{"id":"876c377d-b7e6-498b-b95c-e99f2d44d337","entityType":"agent","slug":"clawhub-psyb0t-mediaproc","name":"mediaproc","canonicalUrl":"https://www.xpersona.co/agent/clawhub-psyb0t-mediaproc","canonicalPath":"/agent/clawhub-psyb0t-mediaproc","generatedAt":"2026-10-09T14:38:44.763Z","source":"CLAWHUB","claimStatus":"UNCLAIMED","verificationTier":"NONE","summary":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T09:28:53.471Z","emptyReason":null},"description":"Process media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. Use when the user wants to transcode video, process audio, manipulate images, or work with media files.","descriptionLabel":"Source description","evidenceSummary":"Capability contract not published. No trust telemetry is available yet. 3.2K downloads reported by the source. Last updated 10/9/2026.","installCommand":"clawhub skill install s17fq93tmpky791n7516jcn08n83sfn2:mediaproc","sourceUrl":"https://clawhub.ai/psyb0t/mediaproc","homepage":"https://clawhub.ai/psyb0t/skills/mediaproc","primaryLinks":[{"label":"View on ClawHub","url":"https://clawhub.ai/psyb0t/mediaproc","kind":"source"},{"label":"Homepage","url":"https://clawhub.ai/psyb0t/skills/mediaproc","kind":"homepage"}],"safetyScore":84,"overallRank":62,"popularityScore":61,"trustScore":null,"claimedByName":null,"isOwner":false,"seoDescription":"mediaproc technical dossier on Xpersona with agent coverage, OPENCLEW support, and live trust metadata."},"coverage":{"evidence":{"source":"public-profile","verified":false,"confidence":"medium","updatedAt":"2026-10-09T09:28:53.471Z","emptyReason":null},"protocols":[{"protocol":"OPENCLEW","label":"OpenClaw","status":"self-declared","notes":"Declared in the public agent profile."}],"capabilities":[],"verifiedCount":0,"selfDeclaredCount":1,"capabilityMatrix":{"rows":[{"key":"OPENCLEW","type":"protocol","support":"unknown","confidenceSource":"profile","notes":"Listed on profile"}],"flattenedTokens":"protocol:OPENCLEW|unknown|profile"}},"adoption":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T09:28:53.471Z","emptyReason":null},"stars":null,"forks":null,"downloads":3155,"packageName":null,"latestVersion":"2.0.12","tractionLabel":"3.2K downloads"},"release":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T09:28:53.471Z","emptyReason":null},"lastUpdatedAt":"2026-10-09T09:28:53.471Z","lastCrawledAt":"2026-10-09T09:28:53.471Z","lastIndexedAt":null,"nextCrawlAt":"2026-10-10T09:28:53.471Z","lastVerifiedAt":null,"highlights":[{"version":"2.0.12","createdAt":"2026-08-01T20:29:27.655Z","changelog":"- Removed the skill-card.md file. - No changes to functionality or documentation content.","fileCount":5,"zipByteSize":6672},{"version":"2.0.11","createdAt":"2026-07-27T23:39:10.360Z","changelog":"- Removed the skill-card.md file. - No changes to core code or functionality. - Documentation remains otherwise unchanged.","fileCount":5,"zipByteSize":6581},{"version":"2.0.10","createdAt":"2026-07-27T23:09:12.592Z","changelog":"- Removed the sample skill-card.md file. - No changes to core functionality or documentation content.","fileCount":5,"zipByteSize":6570},{"version":"2.0.9","createdAt":"2026-07-27T15:18:41.335Z","changelog":"- Removed the file: skill-card.md - No other functional or documentation changes in this release.","fileCount":5,"zipByteSize":6564},{"version":"2.0.8","createdAt":"2026-07-27T13:27:51.063Z","changelog":"- Removed the unnecessary skill-card.md file from the repository. - No changes to core functionality or documentation.","fileCount":5,"zipByteSize":6555},{"version":"2.0.7","createdAt":"2026-07-26T09:30:01.033Z","changelog":"- Removed the skill-card.md file. - No other functional or documentation changes.","fileCount":5,"zipByteSize":6650},{"version":"2.0.6","createdAt":"2026-07-25T23:21:48.216Z","changelog":"- Clarified that scripts/mediaproc.sh sends commands as a single argument and does not invoke any shell, further strengthening security notes about command execution. - Added strong warnings about the destructive nature of remove-file, remove-dir, and especially remove-dir-recursive commands, with advice to seek explicit user confirmation before running them. - Removed skill-card.md (no longer needed). - Minor documentation updates and clarifications in SKILL.md and references/setup.md.","fileCount":5,"zipByteSize":6581},{"version":"2.0.5","createdAt":"2026-07-25T22:21:42.083Z","changelog":"- Clarified that `scripts/mediaproc.sh` does not enable arbitrary code execution; only fixed, server-side allow-listed commands are permitted. - Expanded the security model section to emphasize server-side enforcement and trust boundaries for `MEDIAPROC_HOST`. - Improved language throughout documentation to make security constraints and intended usage more explicit. - Removed the outdated skill-card.md documentation file.","fileCount":5,"zipByteSize":6096}]},"execution":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No published capability contract is available yet."