the file path (under 50 MB) or a cloud link (over 50 MB)\n5. Agent sends the media to the user\n\n⚠️ **Before any extraction:** Confirm the content is not private, paid, or sensitive. Files over 50 MB are uploaded to public temp hosts — the script now shows a pre-upload warning and supports `--no-upload` to skip it entirely.\n\n## Command\n\n```bash\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js <url> [options]\n```\n\n### Options\n\n| Flag | Description |\n|------|-------------|\n| `--output-dir <dir>` | Save location (default: `/tmp/media-share`) |\n| `--title` | Return title/description only, no download |\n| `--info` | Return full metadata as JSON |\n| `--test` | Validate URL without downloading |\n| `--upload` | Force cloud upload even for small files |\n| `--confirm-upload` | **Required for any public cloud upload** — explicit opt-in |\n| `--cloud=<provider>` | Cloud provider: `tmpfiles` or `transfer` |\n| `--no-direct-send` | Always return path, never auto-send |\n| `--no-upload` | **Skip cloud upload entirely** — always return local path |\n| `--list-sites` | Show supported platforms |\n| `--list-types` | Show what media a URL contains |\n\n### Examples\n\n```bash\n# Download media (fastest path)\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.youtube.com/watch?v=dQw4w9WgXcQ\"\n\n# Get title only (no download, instant)\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.instagram.com/p/abc123/\" --title\n\n# Check what's in a URL before downloading\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.tiktok.com/@user/video/123\" --list-types\n\n# Show supported sites\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js --list-sites\n```\n\n## Supported Platforms\n\n**yt-dlp: 1,872 extractors** — covers essentially every major media platform on the internet.\n\n### Quick reference (most common):\nYouTube, TikTok, Instagram, X/Twitter, Facebook, Reddit, Twitch, Vimeo, Dailymotion, Rumble, Peertube, Bilibili, Niconico, SoundCloud, Bandcamp, Pinterest, Imgur, Tumblr, Flickr, Bluesky, Telegram, Kick, Odysee, CNN, BBC, Al Jazeera, TED, Khan Academy, Udemy, Crunchyroll, HiDive, and 1,800+ more.\n\n## File Size Handling\n\n- **Under 50 MB** → Returns local file path (agent sends via chat)\n- **Over 50 MB** → Requires `--confirm-upload` to upload to temp cloud storage, returns download link\n- **Over 50 MB without `--confirm-upload`** → Returns local path only, blocks upload with clear message\n- **Over 50 MB + `--upload`** → Forces cloud upload even for smaller files (still requires `--confirm-upload`)\n\n### Cloud Providers\n\n⚠️ **Both providers are public and third-party.** Uploaded files are accessible to anyone with the link.\n\n| Provider | Max Size | Notes |\n|----------|----------|-------|\n| `tmpfiles` | 50 MB | Simple, no signup, auto-delete |\n| `transfer` | Unlimited | transfer.sh, 30-day retention |\n\n**Pre-upload warning:** Files over 50 MB require `--confirm-upload` for any public cloud upload. Without it, the script returns the local path only and blocks the upload with a clear message. Use `--no-upload` to always save locally without prompts.\n\n## Authentication\n\n⚠️ **Browser cookie access exposes active session tokens for every platform you're logged into.**\n\nSome platforms require cookies for full access:\n\n| Platform | Needs cookies? |\n|----------|---------------|\n| Instagram | Sometimes (private content, full resolution) |\n| X / Twitter | Sometimes (rate limits, some content) |\n| Patreon | Yes (paid content) |\n| OnlyFans | Yes |\n| Fanvue / Fansly | Yes |\n| Netflix / HBO / Disney+ | Via browser cookies |\n| YouTube | Rarely (age-restricted content) |\n\n**If cookies are needed:**\n- Use `--cookies-from-browser chrome` as a **last resort** — it exposes ALL platform session tokens in that browser\n- Warn the user that this could enable unauthorized account access if the machine is compromised\n- Prefer manual cookie paste or API keys when available\n- Never use `--cookies-from-browser` with paid/sensitive platforms unless the user explicitly consents to the risk\n- Consider exporting cookies from only the specific browser/profile needed, not the default one\n\n## How It Works (Under the Hood)\n\n1. **Analyze**: `yt-dlp --dump-json` detects the platform and media type\n2. **Download**: `yt-dlp -o <path>` grabs the highest quality version\n3. **Route**: Under 50 MB → return path. Over 50 MB → upload to cloud → return link\n4. **Fallback**: If download fails, returns title/description so the agent can inform the user\n\n## Dependencies\n\n- `yt-dlp` (installed) — 1,872 extractors\n- `ffmpeg` (installed) — format conversion\n- `curl` (installed) — cloud uploads\n\n## Error Handling\n\nWhen a URL returns no media, the script returns the title/description. The agent should:\n- Inform the user what was found\n- Suggest trying `--cookies-from-browser chrome` if the platform may require auth\n- Note that geo-blocked content cannot be bypassed\n\n## Notes\n\n- Rate limits may apply on some platforms — add delays between calls\n- Some platforms (Instagram, X) work better with cookies\n- If a URL returns no media, return the title/description to the user instead\n- The `generic` extractor handles many embedded video players not explicitly listed\n\nFile v0.3.2:_meta.json\n\n{\n  \"ownerId\": \"kn7b6eyf5vc7khg5fr63pjm8xd82qvw5\",\n  \"slug\": \"clip-media\",\n  \"version\": \"0.3.2\",\n  \"publishedAt\": 1784512666766\n}\n\nFile v0.3.2:skill-card.md\n\n## Description: <br>\nClip Media helps agents extract videos, photos, GIFs, and audio from supported media URLs with yt-dlp, returning local files, metadata, or explicitly confirmed public temporary upload links. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jlacroix82](https://clawhub.ai/user/jlacroix82) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and agents use this skill to inspect or retrieve media from user-provided URLs, including title checks, metadata extraction, media downloads, and optional temporary public upload for large files. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill downloads media from URLs and may be used with private, paid, confidential, or regulated content. <br>\nMitigation: Use it only with non-sensitive content unless the user explicitly intends the download and understands the content handling risk. <br>\nRisk: Browser cookie access can expose active login sessions. <br>\nMitigation: Avoid browser cookies unless the user understands the exposure; use cookie access only as a last resort. <br>\nRisk: Large files or forced uploads can place content on public temporary hosts. <br>\nMitigation: Use --no-upload to keep files local, and use --confirm-upload only when the user intends to create a public temporary link. <br>\n\n\n## Reference(s): <br>\n- [ClawHub Skill Page](https://clawhub.ai/jlacroix82/skills/clip-media) <br>\n- [ClawHub Publisher Profile](https://clawhub.ai/user/jlacroix82) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, JSON, shell commands, files, guidance] <br>\n**Output Format:** [Markdown guidance with shell command examples, JSON metadata, local file paths, and optional public temporary URLs] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Downloads media through yt-dlp; public upload requires --confirm-upload, and --no-upload keeps files local.] <br>\n\n## Skill Version(s): <br>\n0.3.2 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nFile v0.3.2:clawhub.yaml\n\nslug: clip-media\nname: Clip Media\nowner: jlacroix82\ndescription: Extract and download media from URLs using yt-dlp with optional upload support\nversion: 0.3.2\ntype: skill\nauthor: OpenClaw\nlicense: MIT\nkeywords:\n  - media\n  - download\n  - yt-dlp\n  - video\n  - agent\nentry: SKILL.md\ndependencies:\n  - yt-dlp\n\nArchive v0.3.1: 4 files, 11146 bytes\n\nFiles: _meta.json (129b), extract.js (22848b), skill-card.md (2271b), SKILL.md (6174b)\n\nFile v0.3.1:SKILL.md\n\n---\nname: clip\ndescription: Extract media (videos, photos, GIFs, audio) from social media URLs using yt-dlp. Supports 1,872+ platforms. WARNING: files over 50 MB require --confirm-upload for public cloud upload. Browser cookie access exposes authentication material. Only use with non-sensitive content.