},"installCommand":"clawhub skill install s17fq93tmpky791n7516jcn08n83sfn2:mediaproc","setupComplexity":"low","setupSteps":["Install using `clawhub skill install s17fq93tmpky791n7516jcn08n83sfn2:mediaproc` in an isolated environment before connecting it to live workloads.","No published capability contract is available yet, so validate auth and request/response behavior manually.","Review the upstream CLAWHUB listing at https://clawhub.ai/psyb0t/mediaproc before using production credentials."],"contract":{"contractStatus":"missing","authModes":[],"requires":[],"forbidden":[],"supportsMcp":false,"supportsA2a":false,"supportsStreaming":false,"inputSchemaRef":null,"outputSchemaRef":null,"dataRegion":null,"contractUpdatedAt":null,"sourceUpdatedAt":null,"freshnessSeconds":null},"invocationGuide":{"preferredApi":{"snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-mediaproc/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-mediaproc/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-mediaproc/trust"},"curlExamples":["curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-mediaproc/snapshot\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-mediaproc/contract\"","curl -s \"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-mediaproc/trust\""],"jsonRequestTemplate":{"query":"summarize this repo","constraints":{"maxLatencyMs":2000,"protocolPreference":["OPENCLEW"]}},"jsonResponseTemplate":{"ok":true,"result":{"summary":"...","confidence":0.9},"meta":{"source":"CLAWHUB","generatedAt":"2026-10-09T14:38:44.760Z"}},"retryPolicy":{"maxAttempts":3,"backoffMs":[500,1500,3500],"retryableConditions":["HTTP_429","HTTP_503","NETWORK_TIMEOUT"]}},"endpoints":{"dossierUrl":"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-mediaproc/dossier","snapshotUrl":"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-mediaproc/snapshot","contractUrl":"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-mediaproc/contract","trustUrl":"https://www.xpersona.co/api/v1/agents/clawhub-psyb0t-mediaproc/trust"}},"reliability":{"evidence":{"source":"runtime-metrics","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No trust, reliability, or runtime telemetry is available."},"trust":{"status":"unavailable","handshakeStatus":"UNKNOWN","verificationFreshnessHours":null,"reputationScore":null,"p95LatencyMs":null,"successRate30d":null,"fallbackRate":null,"attempts30d":null,"trustUpdatedAt":null,"trustConfidence":"unknown","sourceUpdatedAt":null,"freshnessSeconds":null},"decisionGuardrails":{"doNotUseIf":["Contract metadata is missing or unavailable for deterministic execution."],"safeUseWhen":[],"riskFlags":["missing_or_unavailable_contract","trust_data_unavailable","schema_references_missing"],"operationalConfidence":"low"},"executionMetrics":{"observedLatencyMsP50":null,"observedLatencyMsP95":null,"estimatedCostUsd":null,"uptime30d":null,"rateLimitRpm":null,"rateLimitBurst":null,"lastVerifiedAt":null,"verificationSource":null},"runtimeMetrics":{"successRate":null,"avgLatencyMs":null,"avgCostUsd":null,"hallucinationRate":null,"retryRate":null,"disputeRate":null,"p50Latency":null,"p95Latency":null,"lastUpdated":null}},"benchmarks":{"evidence":{"source":"no-benchmark-data","verified":false,"confidence":"low","updatedAt":null,"emptyReason":"No benchmark suites or observed failure patterns are available."},"suites":[],"failurePatterns":[]},"artifacts":{"evidence":{"source":"CLAWHUB","verified":false,"confidence":"medium","updatedAt":"2026-10-09T09:28:53.471Z","emptyReason":null},"readme":"Skill: mediaproc\n\nOwner: psyb0t\n\nSummary: Process media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. Use when the user wants to transcode video, process audio, manipulate images, or work with media files.\n\nTags: latest:2.0.12\n\nVersion history:\n\nv2.0.12 | 2026-08-01T20:29:27.655Z | auto\n\n- Removed the skill-card.md file.\n- No changes to functionality or documentation content.\n\nv2.0.11 | 2026-07-27T23:39:10.360Z | auto\n\n- Removed the skill-card.md file.\n- No changes to core code or functionality.\n- Documentation remains otherwise unchanged.\n\nv2.0.10 | 2026-07-27T23:09:12.592Z | auto\n\n- Removed the sample skill-card.md file.\n- No changes to core functionality or documentation content.\n\nv2.0.9 | 2026-07-27T15:18:41.335Z | auto\n\n- Removed the file: skill-card.md\n- No other functional or documentation changes in this release.\n\nv2.0.8 | 2026-07-27T13:27:51.063Z | auto\n\n- Removed the unnecessary skill-card.md file from the repository.\n- No changes to core functionality or documentation.\n\nv2.0.7 | 2026-07-26T09:30:01.033Z | auto\n\n- Removed the skill-card.md file.\n- No other functional or documentation changes.\n\nv2.0.6 | 2026-07-25T23:21:48.216Z | auto\n\n- Clarified that scripts/mediaproc.sh sends commands as a single argument and does not invoke any shell, further strengthening security notes about command execution.\n- Added strong warnings about the destructive nature of remove-file, remove-dir, and especially remove-dir-recursive commands, with advice to seek explicit user confirmation before running them.\n- Removed skill-card.md (no longer needed).\n- Minor documentation updates and clarifications in SKILL.md and references/setup.md.\n\nv2.0.5 | 2026-07-25T22:21:42.083Z | auto\n\n- Clarified that `scripts/mediaproc.sh` does not enable arbitrary code execution; only fixed, server-side allow-listed commands are permitted.\n- Expanded the security model section to emphasize server-side enforcement and trust boundaries for `MEDIAPROC_HOST`.\n- Improved language throughout documentation to make security constraints and intended usage more explicit.\n- Removed the outdated skill-card.md documentation file.\n\nv2.0.3 | 2026-07-25T00:02:23.580Z | auto\n\n- Added detailed security model section to documentation, outlining mediaproc’s confinement, allowed commands, authentication requirements, and separation from provisioning.\n- Removed skill-card.md as part of documentation cleanup.\n- Clarified that mediaproc never installs or escalates anything on your machine; server setup is separate.\n- No changes to command usage or file operations.\n\nv2.0.1 | 2026-03-30T11:52:49.971Z | user\n\nNo user-visible changes in this version.  \n- Version bump only; no changes detected in skill documentation or files.\n\nv2.0.0 | 2026-02-17T13:07:21.498Z | user\n\nv2\n\nv1.0.2 | 2026-02-05T19:07:19.415Z | user\n\nInitial release.\n\n- Process video, audio, and image files via SSH in a locked-down container.\n- Provides common media tools: ffmpeg, sox, ImageMagick, and related utilities.\n- Supports secure file operations: upload, download, list, remove, and directory management within a confined workspace.\n- Includes video, audio, and image processing examples and plugin support for effects.\n- Enforces strong security by whitelisting commands and locking all paths under /work.\n\nv1.1.0 | 2026-02-05T09:35:38.549Z | user\n\n- Added explicit instructions for accepting the SSH host key on first connection to prevent host verification errors.\n- Clarified usage of the `ls` command: output style (`ls -alph`), exclusion of `.` and `..`, and support for `--json` flag.\n- Updated file management examples to show both standard and JSON listing with `ls`.\n- No code or interface changes; these are documentation and usability improvements.\n\nv1.0.0 | 2026-02-05T09:09:47.512Z | user\n\nInitial release of mediaproc.\n\n- Provides locked-down media processing over SSH using ffmpeg, sox, and ImageMagick.\n- All operations are confined to a container and restricted to whitelisted commands—no shell access or injection risk.\n- Supports file management commands (ls, put, get, rm, mkdir, rmdir, rrmdir).\n- Allows audio, video, and image transformations, with multiple plugin and font options.\n- Requires configuration of MEDIAPROC_HOST and MEDIAPROC_PORT.\n- Enhanced security: SSH key authentication only, strict path confinement, and complete shell exclusion.\n\nArchive index:\n\nArchive v2.0.12: 5 files, 6672 bytes\n\nFiles: references/setup.md (2926b), scripts/mediaproc.sh (548b), skill-card.md (2402b), SKILL.md (8147b), _meta.json (129b)\n\nFile v2.0.12:SKILL.md\n\n---\nname: mediaproc\ndescription: Process media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. Use when the user wants to transcode video, process audio, manipulate images, or work with media files.\ncompatibility: Requires ssh and a running mediaproc instance. MEDIAPROC_HOST and MEDIAPROC_PORT env vars must be set.\nmetadata:\n  author: psyb0t\n  homepage: https://github.com/psyb0t/docker-mediaproc\n---\n\n# mediaproc\n\nLocked-down media processing over SSH. Built on [lockbox](https://github.com/psyb0t/docker-lockbox) — no shell access, no injection, no bullshit.\n\nFor installation and deployment, see [references/setup.md](references/setup.md).\n\n## Security model\n\nmediaproc is **not** a general-purpose shell, and `scripts/mediaproc.sh` is **not**\narbitrary remote code execution even though it forwards a free-form-looking command\nstring. The instance runs inside a [lockbox](https://github.com/psyb0t/docker-lockbox)-\nhardened container, and this skill only ever talks to an instance you (or your\noperator) already run and trust:\n\n- **Key-auth only** — SSH accepts public-key auth only (no passwords), connecting\n  as a restricted user. There is no interactive shell and no PTY.\n- **Server-side enforced allow-list, not documentation** — `scripts/mediaproc.sh`\n  passes its argument through to the SSH channel as-is, but the *remote* lockbox\n  dispatcher is what decides what runs, and it only ever executes the fixed set\n  documented below: `ffmpeg`, `ffprobe`, `sox`, `soxi`, `convert`, `identify`,\n  `magick`, plus lockbox's built-in, scoped file operations. This is an enforced\n  allow-list on the server, not a client-side convention — the wrapper cannot be\n  used to run anything outside that set. Any other command name is refused before\n  execution; the remote never spawns a shell, so there is no shell-injection\n  surface and no way to chain (`;`, `|`, `&&`, backticks, etc.) into a second\n  command.\n- **Work-dir confined** — every path resolves under the instance work directory\n  (`/work`); traversal is blocked. The sandbox cannot read or write your host\n  filesystem.\n- **Consumer-only** — this skill moves files to/from a running instance and runs\n  the whitelisted media tools on them. It never provisions, escalates, or installs\n  anything on your machine (server setup is a separate, operator-side step — see\n  setup.md).\n- **You must still trust the configured host** — `MEDIAPROC_HOST`/`MEDIAPROC_PORT`\n  point at a specific instance. The allow-list constrains *what* runs, not *where*;\n  if `MEDIAPROC_HOST` is pointed at an instance you don't control, that operator\n  still sees every file you `put`/`get` and every command you send. Only point\n  this skill at a mediaproc instance you or a trusted operator run.\n\n## SSH Wrapper\n\nUse `scripts/mediaproc.sh` for all commands. It handles host, port, and host key acceptance via `MEDIAPROC_HOST` and `MEDIAPROC_PORT` env vars.\n\nThe `<command>` argument looks free-form but is not arbitrary execution: the\nwrapper does no shell evaluation of it — it passes the whole string as a single\nargument over the SSH channel — and it is the *remote* lockbox dispatcher that\nenforces the allow-list from the Security model above, server-side, on every\ninvocation. There is no local or remote shell in the loop, so there's no\ninjection/chaining surface (`;`, `|`, `&&`, backticks, etc. are inert; the\ndispatcher just refuses anything that isn't the fixed command name it expects).