\n---\n\n# Clip\n\n⚠️ **Security warnings before use:**\n- Files over 50 MB **require `--confirm-upload`** to upload to public third-party hosts (tmpfiles.org, transfer.sh)\n- Browser cookie access (`--cookies-from-browser`) exposes **active session tokens** for any platform you're logged into\n- **Never** use with private, paid, confidential, copyrighted, or regulated content unless you explicitly intend external transmission\n\n## How It Works\n\n1. User shares a URL from any supported platform\n2. Run the extraction script\n3. Script downloads the media (or just analyzes it)\n4. Returns the file path (under 50 MB) or a cloud link (over 50 MB)\n5. Agent sends the media to the user\n\n⚠️ **Before any extraction:** Confirm the content is not private, paid, or sensitive. Files over 50 MB are uploaded to public temp hosts — the script now shows a pre-upload warning and supports `--no-upload` to skip it entirely.\n\n## Command\n\n```bash\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js <url> [options]\n```\n\n### Options\n\n| Flag | Description |\n|------|-------------|\n| `--output-dir <dir>` | Save location (default: `/tmp/media-share`) |\n| `--title` | Return title/description only, no download |\n| `--info` | Return full metadata as JSON |\n| `--test` | Validate URL without downloading |\n| `--upload` | Force cloud upload even for small files |\n| `--confirm-upload` | **Required for any public cloud upload** — explicit opt-in |\n| `--cloud=<provider>` | Cloud provider: `tmpfiles` or `transfer` |\n| `--no-direct-send` | Always return path, never auto-send |\n| `--no-upload` | **Skip cloud upload entirely** — always return local path |\n| `--list-sites` | Show supported platforms |\n| `--list-types` | Show what media a URL contains |\n\n### Examples\n\n```bash\n# Download media (fastest path)\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.youtube.com/watch?v=dQw4w9WgXcQ\"\n\n# Get title only (no download, instant)\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.instagram.com/p/abc123/\" --title\n\n# Check what's in a URL before downloading\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.tiktok.com/@user/video/123\" --list-types\n\n# Show supported sites\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js --list-sites\n```\n\n## Supported Platforms\n\n**yt-dlp: 1,872 extractors** — covers essentially every major media platform on the internet.\n\n### Quick reference (most common):\nYouTube, TikTok, Instagram, X/Twitter, Facebook, Reddit, Twitch, Vimeo, Dailymotion, Rumble, Peertube, Bilibili, Niconico, SoundCloud, Bandcamp, Pinterest, Imgur, Tumblr, Flickr, Bluesky, Telegram, Kick, Odysee, CNN, BBC, Al Jazeera, TED, Khan Academy, Udemy, Crunchyroll, HiDive, and 1,800+ more.\n\n## File Size Handling\n\n- **Under 50 MB** → Returns local file path (agent sends via chat)\n- **Over 50 MB** → Requires `--confirm-upload` to upload to temp cloud storage, returns download link\n- **Over 50 MB without `--confirm-upload`** → Returns local path only, blocks upload with clear message\n- **Over 50 MB + `--upload`** → Forces cloud upload even for smaller files (still requires `--confirm-upload`)\n\n### Cloud Providers\n\n⚠️ **Both providers are public and third-party.** Uploaded files are accessible to anyone with the link.\n\n| Provider | Max Size | Notes |\n|----------|----------|-------|\n| `tmpfiles` | 50 MB | Simple, no signup, auto-delete |\n| `transfer` | Unlimited | transfer.sh, 30-day retention |\n\n**Pre-upload warning:** Files over 50 MB require `--confirm-upload` for any public cloud upload. Without it, the script returns the local path only and blocks the upload with a clear message. Use `--no-upload` to always save locally without prompts.\n\n## Authentication\n\n⚠️ **Browser cookie access exposes active session tokens for every platform you're logged into.**\n\nSome platforms require cookies for full access:\n\n| Platform | Needs cookies? |\n|----------|---------------|\n| Instagram | Sometimes (private content, full resolution) |\n| X / Twitter | Sometimes (rate limits, some content) |\n| Patreon | Yes (paid content) |\n| OnlyFans | Yes |\n| Fanvue / Fansly | Yes |\n| Netflix / HBO / Disney+ | Via browser cookies |\n| YouTube | Rarely (age-restricted content) |\n\n**If cookies are needed:**\n- Use `--cookies-from-browser chrome` as a **last resort** — it exposes ALL platform session tokens in that browser\n- Warn the user that this could enable unauthorized account access if the machine is compromised\n- Prefer manual cookie paste or API keys when available\n- Never use `--cookies-from-browser` with paid/sensitive platforms unless the user explicitly consents to the risk\n- Consider exporting cookies from only the specific browser/profile needed, not the default one\n\n## How It Works (Under the Hood)\n\n1. **Analyze**: `yt-dlp --dump-json` detects the platform and media type\n2. **Download**: `yt-dlp -o <path>` grabs the highest quality version\n3. **Route**: Under 50 MB → return path. Over 50 MB → upload to cloud → return link\n4. **Fallback**: If download fails, returns title/description so the agent can inform the user\n\n## Dependencies\n\n- `yt-dlp` (installed) — 1,872 extractors\n- `ffmpeg` (installed) — format conversion\n- `curl` (installed) — cloud uploads\n\n## Error Handling\n\nWhen a URL returns no media, the script returns the title/description. The agent should:\n- Inform the user what was found\n- Suggest trying `--cookies-from-browser chrome` if the platform may require auth\n- Note that geo-blocked content cannot be bypassed\n\n## Notes\n\n- Rate limits may apply on some platforms — add delays between calls\n- Some platforms (Instagram, X) work better with cookies\n- If a URL returns no media, return the title/description to the user instead\n- The `generic` extractor handles many embedded video players not explicitly listed\n\nFile v0.3.1:_meta.json\n\n{\n  \"ownerId\": \"kn7b6eyf5vc7khg5fr63pjm8xd82qvw5\",\n  \"slug\": \"clip-media\",\n  \"version\": \"0.3.1\",\n  \"publishedAt\": 1781294278807\n}\n\nFile v0.3.1:skill-card.md\n\n## Description: <br>\nExtracts media such as videos, photos, GIFs, and audio from social media URLs using yt-dlp across supported platforms. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jlacroix82](https://clawhub.ai/user/jlacroix82) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users and coding agents use Clip Media to inspect, download, or share media from URLs when the user has rights to the content and accepts the exposure risks of downloads, cookies, and optional uploads. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Public cloud uploads to tmpfiles.org or transfer.sh can expose downloaded media to anyone with the link. <br>\nMitigation: Use local output or --no-upload for sensitive content, and require --confirm-upload before any public upload. <br>\nRisk: Browser cookie access can expose active session tokens for sites where the user is logged in. <br>\nMitigation: Use browser cookies only with explicit user consent, prefer non-sensitive public content, and use the narrowest browser profile or credential source available. <br>\nRisk: Downloading private, paid, copyrighted, confidential, or regulated content can create account, legal, or privacy exposure. <br>\nMitigation: Confirm the user has rights to the content and avoid private or sensitive sources unless the user intentionally accepts the risk. <br>\n\n\n## Reference(s): <br>\n- [Clip Media on ClawHub](https://clawhub.ai/jlacroix82/clip-media) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, files, json, shell commands, guidance] <br>\n**Output Format:** [Plain text status, local file paths or public URLs, and optional JSON metadata] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Downloads save locally by default; public cloud upload requires explicit --confirm-upload.] <br>\n\n## Skill Version(s): <br>\n0.3.1 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v0.1.1: 4 files, 10985 bytes\n\nFiles: _meta.json (129b), extract.js (21839b), skill-card.md (2408b), SKILL.md (5891b)\n\nFile v0.1.1:SKILL.md\n\n---\nname: clip\ndescription: Extract media (videos, photos, GIFs, audio) from social media URLs using yt-dlp. Supports 1,872+ platforms. WARNING: files over 50 MB are uploaded to public third-party hosts. Browser cookie access exposes authentication material. Only use with non-sensitive content.