\n\n```bash\nscripts/mediaproc.sh <command> [args]\nscripts/mediaproc.sh <command> < input_file\nscripts/mediaproc.sh <command> > output_file\n```\n\n## Media Tools\n\n| Command    | Description                                  |\n| ---------- | -------------------------------------------- |\n| `ffmpeg`   | Video/audio encoding, transcoding, filtering |\n| `ffprobe`  | Media file analysis                          |\n| `sox`      | Audio processing                             |\n| `soxi`     | Audio file info                              |\n| `convert`  | Image conversion/manipulation (ImageMagick)  |\n| `identify` | Image file info (ImageMagick)                |\n| `magick`   | ImageMagick CLI                              |\n\n## Upload, Process, Download\n\n```bash\n# Upload\nscripts/mediaproc.sh \"put input.mp4\" < input.mp4\n\n# Transcode\nscripts/mediaproc.sh \"ffmpeg -i /work/input.mp4 -c:v libx264 /work/output.mp4\"\n\n# Download result\nscripts/mediaproc.sh \"get output.mp4\" > output.mp4\n\n# Clean up\nscripts/mediaproc.sh \"remove-file input.mp4\"\nscripts/mediaproc.sh \"remove-file output.mp4\"\n```\n\n## Video Operations\n\n```bash\n# Get video info as JSON\nscripts/mediaproc.sh \"ffprobe -v quiet -print_format json -show_format -show_streams /work/video.mp4\"\n\n# Apply frei0r glow effect\nscripts/mediaproc.sh \"ffmpeg -i /work/in.mp4 -vf frei0r=glow:0.5 /work/out.mp4\"\n\n# Extract audio from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -vn -acodec libmp3lame /work/audio.mp3\"\n\n# Create thumbnail from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -ss 00:00:05 -vframes 1 /work/thumb.jpg\"\n```\n\n## Audio Operations\n\n```bash\n# Convert audio format\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.mp3\"\n\n# Get audio info\nscripts/mediaproc.sh \"soxi /work/audio.wav\"\n\n# Normalize audio\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.wav norm\"\n```\n\n## Image Operations\n\n```bash\n# Resize image\nscripts/mediaproc.sh \"convert /work/input.png -resize 50% /work/output.png\"\n\n# Create thumbnail\nscripts/mediaproc.sh \"convert /work/input.jpg -thumbnail 200x200 /work/thumb.jpg\"\n\n# Get image info\nscripts/mediaproc.sh \"identify /work/image.png\"\n```\n\n## File Operations\n\nAll paths relative to the work directory. Traversal blocked.\n\n**Destructive.** `remove-file`, `remove-dir`, and `remove-dir-recursive`\npermanently delete data in the remote work directory — there is no trash/undo.\n`remove-dir-recursive` deletes an entire subtree in one call and is especially\ndangerous. Only run these after explicit user confirmation of the exact path.\n\n| Command                | Description                        |\n| ---------------------- | ---------------------------------- |\n| `put <path>`           | Upload file from stdin             |\n| `get <path>`           | Download file to stdout            |\n| `list-files [--json]`  | List directory                     |\n| `remove-file <path>`   | Delete a file                      |\n| `create-dir <path>`    | Create directory                   |\n| `remove-dir <path>`    | Remove empty directory             |\n| `remove-dir-recursive <path>` | Remove directory recursively |\n| `move-file <src> <dst>`| Move or rename                     |\n| `copy-file <src> <dst>`| Copy a file                        |\n| `file-info <path>`     | Get file metadata as JSON          |\n| `file-exists <path>`   | Check if file exists (true/false)  |\n| `file-hash <path>`     | Get SHA256 hash                    |\n| `disk-usage [path]`    | Get bytes used                     |\n| `search-files <glob>`  | Glob search                        |\n| `append-file <path>`   | Append stdin to a file             |\n\n```bash\n# List files\nscripts/mediaproc.sh \"list-files\"\n\n# List as JSON (size, modified, isDir, permissions)\nscripts/mediaproc.sh \"list-files --json\"\n\n# List subdirectory\nscripts/mediaproc.sh \"list-files project1\"\n\n# File operations\nscripts/mediaproc.sh \"create-dir project1\"\nscripts/mediaproc.sh \"move-file old.mp4 new.mp4\"\nscripts/mediaproc.sh \"copy-file input.mp4 backup.mp4\"\nscripts/mediaproc.sh \"file-info video.mp4\"\nscripts/mediaproc.sh \"file-exists video.mp4\"\nscripts/mediaproc.sh \"file-hash video.mp4\"\nscripts/mediaproc.sh \"search-files '*.mp4'\"\nscripts/mediaproc.sh \"disk-usage\"\nscripts/mediaproc.sh \"remove-dir-recursive project1\"\n```\n\n## Plugins\n\n- **frei0r** — Video effect plugins (used via `-vf frei0r=...`)\n- **LADSPA** — Audio effect plugins: SWH, TAP, CMT (used via `-af ladspa=...`)\n- **LV2** — Audio plugins (used via `-af lv2=...`)\n\n## Fonts\n\n2200+ fonts included covering emoji, CJK, Arabic, Thai, Indic, monospace, and more. Custom fonts can be mounted to `/usr/share/fonts/custom`.\n\nFile v2.0.12:_meta.json\n\n{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"mediaproc\",\n  \"version\": \"2.0.12\",\n  \"publishedAt\": 1785616167655\n}\n\nFile v2.0.12:references/setup.md\n\n# mediaproc setup\n\n## Quick Install\n\nThe installer creates `~/.mediaproc/` (docker-compose, authorized_keys, work\ndirectory) and drops a `mediaproc` command into `/usr/local/bin`. The container\nit stands up is a [lockbox](https://github.com/psyb0t/docker-lockbox)-hardened\nSSH sandbox (key-auth, whitelisted commands only — see the Security model in\nSKILL.md).\n\nBecause the installer runs as **root**, pin it to a released tag and read it\nbefore running — don't pipe a mutable `main` branch straight into a root shell:\n\n```bash\n# Pick a released tag: https://github.com/psyb0t/docker-mediaproc/releases\nREF=vX.Y.Z\ncurl -fsSL \"https://raw.githubusercontent.com/psyb0t/docker-mediaproc/${REF}/install.sh\" -o install.sh\nless install.sh            # review exactly what runs as root\nsudo bash install.sh\n```\n\n## Starting\n\n```bash\n# Add your SSH key\ncat ~/.ssh/id_rsa.pub >> ~/.mediaproc/authorized_keys\n\n# Basic start (detached)\nmediaproc start -d\n\n# With resource limits\nmediaproc start -d -c 4 -r 4g -s 2g\n\n# Custom port\nmediaproc start -d -p 2223\n\n# Custom fonts directory\nmediaproc start -d -f /path/to/fonts\n```\n\nAll flags persist to `~/.mediaproc/.env` — next `start` reuses the last values.\n\n## Management\n\n```bash\nmediaproc stop                # stop\nmediaproc upgrade             # pull latest image, asks to stop/restart\nmediaproc uninstall           # stop and remove everything\nmediaproc status              # show status\nmediaproc logs                # show container logs\n```\n\n## Configuration\n\n| Flag | Env var            | Default    | Description           |\n| ---- | ------------------ | ---------- | --------------------- |\n| `-p` | `MEDIAPROC_PORT`   | `2222`     | SSH port              |\n| `-f` | `MEDIAPROC_FONTS_DIR` | `./fonts` | Custom fonts directory |\n| `-c` | `MEDIAPROC_CPUS`   | `0`        | CPU limit (0 = unlimited) |\n| `-r` | `MEDIAPROC_MEMORY` | `0`        | RAM limit (0 = unlimited) |\n| `-s` | `MEDIAPROC_SWAP`   | `0`        | Swap limit (0 = no swap)  |\n\nThe skill's client side (`scripts/mediaproc.sh`) connects using `MEDIAPROC_HOST` /\n`MEDIAPROC_PORT`, pointing at an instance set up as above. The server-side\nallow-list constrains which commands run, but not who you're trusting — only\npoint `MEDIAPROC_HOST` at a mediaproc instance you or a trusted operator control;\nwhoever runs that instance can see every file transferred through it.\n\n`MEDIAPROC_HOST` is read from the environment at call time with no validation\nbeyond \"does SSH connect\" — treat it like any other trusted config value, not\nuntrusted runtime input. Provision it the same way you'd provision a secret or\na connection string (your shell profile, an env file under your control, your\ndeployment config), not from a value an untrusted caller can set. If something\nelse can inject `MEDIAPROC_HOST` into the environment the skill runs in, it can\nredirect every `put`/`get` and command to a host of its choosing.\n\nFile v2.0.12:skill-card.md\n\n## Description:\n\nProcess media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[psyb0t](https://clawhub.ai/user/psyb0t)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and media-processing operators use this skill to upload media to a trusted mediaproc SSH instance, run allow-listed video, audio, image, and file operations, and retrieve processed outputs.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: A remotely downloaded installer runs with root privileges during setup.\n\nMitigation: Pin the installer to a released tag or commit, inspect it before execution, and prefer checksum or signature verification before running it with sudo.\n\nRisk: Media files and commands are visible to the operator of the configured MEDIAPROC_HOST.\n\nMitigation: Use only a mediaproc instance you control or fully trust, and avoid processing sensitive media on untrusted hosts.\n\nRisk: The SSH wrapper accepts new host keys automatically on first connection.\n\nMitigation: Verify the SSH host key before processing sensitive media or connecting in higher-risk environments.\n\nRisk: Destructive file operations can permanently delete data in the remote work directory.\n\nMitigation: Require explicit confirmation of exact remote paths before remove-file, remove-dir, or remove-dir-recursive commands.\n\n## Reference(s):\n\n- [mediaproc setup](references/setup.md)\n- [docker-mediaproc](https://github.com/psyb0t/docker-mediaproc)\n- [docker-lockbox](https://github.com/psyb0t/docker-lockbox)\n- [docker-mediaproc releases](https://github.com/psyb0t/docker-mediaproc/releases)\n\n## Skill Output:\n\n**Output Type(s):** [Markdown, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown with inline shell commands and command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Commands require ssh plus MEDIAPROC_HOST and MEDIAPROC_PORT pointing to a trusted running mediaproc instance.]\n\n## Skill Version(s):\n\n2.0.12 (source: ClawHub release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment.\n\nArchive v2.0.11: 5 files, 6581 bytes\n\nFiles: references/setup.md (2926b), scripts/mediaproc.sh (548b), skill-card.md (2373b), SKILL.md (8147b), _meta.json (129b)\n\nFile v2.0.11:SKILL.md\n\n---\nname: mediaproc\ndescription: Process media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. Use when the user wants to transcode video, process audio, manipulate images, or work with media files.\ncompatibility: Requires ssh and a running mediaproc instance. MEDIAPROC_HOST and MEDIAPROC_PORT env vars must be set.\nmetadata:\n  author: psyb0t\n  homepage: https://github.com/psyb0t/docker-mediaproc\n---\n\n# mediaproc\n\nLocked-down media processing over SSH. Built on [lockbox](https://github.com/psyb0t/docker-lockbox) — no shell access, no injection, no bullshit.\n\nFor installation and deployment, see [references/setup.md](references/setup.md).\n\n## Security model\n\nmediaproc is **not** a general-purpose shell, and `scripts/mediaproc.sh` is **not**\narbitrary remote code execution even though it forwards a free-form-looking command\nstring. The instance runs inside a [lockbox](https://github.com/psyb0t/docker-lockbox)-\nhardened container, and this skill only ever talks to an instance you (or your\noperator) already run and trust:\n\n- **Key-auth only** — SSH accepts public-key auth only (no passwords), connecting\n  as a restricted user. There is no interactive shell and no PTY.\n- **Server-side enforced allow-list, not documentation** — `scripts/mediaproc.sh`\n  passes its argument through to the SSH channel as-is, but the *remote* lockbox\n  dispatcher is what decides what runs, and it only ever executes the fixed set\n  documented below: `ffmpeg`, `ffprobe`, `sox`, `soxi`, `convert`, `identify`,\n  `magick`, plus lockbox's built-in, scoped file operations. This is an enforced\n  allow-list on the server, not a client-side convention — the wrapper cannot be\n  used to run anything outside that set. Any other command name is refused before\n  execution; the remote never spawns a shell, so there is no shell-injection\n  surface and no way to chain (`;`, `|`, `&&`, backticks, etc.) into a second\n  command.\n- **Work-dir confined** — every path resolves under the instance work directory\n  (`/work`); traversal is blocked. The sandbox cannot read or write your host\n  filesystem.