\n---\n\n# Clip\n\n⚠️ **Security warnings before use:**\n- Files over 50 MB are uploaded to **public third-party file hosts** (tmpfiles.org, transfer.sh) — not private\n- Browser cookie access (`--cookies-from-browser`) exposes **active session tokens** for any platform you're logged into\n- **Never** use with private, paid, confidential, copyrighted, or regulated content unless you explicitly intend external transmission\n- Default behavior includes external upload — confirm before use\n\n## How It Works\n\n1. User shares a URL from any supported platform\n2. Run the extraction script\n3. Script downloads the media (or just analyzes it)\n4. Returns the file path (under 50 MB) or a cloud link (over 50 MB)\n5. Agent sends the media to the user\n\n⚠️ **Before any extraction:** Confirm the content is not private, paid, or sensitive. Files over 50 MB are uploaded to public temp hosts — the script now shows a pre-upload warning and supports `--no-upload` to skip it entirely.\n\n## Command\n\n```bash\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js <url> [options]\n```\n\n### Options\n\n| Flag | Description |\n|------|-------------|\n| `--output-dir <dir>` | Save location (default: `/tmp/media-share`) |\n| `--title` | Return title/description only, no download |\n| `--info` | Return full metadata as JSON |\n| `--test` | Validate URL without downloading |\n| `--upload` | Force cloud upload even for small files |\n| `--cloud=<provider>` | Cloud provider: `tmpfiles` or `transfer` |\n| `--no-direct-send` | Always return path, never auto-send |\n| `--no-upload` | **Skip cloud upload entirely** — always return local path |\n| `--list-sites` | Show supported platforms |\n| `--list-types` | Show what media a URL contains |\n\n### Examples\n\n```bash\n# Download media (fastest path)\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.youtube.com/watch?v=dQw4w9WgXcQ\"\n\n# Get title only (no download, instant)\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.instagram.com/p/abc123/\" --title\n\n# Check what's in a URL before downloading\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.tiktok.com/@user/video/123\" --list-types\n\n# Show supported sites\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js --list-sites\n```\n\n## Supported Platforms\n\n**yt-dlp: 1,872 extractors** — covers essentially every major media platform on the internet.\n\n### Quick reference (most common):\nYouTube, TikTok, Instagram, X/Twitter, Facebook, Reddit, Twitch, Vimeo, Dailymotion, Rumble, Peertube, Bilibili, Niconico, SoundCloud, Bandcamp, Pinterest, Imgur, Tumblr, Flickr, Bluesky, Telegram, Kick, Odysee, CNN, BBC, Al Jazeera, TED, Khan Academy, Udemy, Crunchyroll, HiDive, and 1,800+ more.\n\n## File Size Handling\n\n- **Under 50 MB** → Returns local file path (agent sends via chat)\n- **Over 50 MB** → Auto-uploads to temp cloud storage, returns download link\n- **Over 50 MB + `--upload`** → Forces cloud upload even for smaller files\n\n### Cloud Providers\n\n⚠️ **Both providers are public and third-party.** Uploaded files are accessible to anyone with the link.\n\n| Provider | Max Size | Notes |\n|----------|----------|-------|\n| `tmpfiles` | 50 MB | Simple, no signup, auto-delete |\n| `transfer` | Unlimited | transfer.sh, 30-day retention |\n\n**Pre-upload warning:** The script now shows a warning before any upload. Use `--no-upload` to disable cloud upload entirely and always return the local file path.\n\n## Authentication\n\n⚠️ **Browser cookie access exposes active session tokens for every platform you're logged into.**\n\nSome platforms require cookies for full access:\n\n| Platform | Needs cookies? |\n|----------|---------------|\n| Instagram | Sometimes (private content, full resolution) |\n| X / Twitter | Sometimes (rate limits, some content) |\n| Patreon | Yes (paid content) |\n| OnlyFans | Yes |\n| Fanvue / Fansly | Yes |\n| Netflix / HBO / Disney+ | Via browser cookies |\n| YouTube | Rarely (age-restricted content) |\n\n**If cookies are needed:**\n- Use `--cookies-from-browser chrome` as a **last resort** — it exposes ALL platform session tokens in that browser\n- Warn the user that this could enable unauthorized account access if the machine is compromised\n- Prefer manual cookie paste or API keys when available\n- Never use `--cookies-from-browser` with paid/sensitive platforms unless the user explicitly consents to the risk\n- Consider exporting cookies from only the specific browser/profile needed, not the default one\n\n## How It Works (Under the Hood)\n\n1. **Analyze**: `yt-dlp --dump-json` detects the platform and media type\n2. **Download**: `yt-dlp -o <path>` grabs the highest quality version\n3. **Route**: Under 50 MB → return path. Over 50 MB → upload to cloud → return link\n4. **Fallback**: If download fails, returns title/description so the agent can inform the user\n\n## Dependencies\n\n- `yt-dlp` (installed) — 1,872 extractors\n- `ffmpeg` (installed) — format conversion\n- `curl` (installed) — cloud uploads\n\n## Error Handling\n\nWhen a URL returns no media, the script returns the title/description. The agent should:\n- Inform the user what was found\n- Suggest trying `--cookies-from-browser chrome` if the platform may require auth\n- Note that geo-blocked content cannot be bypassed\n\n## Notes\n\n- Rate limits may apply on some platforms — add delays between calls\n- Some platforms (Instagram, X) work better with cookies\n- If a URL returns no media, return the title/description to the user instead\n- The `generic` extractor handles many embedded video players not explicitly listed\n\nFile v0.1.1:_meta.json\n\n{\n  \"ownerId\": \"kn7b6eyf5vc7khg5fr63pjm8xd82qvw5\",\n  \"slug\": \"clip-media\",\n  \"version\": \"0.1.1\",\n  \"publishedAt\": 1781277897110\n}\n\nFile v0.1.1:skill-card.md\n\n## Description: <br>\nClip Media extracts videos, photos, GIFs, and audio from supported social media URLs using yt-dlp, with warnings for public large-file uploads and browser-cookie access. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jlacroix82](https://clawhub.ai/user/jlacroix82) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nAgents and users use this skill to inspect or download media from user-provided URLs, returning local file paths, public temporary links, titles, or metadata. It is intended for non-sensitive content where the user accepts platform, privacy, copyright, and account-access constraints. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Large media files may be uploaded to public third-party temporary hosts. <br>\nMitigation: Use --no-upload for local-only handling and avoid private, paid, confidential, regulated, or account-gated content unless external transmission is intended. <br>\nRisk: Browser cookie access can expose active session material for logged-in platforms. <br>\nMitigation: Use browser-cookie access only with explicit consent, prefer less-sensitive authentication methods, and limit use to the specific profile or platform needed. <br>\nRisk: Media downloads from user-provided URLs can involve platform restrictions, copyright concerns, or geo-blocking. <br>\nMitigation: Confirm the user has rights to retrieve the content and communicate when a platform restriction prevents extraction. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jlacroix82/clip-media) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, json, files, shell commands, guidance] <br>\n**Output Format:** [Console text, JSON metadata, local file paths, or public temporary download URLs] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Downloads are saved locally by default; files over 50 MB may be uploaded to public temporary hosts unless --no-upload is used.] <br>\n\n## Skill Version(s): <br>\n0.1.1 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v0.3.0: 4 files, 10905 bytes\n\nFiles: _meta.json (129b), extract.js (21931b), skill-card.md (2205b), SKILL.md (5891b)\n\nFile v0.3.0:SKILL.md\n\n---\nname: clip\ndescription: Extract media (videos, photos, GIFs, audio) from social media URLs using yt-dlp. Supports 1,872+ platforms. WARNING: files over 50 MB are uploaded to public third-party hosts. Browser cookie access exposes authentication material. Only use with non-sensitive content.\n---\n\n# Clip\n\n⚠️ **Security warnings before use:**\n- Files over 50 MB are uploaded to **public third-party file hosts** (tmpfiles.org, transfer.sh) — not private\n- Browser cookie access (`--cookies-from-browser`) exposes **active session tokens** for any platform you're logged into\n- **Never** use with private, paid, confidential, copyrighted, or regulated content unless you explicitly intend external transmission\n- Default behavior includes external upload — confirm before use\n\n## How It Works\n\n1. User shares a URL from any supported platform\n2. Run the extraction script\n3. Script downloads the media (or just analyzes it)\n4. Returns the file path (under 50 MB) or a cloud link (over 50 MB)\n5. Agent sends the media to the user\n\n⚠️ **Before any extraction:** Confirm the content is not private, paid, or sensitive. Files over 50 MB are uploaded to public temp hosts — the script now shows a pre-upload warning and supports `--no-upload` to skip it entirely.\n\n## Command\n\n```bash\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js <url> [options]\n```\n\n### Options\n\n| Flag | Description |\n|------|-------------|\n| `--output-dir <dir>` | Save location (default: `/tmp/media-share`) |\n| `--title` | Return title/description only, no download |\n| `--info` | Return full metadata as JSON |\n| `--test` | Validate URL without downloading |\n| `--upload` | Force cloud upload even for small files |\n| `--cloud=<provider>` | Cloud provider: `tmpfiles` or `transfer` |\n| `--no-direct-send` | Always return path, never auto-send |\n| `--no-upload` | **Skip cloud upload entirely** — always return local path |\n| `--list-sites` | Show supported platforms |\n| `--list-types` | Show what media a URL contains |\n\n### Examples\n\n```bash\n# Download media (fastest path)\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.youtube.com/watch?v=dQw4w9WgXcQ\"\n\n# Get title only (no download, instant)\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.instagram.com/p/abc123/\" --title\n\n# Check what's in a URL before downloading\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.tiktok.com/@user/video/123\" --list-types\n\n# Show supported sites\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js --list-sites\n```\n\n## Supported Platforms\n\n**yt-dlp: 1,872 extractors** — covers essentially every major media platform on the internet.\n\n### Quick reference (most common):\nYouTube, TikTok, Instagram, X/Twitter, Facebook, Reddit, Twitch, Vimeo, Dailymotion, Rumble, Peertube, Bilibili, Niconico, SoundCloud, Bandcamp, Pinterest, Imgur, Tumblr, Flickr, Bluesky, Telegram, Kick, Odysee, CNN, BBC, Al Jazeera, TED, Khan Academy, Udemy, Crunchyroll, HiDive, and 1,800+ more.\n\n## File Size Handling\n\n- **Under 50 MB** → Returns local file path (agent sends via chat)\n- **Over 50 MB** → Auto-uploads to temp cloud storage, returns download link\n- **Over 50 MB + `--upload`** → Forces cloud upload even for smaller files\n\n### Cloud Providers\n\n⚠️ **Both providers are public and third-party.** Uploaded files are accessible to anyone with the link.\n\n| Provider | Max Size | Notes |\n|----------|----------|-------|\n| `tmpfiles` | 50 MB | Simple, no signup, auto-delete |\n| `transfer` | Unlimited | transfer.sh, 30-day retention |\n\n**Pre-upload warning:** The script now shows a warning before any upload. Use `--no-upload` to disable cloud upload entirely and always return the local file path.\n\n## Authentication\n\n⚠️ **Browser cookie access exposes active session tokens for every platform you're logged into.**\n\nSome platforms require cookies for full access:\n\n| Platform | Needs cookies? |\n|----------|---------------|\n| Instagram | Sometimes (private content, full resolution) |\n| X / Twitter | Sometimes (rate limits, some content) |\n| Patreon | Yes (paid content) |\n| OnlyFans | Yes |\n| Fanvue / Fansly | Yes |\n| Netflix / HBO / Disney+ | Via browser cookies |\n| YouTube | Rarely (age-restricted content) |\n\n**If cookies are needed:**\n- Use `--cookies-from-browser chrome` as a **last resort** — it exposes ALL platform session tokens in that browser\n- Warn the user that this could enable unauthorized account access if the machine is compromised\n- Prefer manual cookie paste or API keys when available\n- Never use `--cookies-from-browser` with paid/sensitive platforms unless the user explicitly consents to the risk\n- Consider exporting cookies from only the specific browser/profile needed, not the default one\n\n## How It Works (Under the Hood)\n\n1. **Analyze**: `yt-dlp --dump-json` detects the platform and media type\n2. **Download**: `yt-dlp -o <path>` grabs the highest quality version\n3. **Route**: Under 50 MB → return path. Over 50 MB → upload to cloud → return link\n4. **Fallback**: If download fails, returns title/description so the agent can inform the user\n\n## Dependencies\n\n- `yt-dlp` (installed) — 1,872 extractors\n- `ffmpeg` (installed) — format conversion\n- `curl` (installed) — cloud uploads\n\n## Error Handling\n\nWhen a URL returns no media, the script returns the title/description. The agent should:\n- Inform the user what was found\n- Suggest trying `--cookies-from-browser chrome` if the platform may require auth\n- Note that geo-blocked content cannot be bypassed\n\n## Notes\n\n- Rate limits may apply on some platforms — add delays between calls\n- Some platforms (Instagram, X) work better with cookies\n- If a URL returns no media, return the title/description to the user instead\n- The `generic` extractor handles many embedded video players not explicitly listed\n\nFile v0.3.0:_meta.json\n\n{\n  \"ownerId\": \"kn7b6eyf5vc7khg5fr63pjm8xd82qvw5\",\n  \"slug\": \"clip-media\",\n  \"version\": \"0.3.0\",\n  \"publishedAt\": 1780628527648\n}\n\nFile v0.3.0:skill-card.md\n\n## Description: <br>\nClip Media helps agents inspect or download media from supported social media URLs with yt-dlp, returning metadata, local file paths, or public temporary upload links. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jlacroix82](https://clawhub.ai/user/jlacroix82) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users and developers use Clip Media to validate, summarize, or download media from user-provided social URLs for agent workflows. It should be used only with non-sensitive content and with rights to download or share the media. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Large downloaded media can be uploaded to public temporary hosts. <br>\nMitigation: Use --no-upload for private or sensitive material and confirm the user intends any external transfer before downloading. <br>\nRisk: Browser-cookie workflows can expose active session tokens. <br>\nMitigation: Use browser cookies only as a last resort, warn the user first, and prefer a scoped browser profile or manual credentials when available. <br>\nRisk: Downloaded media may be paid, confidential, regulated, or copyrighted. <br>\nMitigation: Use the skill only for content the user has the right to download and share. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jlacroix82/clip-media) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, JSON, shell commands, files, guidance] <br>\n**Output Format:** [Markdown guidance with shell commands, JSON metadata, local file paths, and public download links.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May download files locally and may upload files over 50 MB to public temporary hosts unless --no-upload is used.] <br>\n\n## Skill Version(s): <br>\n0.3.0 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v0.2.0: 4 files, 10833 bytes\n\nFiles: _meta.json (129b), extract.js (21615b), skill-card.md (2277b), SKILL.md (5642b)\n\nFile v0.2.0:SKILL.md\n\n---\nname: clip\ndescription: Extract media (videos, photos, GIFs, audio) from social media URLs using yt-dlp. Supports 1,872+ platforms. WARNING: files over 50 MB are uploaded to public third-party hosts. Browser cookie access exposes authentication material. Only use with non-sensitive content.\n---\n\n# Clip\n\n⚠️ **Security warnings before use:**\n- Files over 50 MB are uploaded to **public third-party file hosts** (tmpfiles.org, transfer.sh) — not private\n- Browser cookie access (`--cookies-from-browser`) exposes **active session tokens** for any platform you're logged into\n- **Never** use with private, paid, confidential, copyrighted, or regulated content unless you explicitly intend external transmission\n- Default behavior includes external upload — confirm before use\n\n## How It Works\n\n1. User shares a URL from any supported platform\n2. Run the extraction script\n3. Script downloads the media (or just analyzes it)\n4. Returns the file path (under 50 MB) or a cloud link (over 50 MB)\n5. Agent sends the media to the user\n\n⚠️ **Before any extraction:** Confirm the content is not private, paid, or sensitive. If over 50 MB, warn the user that the file will be uploaded to a public host.\n\n## Command\n\n```bash\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js <url> [options]\n```\n\n### Options\n\n| Flag | Description |\n|------|-------------|\n| `--output-dir <dir>` | Save location (default: `/tmp/media-share`) |\n| `--title` | Return title/description only, no download |\n| `--info` | Return full metadata as JSON |\n| `--test` | Validate URL without downloading |\n| `--upload` | Force cloud upload even for small files |\n| `--cloud=<provider>` | Cloud provider: `tmpfiles` or `transfer` |\n| `--no-direct-send` | Always return path, never auto-send |\n| `--list-sites` | Show supported platforms |\n| `--list-types` | Show what media a URL contains |\n\n### Examples\n\n```bash\n# Download media (fastest path)\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.youtube.com/watch?v=dQw4w9WgXcQ\"\n\n# Get title only (no download, instant)\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.instagram.com/p/abc123/\" --title\n\n# Check what's in a URL before downloading\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.tiktok.com/@user/video/123\" --list-types\n\n# Show supported sites\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js --list-sites\n```\n\n## Supported Platforms\n\n**yt-dlp: 1,872 extractors** — covers essentially every major media platform on the internet.\n\n### Quick reference (most common):\nYouTube, TikTok, Instagram, X/Twitter, Facebook, Reddit, Twitch, Vimeo, Dailymotion, Rumble, Peertube, Bilibili, Niconico, SoundCloud, Bandcamp, Pinterest, Imgur, Tumblr, Flickr, Bluesky, Telegram, Kick, Odysee, CNN, BBC, Al Jazeera, TED, Khan Academy, Udemy, Crunchyroll, HiDive, and 1,800+ more.\n\n## File Size Handling\n\n- **Under 50 MB** → Returns local file path (agent sends via chat)\n- **Over 50 MB** → Auto-uploads to temp cloud storage, returns download link\n- **Over 50 MB + `--upload`** → Forces cloud upload even for smaller files\n\n### Cloud Providers\n\n⚠️ **Both providers are public and third-party.** Uploaded files are accessible to anyone with the link.\n\n| Provider | Max Size | Notes |\n|----------|----------|-------|\n| `tmpfiles` | 50 MB | Simple, no signup, auto-delete |\n| `transfer` | Unlimited | transfer.sh, 30-day retention |\n\n**Always warn the user before uploading to these providers.**\n\n## Authentication\n\n⚠️ **Browser cookie access exposes active session tokens for every platform you're logged into.**\n\nSome platforms require cookies for full access:\n\n| Platform | Needs cookies? |\n|----------|---------------|\n| Instagram | Sometimes (private content, full resolution) |\n| X / Twitter | Sometimes (rate limits, some content) |\n| Patreon | Yes (paid content) |\n| OnlyFans | Yes |\n| Fanvue / Fansly | Yes |\n| Netflix / HBO / Disney+ | Via browser cookies |\n| YouTube | Rarely (age-restricted content) |\n\n**If cookies are needed:**\n- Use `--cookies-from-browser chrome` as a **last resort** — it exposes ALL platform session tokens in that browser\n- Warn the user that this could enable unauthorized account access if the machine is compromised\n- Prefer manual cookie paste or API keys when available\n- Never use `--cookies-from-browser` with paid/sensitive platforms unless the user explicitly consents to the risk\n- Consider exporting cookies from only the specific browser/profile needed, not the default one\n\n## How It Works (Under the Hood)\n\n1. **Analyze**: `yt-dlp --dump-json` detects the platform and media type\n2. **Download**: `yt-dlp -o <path>` grabs the highest quality version\n3. **Route**: Under 50 MB → return path. Over 50 MB → upload to cloud → return link\n4. **Fallback**: If download fails, returns title/description so the agent can inform the user\n\n## Dependencies\n\n- `yt-dlp` (installed) — 1,872 extractors\n- `ffmpeg` (installed) — format conversion\n- `curl` (installed) — cloud uploads\n\n## Error Handling\n\nWhen a URL returns no media, the script returns the title/description. The agent should:\n- Inform the user what was found\n- Suggest trying `--cookies-from-browser chrome` if the platform may require auth\n- Note that geo-blocked content cannot be bypassed\n\n## Notes\n\n- Rate limits may apply on some platforms — add delays between calls\n- Some platforms (Instagram, X) work better with cookies\n- If a URL returns no media, return the title/description to the user instead\n- The `generic` extractor handles many embedded video players not explicitly listed\n\nFile v0.2.0:_meta.json\n\n{\n  \"ownerId\": \"kn7b6eyf5vc7khg5fr63pjm8xd82qvw5\",\n  \"slug\": \"clip-media\",\n  \"version\": \"0.2.0\",\n  \"publishedAt\": 1780599748387\n}\n\nFile v0.2.0:skill-card.md\n\n## Description: <br>\nExtracts media such as videos, photos, GIFs, and audio from social media URLs using yt-dlp, with warnings for public uploads and browser-cookie exposure. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jlacroix82](https://clawhub.ai/user/jlacroix82) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users and agent operators use this skill to inspect or download media from supported URLs and return either local file paths, temporary public download links, or metadata summaries. It is intended only for non-sensitive content unless the user explicitly accepts the external transmission and credential-handling risks. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Downloaded media may be uploaded automatically to public temporary hosting when it exceeds direct-send limits or when upload is forced. <br>\nMitigation: Use only non-sensitive media unless the user explicitly accepts public-link sharing, and inspect or disable upload paths before handling private, authenticated, paid, confidential, or rights-restricted content. <br>\nRisk: Browser-cookie based access can expose active authentication material. <br>\nMitigation: Avoid browser-cookie access for sensitive or paid platforms unless the user has explicitly consented and the execution environment has been reviewed. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jlacroix82/clip-media) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Text, JSON, Files, Shell commands, Guidance] <br>\n**Output Format:** [Console text, JSON metadata, local file paths, or temporary public URLs] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May download media locally and may upload files larger than 50 MB, or files forced with --upload, to public temporary hosting services.] <br>\n\n## Skill Version(s): <br>\n0.2.0 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v0.1.2: 4 files, 10643 bytes\n\nFiles: _meta.json (129b), extract.js (21078b), skill-card.md (2292b), SKILL.md (5553b)\n\nFile v0.1.2:SKILL.md\n\n---\nname: clip\ndescription: Extract media (videos, photos, GIFs, audio) from social media URLs using yt-dlp. Supports 1,872+ platforms. WARNING: files over 50 MB are uploaded to public third-party hosts. Browser cookie access exposes authentication material. Only use with non-sensitive content.\n---\n\n# Clip\n\n⚠️ **Security warnings before use:**\n- Files over 50 MB are uploaded to **public third-party file hosts** (tmpfiles.org, transfer.sh) — not private\n- Browser cookie access (`--cookies-from-browser`) exposes **active session tokens** for any platform you're logged into\n- **Never** use with private, paid, confidential, copyrighted, or regulated content unless you explicitly intend external transmission\n- Default behavior includes external upload — confirm before use\n\n## How It Works\n\n1. User shares a URL from any supported platform\n2. Run the extraction script\n3. Script downloads the media (or just analyzes it)\n4. Returns the file path (under 50 MB) or a cloud link (over 50 MB)\n5. Agent sends the media to the user\n\n⚠️ **Before any extraction:** Confirm the content is not private, paid, or sensitive. If over 50 MB, warn the user that the file will be uploaded to a public host.\n\n## Command\n\n```bash\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js <url> [options]\n```\n\n### Options\n\n| Flag | Description |\n|------|-------------|\n| `--output-dir <dir>` | Save location (default: `/tmp/media-share`) |\n| `--title` | Return title/description only, no download |\n| `--info` | Return full metadata as JSON |\n| `--test` | Validate URL without downloading |\n| `--upload` | Force cloud upload even for small files |\n| `--cloud=<provider>` | Cloud provider: `tmpfiles` or `transfer` |\n| `--no-direct-send` | Always return path, never auto-send |\n| `--list-sites` | Show supported platforms |\n| `--list-types` | Show what media a URL contains |\n\n### Examples\n\n```bash\n# Download media (fastest path)\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.youtube.com/watch?v=dQw4w9WgXcQ\"\n\n# Get title only (no download, instant)\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.instagram.com/p/abc123/\" --title\n\n# Check what's in a URL before downloading\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.tiktok.com/@user/video/123\" --list-types\n\n# Show supported sites\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js --list-sites\n```\n\n## Supported Platforms\n\n**yt-dlp: 1,872 extractors** — covers essentially every major media platform on the internet.\n\n### Quick reference (most common):\nYouTube, TikTok, Instagram, X/Twitter, Facebook, Reddit, Twitch, Vimeo, Dailymotion, Rumble, Peertube, Bilibili, Niconico, SoundCloud, Bandcamp, Pinterest, Imgur, Tumblr, Flickr, Bluesky, Telegram, Kick, Odysee, CNN, BBC, Al Jazeera, TED, Khan Academy, Udemy, Crunchyroll, HiDive, and 1,800+ more.\n\n## File Size Handling\n\n- **Under 50 MB** → Returns local file path (agent sends via chat)\n- **Over 50 MB** → Auto-uploads to temp cloud storage, returns download link\n- **Over 50 MB + `--upload`** → Forces cloud upload even for smaller files\n\n### Cloud Providers\n\n⚠️ **Both providers are public and third-party.** Uploaded files are accessible to anyone with the link.\n\n| Provider | Max Size | Notes |\n|----------|----------|-------|\n| `tmpfiles` | 50 MB | Simple, no signup, auto-delete |\n| `transfer` | Unlimited | transfer.sh, 30-day retention |\n\n**Always warn the user before uploading to these providers.**\n\n## Authentication\n\n⚠️ **Browser cookie access exposes active session tokens for every platform you're logged into.**\n\nSome platforms require cookies for full access:\n\n| Platform | Needs cookies? |\n|----------|---------------|\n| Instagram | Sometimes (private content, full resolution) |\n| X / Twitter | Sometimes (rate limits, some content) |\n| Patreon | Yes (paid content) |\n| OnlyFans | Yes |\n| Fanvue / Fansly | Yes |\n| Netflix / HBO / Disney+ | Via browser cookies |\n| YouTube | Rarely (age-restricted content) |\n\n**Before using `--cookies-from-browser`:**\n- Confirm the user understands this exposes session tokens for ALL platforms in that browser\n- Warn that this could enable unauthorized account access if the machine is compromised\n- Prefer alternative auth methods (API keys, manual cookie paste) when available\n- Never use `--cookies-from-browser` with paid/sensitive platforms unless the user explicitly consents to the risk\n\n## How It Works (Under the Hood)\n\n1. **Analyze**: `yt-dlp --dump-json` detects the platform and media type\n2. **Download**: `yt-dlp -o <path>` grabs the highest quality version\n3. **Route**: Under 50 MB → return path. Over 50 MB → upload to cloud → return link\n4. **Fallback**: If download fails, returns title/description so the agent can inform the user\n\n## Dependencies\n\n- `yt-dlp` (installed) — 1,872 extractors\n- `ffmpeg` (installed) — format conversion\n- `curl` (installed) — cloud uploads\n\n## Error Handling\n\nWhen a URL returns no media, the script returns the title/description. The agent should:\n- Inform the user what was found\n- Suggest trying `--cookies-from-browser chrome` if the platform may require auth\n- Note that geo-blocked content cannot be bypassed\n\n## Notes\n\n- Rate limits may apply on some platforms — add delays between calls\n- Some platforms (Instagram, X) work better with cookies\n- If a URL returns no media, return the title/description to the user instead\n- The `generic` extractor handles many embedded video players not explicitly listed\n\nFile v0.1.2:_meta.json\n\n{\n  \"ownerId\": \"kn7b6eyf5vc7khg5fr63pjm8xd82qvw5\",\n  \"slug\": \"clip-media\",\n  \"version\": \"0.1.2\",\n  \"publishedAt\": 1780543970048\n}\n\nFile v0.1.2:skill-card.md\n\n## Description: <br>\nExtracts videos, photos, GIFs, and audio from social media URLs with yt-dlp across many supported platforms. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jlacroix82](https://clawhub.ai/user/jlacroix82) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users and developers use this skill to inspect or download publicly shareable media from supported social and media URLs. It can return metadata, local file paths, or public upload links when files exceed direct-send limits. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: User-supplied URLs are incorporated into shell commands, creating a serious local command-injection risk. <br>\nMitigation: Install only from a trusted publisher and fix the script to invoke yt-dlp and curl without a shell before broad use with arbitrary URLs. <br>\nRisk: Downloaded media may be uploaded to public third-party file hosts when files exceed direct-send limits or upload is forced. <br>\nMitigation: Avoid private, paid, confidential, copyrighted, or regulated content, and warn the user before any public upload. <br>\nRisk: Browser cookie access can expose active authentication material for logged-in platforms. <br>\nMitigation: Use browser cookies only with explicit user consent and prefer scoped or manual authentication methods when available. <br>\n\n\n## Reference(s): <br>\n- [ClawHub Skill Page](https://clawhub.ai/jlacroix82/clip-media) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown instructions with shell command examples; script output may be plain text or JSON metadata.] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May return local file paths for small downloads or public third-party upload links for larger files.] <br>\n\n## Skill Version(s): <br>\n0.1.2 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v0.1.0: 4 files, 10126 bytes\n\nFiles: extract.js (21078b), skill-card.md (2403b), SKILL.md (4301b), _meta.json (129b)\n\nFile v0.1.0:SKILL.md\n\n---\nname: clip\ndescription: Extract media (videos, photos, GIFs, audio) from social media URLs using yt-dlp. Supports 1,872+ platforms including YouTube, TikTok, Instagram, X/Twitter, Facebook, Reddit, Twitch, Vimeo, and more. Drops a URL and returns the media file or cloud link.\n---\n\n# Clip\n\nDrop a URL → get the media back. Fast.\n\n## How It Works\n\n1. User shares a URL from any supported platform\n2. Run the extraction script\n3. Script downloads the media (or just analyzes it)\n4. Returns the file path (under 50 MB) or a cloud link (over 50 MB)\n5. Agent sends the media to the user\n\n## Command\n\n```bash\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js <url> [options]\n```\n\n### Options\n\n| Flag | Description |\n|------|-------------|\n| `--output-dir <dir>` | Save location (default: `/tmp/media-share`) |\n| `--title` | Return title/description only, no download |\n| `--info` | Return full metadata as JSON |\n| `--test` | Validate URL without downloading |\n| `--upload` | Force cloud upload even for small files |\n| `--cloud=<provider>` | Cloud provider: `tmpfiles` or `transfer` |\n| `--no-direct-send` | Always return path, never auto-send |\n| `--list-sites` | Show supported platforms |\n| `--list-types` | Show what media a URL contains |\n\n### Examples\n\n```bash\n# Download media (fastest path)\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.youtube.com/watch?v=dQw4w9WgXcQ\"\n\n# Get title only (no download, instant)\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.instagram.com/p/abc123/\" --title\n\n# Check what's in a URL before downloading\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js \"https://www.tiktok.com/@user/video/123\" --list-types\n\n# Show supported sites\nnode /home/jarvis/.openclaw/workspace/skills/clip/extract.js --list-sites\n```\n\n## Supported Platforms\n\n**yt-dlp: 1,872 extractors** — covers essentially every major media platform on the internet.\n\n### Quick reference (most common):\nYouTube, TikTok, Instagram, X/Twitter, Facebook, Reddit, Twitch, Vimeo, Dailymotion, Rumble, Peertube, Bilibili, Niconico, SoundCloud, Bandcamp, Pinterest, Imgur, Tumblr, Flickr, Bluesky, Telegram, Kick, Odysee, CNN, BBC, Al Jazeera, TED, Khan Academy, Udemy, Crunchyroll, HiDive, and 1,800+ more.\n\n## File Size Handling\n\n- **Under 50 MB** → Returns local file path (agent sends via chat)\n- **Over 50 MB** → Auto-uploads to temp cloud storage, returns download link\n- **Over 50 MB + `--upload`** → Forces cloud upload even for smaller files\n\n### Cloud Providers\n\n| Provider | Max Size | Notes |\n|----------|----------|-------|\n| `tmpfiles` | 50 MB | Simple, no signup, auto-delete |\n| `transfer` | Unlimited | transfer.sh, 30-day retention |\n\n## Authentication\n\nSome platforms require cookies for full access:\n\n| Platform | Needs cookies? |\n|----------|---------------|\n| Instagram | Sometimes (private content, full resolution) |\n| X / Twitter | Sometimes (rate limits, some content) |\n| Patreon | Yes (paid content) |\n| OnlyFans | Yes |\n| Fanvue / Fansly | Yes |\n| Netflix / HBO / Disney+ | Via browser cookies |\n| YouTube | Rarely (age-restricted content) |\n\nAdd `--cookies-from-browser chrome` to the command when needed.\n\n## How It Works (Under the Hood)\n\n1. **Analyze**: `yt-dlp --dump-json` detects the platform and media type\n2. **Download**: `yt-dlp -o <path>` grabs the highest quality version\n3. **Route**: Under 50 MB → return path. Over 50 MB → upload to cloud → return link\n4. **Fallback**: If download fails, returns title/description so the agent can inform the user\n\n## Dependencies\n\n- `yt-dlp` (installed) — 1,872 extractors\n- `ffmpeg` (installed) — format conversion\n- `curl` (installed) — cloud uploads\n\n## Error Handling\n\nWhen a URL returns no media, the script returns the title/description. The agent should:\n- Inform the user what was found\n- Suggest trying `--cookies-from-browser chrome` if the platform may require auth\n- Note that geo-blocked content cannot be bypassed\n\n## Notes\n\n- Rate limits may apply on some platforms — add delays between calls\n- Some platforms (Instagram, X) work better with cookies\n- If a URL returns no media, return the title/description to the user instead\n- The `generic` extractor handles many embedded video players not explicitly listed\n\nFile v0.1.0:_meta.json\n\n{\n  \"ownerId\": \"kn7b6eyf5vc7khg5fr63pjm8xd82qvw5\",\n  \"slug\": \"clip-media\",\n  \"version\": \"0.1.0\",\n  \"publishedAt\": 1779679405261\n}\n\nFile v0.1.0:skill-card.md\n\n## Description: <br>\nClip extracts videos, photos, GIFs, and audio from social media URLs using yt-dlp and returns a local media file path, metadata, or a cloud link. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[jlacroix82](https://clawhub.ai/user/jlacroix82) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nExternal users and agents use Clip to fetch or inspect media from supported social and media URLs, returning downloaded media when appropriate or metadata when a download is not requested or fails. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Downloaded media may be uploaded to temporary public third-party file hosts when files exceed the direct-send threshold or upload is forced. <br>\nMitigation: Use the skill only for media that is appropriate to share with those hosts, and avoid private, confidential, regulated, paid, or copyrighted media unless that handling is intentional. <br>\nRisk: Browser-cookie access can expose active login sessions for platforms that require authentication. <br>\nMitigation: Do not use browser-cookie options unless the operator understands the account-session exposure and has explicit permission to access the content. <br>\nRisk: The skill downloads remote media to local storage. <br>\nMitigation: Review URLs before execution, use a controlled output directory, and remove downloaded files when they are no longer needed. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/jlacroix82/clip-media) <br>\n- [ClawHub publisher profile](https://clawhub.ai/user/jlacroix82) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, JSON, files, shell commands, guidance] <br>\n**Output Format:** [Command-line text, JSON metadata, local file paths, or cloud download URLs] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Returns local paths for files under 50 MB and may return temporary public cloud links for larger files or forced uploads.] <br>\n\n## Skill Version(s): <br>\n0.1.0 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>","readmeExcerpt":"Skill: Clip Media Owner: jlacroix82 Summary: Extract media (videos, photos, GIFs, audio) from social media URLs using yt-dlp. Supports 1,872+ platforms including YouTube, TikTok, Instagram, X/Twitter, F... Tags: latest:0.3.5 Version history: v0.3.5 | 2026-07-22T16:26:47.646Z | user Security: external URL fetch warnings, input validation notes v0.3.4 | 2026-07-22T16:04:54.784Z | user Security improvements: clarified d","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"node skills/clip/extract.js <url> [options]"},{"language":"bash","snippet":"# Download media (fastest path)\nnode skills/clip/extract.js \"https://www.youtube.com/watch?v=dQw4w9WgXcQ\"\n\n# Get title only (no download, instant)\nnode skills/clip/extract.js \"https://www.instagram.com/p/abc123/\" --title\n\n# Check what's in a URL before downloading\nnode skills/clip/extract.js \"https://www.tiktok.com/@user/video/123\" --list-types\n\n# Show supported sites\nnode skills/clip/extract.js --list-sites"},{"language":"bash","snippet":"node skills/clip/extract.js <url> [options]"},{"language":"bash","snippet":"# Download