\n- **Consumer-only** — this skill moves files to/from a running instance and runs\n  the whitelisted media tools on them. It never provisions, escalates, or installs\n  anything on your machine (server setup is a separate, operator-side step — see\n  setup.md).\n- **You must still trust the configured host** — `MEDIAPROC_HOST`/`MEDIAPROC_PORT`\n  point at a specific instance. The allow-list constrains *what* runs, not *where*;\n  if `MEDIAPROC_HOST` is pointed at an instance you don't control, that operator\n  still sees every file you `put`/`get` and every command you send. Only point\n  this skill at a mediaproc instance you or a trusted operator run.\n\n## SSH Wrapper\n\nUse `scripts/mediaproc.sh` for all commands. It handles host, port, and host key acceptance via `MEDIAPROC_HOST` and `MEDIAPROC_PORT` env vars.\n\nThe `<command>` argument looks free-form but is not arbitrary execution: the\nwrapper does no shell evaluation of it — it passes the whole string as a single\nargument over the SSH channel — and it is the *remote* lockbox dispatcher that\nenforces the allow-list from the Security model above, server-side, on every\ninvocation. There is no local or remote shell in the loop, so there's no\ninjection/chaining surface (`;`, `|`, `&&`, backticks, etc. are inert; the\ndispatcher just refuses anything that isn't the fixed command name it expects).\n\n```bash\nscripts/mediaproc.sh <command> [args]\nscripts/mediaproc.sh <command> < input_file\nscripts/mediaproc.sh <command> > output_file\n```\n\n## Media Tools\n\n| Command    | Description                                  |\n| ---------- | -------------------------------------------- |\n| `ffmpeg`   | Video/audio encoding, transcoding, filtering |\n| `ffprobe`  | Media file analysis                          |\n| `sox`      | Audio processing                             |\n| `soxi`     | Audio file info                              |\n| `convert`  | Image conversion/manipulation (ImageMagick)  |\n| `identify` | Image file info (ImageMagick)                |\n| `magick`   | ImageMagick CLI                              |\n\n## Upload, Process, Download\n\n```bash\n# Upload\nscripts/mediaproc.sh \"put input.mp4\" < input.mp4\n\n# Transcode\nscripts/mediaproc.sh \"ffmpeg -i /work/input.mp4 -c:v libx264 /work/output.mp4\"\n\n# Download result\nscripts/mediaproc.sh \"get output.mp4\" > output.mp4\n\n# Clean up\nscripts/mediaproc.sh \"remove-file input.mp4\"\nscripts/mediaproc.sh \"remove-file output.mp4\"\n```\n\n## Video Operations\n\n```bash\n# Get video info as JSON\nscripts/mediaproc.sh \"ffprobe -v quiet -print_format json -show_format -show_streams /work/video.mp4\"\n\n# Apply frei0r glow effect\nscripts/mediaproc.sh \"ffmpeg -i /work/in.mp4 -vf frei0r=glow:0.5 /work/out.mp4\"\n\n# Extract audio from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -vn -acodec libmp3lame /work/audio.mp3\"\n\n# Create thumbnail from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -ss 00:00:05 -vframes 1 /work/thumb.jpg\"\n```\n\n## Audio Operations\n\n```bash\n# Convert audio format\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.mp3\"\n\n# Get audio info\nscripts/mediaproc.sh \"soxi /work/audio.wav\"\n\n# Normalize audio\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.wav norm\"\n```\n\n## Image Operations\n\n```bash\n# Resize image\nscripts/mediaproc.sh \"convert /work/input.png -resize 50% /work/output.png\"\n\n# Create thumbnail\nscripts/mediaproc.sh \"convert /work/input.jpg -thumbnail 200x200 /work/thumb.jpg\"\n\n# Get image info\nscripts/mediaproc.sh \"identify /work/image.png\"\n```\n\n## File Operations\n\nAll paths relative to the work directory. Traversal blocked.\n\n**Destructive.** `remove-file`, `remove-dir`, and `remove-dir-recursive`\npermanently delete data in the remote work directory — there is no trash/undo.\n`remove-dir-recursive` deletes an entire subtree in one call and is especially\ndangerous. Only run these after explicit user confirmation of the exact path.\n\n| Command                | Description                        |\n| ---------------------- | ---------------------------------- |\n| `put <path>`           | Upload file from stdin             |\n| `get <path>`           | Download file to stdout            |\n| `list-files [--json]`  | List directory                     |\n| `remove-file <path>`   | Delete a file                      |\n| `create-dir <path>`    | Create directory                   |\n| `remove-dir <path>`    | Remove empty directory             |\n| `remove-dir-recursive <path>` | Remove directory recursively |\n| `move-file <src> <dst>`| Move or rename                     |\n| `copy-file <src> <dst>`| Copy a file                        |\n| `file-info <path>`     | Get file metadata as JSON          |\n| `file-exists <path>`   | Check if file exists (true/false)  |\n| `file-hash <path>`     | Get SHA256 hash                    |\n| `disk-usage [path]`    | Get bytes used                     |\n| `search-files <glob>`  | Glob search                        |\n| `append-file <path>`   | Append stdin to a file             |\n\n```bash\n# List files\nscripts/mediaproc.sh \"list-files\"\n\n# List as JSON (size, modified, isDir, permissions)\nscripts/mediaproc.sh \"list-files --json\"\n\n# List subdirectory\nscripts/mediaproc.sh \"list-files project1\"\n\n# File operations\nscripts/mediaproc.sh \"create-dir project1\"\nscripts/mediaproc.sh \"move-file old.mp4 new.mp4\"\nscripts/mediaproc.sh \"copy-file input.mp4 backup.mp4\"\nscripts/mediaproc.sh \"file-info video.mp4\"\nscripts/mediaproc.sh \"file-exists video.mp4\"\nscripts/mediaproc.sh \"file-hash video.mp4\"\nscripts/mediaproc.sh \"search-files '*.mp4'\"\nscripts/mediaproc.sh \"disk-usage\"\nscripts/mediaproc.sh \"remove-dir-recursive project1\"\n```\n\n## Plugins\n\n- **frei0r** — Video effect plugins (used via `-vf frei0r=...`)\n- **LADSPA** — Audio effect plugins: SWH, TAP, CMT (used via `-af ladspa=...`)\n- **LV2** — Audio plugins (used via `-af lv2=...`)\n\n## Fonts\n\n2200+ fonts included covering emoji, CJK, Arabic, Thai, Indic, monospace, and more. Custom fonts can be mounted to `/usr/share/fonts/custom`.\n\nFile v2.0.11:_meta.json\n\n{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"mediaproc\",\n  \"version\": \"2.0.11\",\n  \"publishedAt\": 1785195550360\n}\n\nFile v2.0.11:references/setup.md\n\n# mediaproc setup\n\n## Quick Install\n\nThe installer creates `~/.mediaproc/` (docker-compose, authorized_keys, work\ndirectory) and drops a `mediaproc` command into `/usr/local/bin`. The container\nit stands up is a [lockbox](https://github.com/psyb0t/docker-lockbox)-hardened\nSSH sandbox (key-auth, whitelisted commands only — see the Security model in\nSKILL.md).\n\nBecause the installer runs as **root**, pin it to a released tag and read it\nbefore running — don't pipe a mutable `main` branch straight into a root shell:\n\n```bash\n# Pick a released tag: https://github.com/psyb0t/docker-mediaproc/releases\nREF=vX.Y.Z\ncurl -fsSL \"https://raw.githubusercontent.com/psyb0t/docker-mediaproc/${REF}/install.sh\" -o install.sh\nless install.sh            # review exactly what runs as root\nsudo bash install.sh\n```\n\n## Starting\n\n```bash\n# Add your SSH key\ncat ~/.ssh/id_rsa.pub >> ~/.mediaproc/authorized_keys\n\n# Basic start (detached)\nmediaproc start -d\n\n# With resource limits\nmediaproc start -d -c 4 -r 4g -s 2g\n\n# Custom port\nmediaproc start -d -p 2223\n\n# Custom fonts directory\nmediaproc start -d -f /path/to/fonts\n```\n\nAll flags persist to `~/.mediaproc/.env` — next `start` reuses the last values.\n\n## Management\n\n```bash\nmediaproc stop                # stop\nmediaproc upgrade             # pull latest image, asks to stop/restart\nmediaproc uninstall           # stop and remove everything\nmediaproc status              # show status\nmediaproc logs                # show container logs\n```\n\n## Configuration\n\n| Flag | Env var            | Default    | Description           |\n| ---- | ------------------ | ---------- | --------------------- |\n| `-p` | `MEDIAPROC_PORT`   | `2222`     | SSH port              |\n| `-f` | `MEDIAPROC_FONTS_DIR` | `./fonts` | Custom fonts directory |\n| `-c` | `MEDIAPROC_CPUS`   | `0`        | CPU limit (0 = unlimited) |\n| `-r` | `MEDIAPROC_MEMORY` | `0`        | RAM limit (0 = unlimited) |\n| `-s` | `MEDIAPROC_SWAP`   | `0`        | Swap limit (0 = no swap)  |\n\nThe skill's client side (`scripts/mediaproc.sh`) connects using `MEDIAPROC_HOST` /\n`MEDIAPROC_PORT`, pointing at an instance set up as above. The server-side\nallow-list constrains which commands run, but not who you're trusting — only\npoint `MEDIAPROC_HOST` at a mediaproc instance you or a trusted operator control;\nwhoever runs that instance can see every file transferred through it.\n\n`MEDIAPROC_HOST` is read from the environment at call time with no validation\nbeyond \"does SSH connect\" — treat it like any other trusted config value, not\nuntrusted runtime input. Provision it the same way you'd provision a secret or\na connection string (your shell profile, an env file under your control, your\ndeployment config), not from a value an untrusted caller can set. If something\nelse can inject `MEDIAPROC_HOST` into the environment the skill runs in, it can\nredirect every `put`/`get` and command to a host of its choosing.\n\nFile v2.0.11:skill-card.md\n\n## Description: <br>\nProcess media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[psyb0t](https://clawhub.ai/user/psyb0t) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, operators, and agents use this skill to upload media to a trusted mediaproc SSH instance, run whitelisted media-processing tools, and download processed files or metadata. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: A misconfigured or untrusted MEDIAPROC_HOST can receive files and commands intended for a trusted mediaproc instance. <br>\nMitigation: Provision MEDIAPROC_HOST and MEDIAPROC_PORT as trusted configuration and do not let untrusted callers set them. <br>\nRisk: The setup flow can involve reviewing and running an installer with elevated privileges. <br>\nMitigation: Pin the installer to a released tag and review the installer before running it as root. <br>\nRisk: Remote delete operations permanently remove files or directories in the mediaproc work directory. <br>\nMitigation: Confirm exact remote paths before running remove-file, remove-dir, or remove-dir-recursive. <br>\n\n\n## Reference(s): <br>\n- [mediaproc setup](references/setup.md) <br>\n- [docker-mediaproc](https://github.com/psyb0t/docker-mediaproc) <br>\n- [docker-lockbox](https://github.com/psyb0t/docker-lockbox) <br>\n- [docker-mediaproc releases](https://github.com/psyb0t/docker-mediaproc/releases) <br>\n- [ClawHub skill page](https://clawhub.ai/psyb0t/skills/mediaproc) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Shell commands, Files, Configuration, Guidance] <br>\n**Output Format:** [Markdown guidance with shell command invocations and streamed file input/output] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires ssh, MEDIAPROC_HOST, MEDIAPROC_PORT, and a trusted running mediaproc instance.] <br>\n\n## Skill Version(s): <br>\n2.0.11 (source: ClawHub release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v2.0.10: 5 files, 6570 bytes\n\nFiles: references/setup.md (2926b), scripts/mediaproc.sh (548b), skill-card.md (2266b), SKILL.md (8147b), _meta.json (129b)\n\nFile v2.0.10:SKILL.md\n\n---\nname: mediaproc\ndescription: Process media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. Use when the user wants to transcode video, process audio, manipulate images, or work with media files.