media (fastest path)\nnode skills/clip/extract.js \"https://www.youtube.com/watch?v=dQw4w9WgXcQ\"\n\n# Get title only (no download, instant)\nnode skills/clip/extract.js \"https://www.instagram.com/p/abc123/\" --title\n\n# Check what's in a URL before downloading\nnode skills/clip/extract.js \"https://www.tiktok.com/@user/video/123\" --list-types\n\n# Show supported sites\nnode skills/clip/extract.js --list-sites"},{"language":"bash","snippet":"node skills/clip/extract.js <url> [options]"},{"language":"bash","snippet":"# Download media (fastest path)\nnode skills/clip/extract.js \"https://www.youtube.com/watch?v=dQw4w9WgXcQ\"\n\n# Get title only (no download, instant)\nnode skills/clip/extract.js \"https://www.instagram.com/p/abc123/\" --title\n\n# Check what's in a URL before downloading\nnode skills/clip/extract.js \"https://www.tiktok.com/@user/video/123\" --list-types\n\n# Show supported sites\nnode skills/clip/extract.js --list-sites"}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: clip\ndescription: Extract media (videos, photos, GIFs, audio) from social media URLs using yt-dlp. Supports 1,872+ platforms. WARNING: files over 50 MB require --confirm-upload for public cloud upload. Browser cookie access exposes authentication material. Only use with non-sensitive content.\n---\n\n# Clip\n\n⚠️ **Security warnings before use:**\n- Files over 50 MB **require `--confirm-upload`** to upload to public third-party hosts (tmpfiles.org, transfer.sh)\n- Browser cookie access (`--cookies-from-browser`) exposes **active session tokens** for any platform you're logged into\n- **Never** use with private, paid, confidential, copyrighted, or regulated content unless you explicitly intend external transmission\n\n## How It Works\n\n1. User shares a URL from any supported platform\n2. Run the extraction script\n3. Script downloads the media (or just analyzes it)\n4. Returns the file path (under 50 MB) or a cloud link (over 50 MB)\n5. Agent sends the media to the user\n\n⚠️ **Before any extraction:** Confirm the content is not private, paid, or sensitive. Files over 50 MB are uploaded to public temp hosts — the script now shows a pre-upload warning and supports `--no-upload` to skip it entirely.\n\n## Command\n\n```bash\nnode skills/clip/extract.js <url> [options]\n```\n\n### Options\n\n| Flag | Description |\n|------|-------------|\n| `--output-dir <dir>` | Save location (default: `/tmp/media-share`) |\n| `--title` | Return title/description only, no download |\n| `--info` | Return full metadata as JSON |\n| `--test` | Validate URL without downloading |\n| `--upload` | Force cloud upload even for small files |\n| `--confirm-upload` | **Required for any public cloud upload** — explicit opt-in |\n| `--cloud=<provider>` | Cloud provider: `tmpfiles` or `transfer` |\n| `--no-direct-send` | Always return path, never auto-send |\n| `--no-upload` | **Skip cloud upload entirely** — always return local path |\n| `--list-sites` | Show supported platforms |\n| `--list-types` | Show what media a URL contains |\n\n### Examples\n\n```bash\n# Download media (fastest path)\nnode skills/clip/extract.js \"https://www.youtube.com/watch?v=dQw4w9WgXcQ\"\n\n# Get title only (no download, instant)\nnode skills/clip/extract.js \"https://www.instagram.com/p/abc123/\" --title\n\n# Check what's in a URL before downloading\nnode skills/clip/extract.js \"https://www.tiktok.com/@user/video/123\" --list-types\n\n# Show supported sites\nnode skills/clip/extract.js --list-sites\n```\n\n## Supported Platforms\n\n**yt-dlp: 1,872 extractors** — covers essentially every major media platform on the internet.\n\n### Quick reference (most common):\nYouTube, TikTok, Instagram, X/Twitter, Facebook, Reddit, Twitch, Vimeo, Dailymotion, Rumble, Peertube, Bilibili, Niconico, SoundCloud, Bandcamp, Pinterest, Imgur, Tumblr, Flickr, Bluesky, Telegram, Kick, Odysee, CNN, BBC, Al Jazeera, TED, Khan Academy, Udemy, Crunchyroll, HiDive, and 1,800+ more.\n\n## File Size Handling\n\n- **Under 50 MB** → Returns local file path (agent sends via chat)\n- **Over 50"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn7b6eyf5vc7khg5fr63pjm8xd82qvw5\",\n  \"slug\": \"clip-media\",\n  \"version\": \"0.3.5\",\n  \"publishedAt\": 1784737607646\n}"},{"path":"skill-card.md","content":"## Description:\n\nExtract media such as videos, photos, GIFs, and audio from social media URLs using yt-dlp, returning local files, metadata, or an explicitly confirmed public upload link.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[jlacroix82](https://clawhub.ai/user/jlacroix82)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and agents use Clip Media to inspect or retrieve media from supported URLs and return metadata, local file paths, or temporary public links after explicit upload consent. It is intended for non-sensitive media where downloading and any external transmission are permitted.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: Public upload paths can expose media through third-party temporary hosts and may not use the upload host the user selected.\n\nMitigation: Use --no-upload for sensitive files, require --confirm-upload for any public upload, and verify the actual returned host before sharing the link.\n\nRisk: Browser-wide cookie access can expose active authenticated sessions.\n\nMitigation: Avoid --cookies-from-browser unless the user explicitly accepts the risk; prefer non-sensitive public URLs or narrowly scoped manual credentials.\n\nRisk: Private, paid, copyrighted, regulated, or confidential media can create legal, privacy, or policy exposure if downloaded or transmitted.\n\nMitigation: Confirm the content is permitted for download and sharing before extraction, and keep regulated or confidential content local.\n\n## Reference(s):\n\n- [ClawHub Skill Page](https://clawhub.ai/jlacroix82/skills/clip-media)\n- [Publisher Profile](https://clawhub.ai/user/jlacroix82)\n\n## Skill Output:\n\n**Output Type(s):** [text, JSON, files, shell commands, guidance]\n\n**Output Format:** [Plain text, JSON metadata, local file paths, and temporary public URLs]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Downloads are saved locally by default; public uploads require explicit confirmation and may use third-party temporary hosts.]\n\n## Skill Version(s):\n\n0.3.5 (source: server release metadata and clawhub.yaml)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."},{"path":"clawhub.yaml","content":"slug: clip-media\nname: Clip Media\nowner: jlacroix82\ndescription: Extract and download media from URLs using yt-dlp. ⚠️ Files over 50MB require explicit opt-in for public cloud upload. Browser cookie access exposes session tokens.\nversion: 0.3.5\ntype: skill\nauthor: OpenClaw\nlicense: MIT\nkeywords:\n  - media\n  - download\n  - yt-dlp\n  - video\n  - agent\nentry: SKILL.md\ndependencies:\n  - yt-dlp"}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":"Extract media (videos, photos, GIFs, audio) from social media URLs using yt-dlp. Supports 1,872+ platforms including YouTube, TikTok, Instagram, X/Twitter, F... Skill: Clip Media Owner: jlacroix82 Summary: Extract media (videos, photos, GIFs, audio) from social media URLs using yt-dlp. Supports 1,872+ platforms including YouTube, TikTok, Instagram, X/Twitter, F... Tags: latest:0.3.5 Version history: v0.3.5 | 2026-07-22T16:26:47.646Z | user Security: external URL fetch warnings, input validation notes v0.3.4 | 2026-07-22T16:04:54.784Z | user Security improvements: clarified d","editorialQuality":{"score":100,"threshold":65,"status":"ready","wordCount":1300,"uniquenessScore":49,"reasons":[]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T23:52:27.504Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T23:52:27.504Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-10T06:44:45.582Z","emptyReason":null},"items":[{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-10-09T19:11:12.944Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}