\ncompatibility: Requires ssh and a running mediaproc instance. MEDIAPROC_HOST and MEDIAPROC_PORT env vars must be set.\nmetadata:\n  author: psyb0t\n  homepage: https://github.com/psyb0t/docker-mediaproc\n---\n\n# mediaproc\n\nLocked-down media processing over SSH. Built on [lockbox](https://github.com/psyb0t/docker-lockbox) — no shell access, no injection, no bullshit.\n\nFor installation and deployment, see [references/setup.md](references/setup.md).\n\n## Security model\n\nmediaproc is **not** a general-purpose shell, and `scripts/mediaproc.sh` is **not**\narbitrary remote code execution even though it forwards a free-form-looking command\nstring. The instance runs inside a [lockbox](https://github.com/psyb0t/docker-lockbox)-\nhardened container, and this skill only ever talks to an instance you (or your\noperator) already run and trust:\n\n- **Key-auth only** — SSH accepts public-key auth only (no passwords), connecting\n  as a restricted user. There is no interactive shell and no PTY.\n- **Server-side enforced allow-list, not documentation** — `scripts/mediaproc.sh`\n  passes its argument through to the SSH channel as-is, but the *remote* lockbox\n  dispatcher is what decides what runs, and it only ever executes the fixed set\n  documented below: `ffmpeg`, `ffprobe`, `sox`, `soxi`, `convert`, `identify`,\n  `magick`, plus lockbox's built-in, scoped file operations. This is an enforced\n  allow-list on the server, not a client-side convention — the wrapper cannot be\n  used to run anything outside that set. Any other command name is refused before\n  execution; the remote never spawns a shell, so there is no shell-injection\n  surface and no way to chain (`;`, `|`, `&&`, backticks, etc.) into a second\n  command.\n- **Work-dir confined** — every path resolves under the instance work directory\n  (`/work`); traversal is blocked. The sandbox cannot read or write your host\n  filesystem.\n- **Consumer-only** — this skill moves files to/from a running instance and runs\n  the whitelisted media tools on them. It never provisions, escalates, or installs\n  anything on your machine (server setup is a separate, operator-side step — see\n  setup.md).\n- **You must still trust the configured host** — `MEDIAPROC_HOST`/`MEDIAPROC_PORT`\n  point at a specific instance. The allow-list constrains *what* runs, not *where*;\n  if `MEDIAPROC_HOST` is pointed at an instance you don't control, that operator\n  still sees every file you `put`/`get` and every command you send. Only point\n  this skill at a mediaproc instance you or a trusted operator run.\n\n## SSH Wrapper\n\nUse `scripts/mediaproc.sh` for all commands. It handles host, port, and host key acceptance via `MEDIAPROC_HOST` and `MEDIAPROC_PORT` env vars.\n\nThe `<command>` argument looks free-form but is not arbitrary execution: the\nwrapper does no shell evaluation of it — it passes the whole string as a single\nargument over the SSH channel — and it is the *remote* lockbox dispatcher that\nenforces the allow-list from the Security model above, server-side, on every\ninvocation. There is no local or remote shell in the loop, so there's no\ninjection/chaining surface (`;`, `|`, `&&`, backticks, etc. are inert; the\ndispatcher just refuses anything that isn't the fixed command name it expects).\n\n```bash\nscripts/mediaproc.sh <command> [args]\nscripts/mediaproc.sh <command> < input_file\nscripts/mediaproc.sh <command> > output_file\n```\n\n## Media Tools\n\n| Command    | Description                                  |\n| ---------- | -------------------------------------------- |\n| `ffmpeg`   | Video/audio encoding, transcoding, filtering |\n| `ffprobe`  | Media file analysis                          |\n| `sox`      | Audio processing                             |\n| `soxi`     | Audio file info                              |\n| `convert`  | Image conversion/manipulation (ImageMagick)  |\n| `identify` | Image file info (ImageMagick)                |\n| `magick`   | ImageMagick CLI                              |\n\n## Upload, Process, Download\n\n```bash\n# Upload\nscripts/mediaproc.sh \"put input.mp4\" < input.mp4\n\n# Transcode\nscripts/mediaproc.sh \"ffmpeg -i /work/input.mp4 -c:v libx264 /work/output.mp4\"\n\n# Download result\nscripts/mediaproc.sh \"get output.mp4\" > output.mp4\n\n# Clean up\nscripts/mediaproc.sh \"remove-file input.mp4\"\nscripts/mediaproc.sh \"remove-file output.mp4\"\n```\n\n## Video Operations\n\n```bash\n# Get video info as JSON\nscripts/mediaproc.sh \"ffprobe -v quiet -print_format json -show_format -show_streams /work/video.mp4\"\n\n# Apply frei0r glow effect\nscripts/mediaproc.sh \"ffmpeg -i /work/in.mp4 -vf frei0r=glow:0.5 /work/out.mp4\"\n\n# Extract audio from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -vn -acodec libmp3lame /work/audio.mp3\"\n\n# Create thumbnail from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -ss 00:00:05 -vframes 1 /work/thumb.jpg\"\n```\n\n## Audio Operations\n\n```bash\n# Convert audio format\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.mp3\"\n\n# Get audio info\nscripts/mediaproc.sh \"soxi /work/audio.wav\"\n\n# Normalize audio\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.wav norm\"\n```\n\n## Image Operations\n\n```bash\n# Resize image\nscripts/mediaproc.sh \"convert /work/input.png -resize 50% /work/output.png\"\n\n# Create thumbnail\nscripts/mediaproc.sh \"convert /work/input.jpg -thumbnail 200x200 /work/thumb.jpg\"\n\n# Get image info\nscripts/mediaproc.sh \"identify /work/image.png\"\n```\n\n## File Operations\n\nAll paths relative to the work directory. Traversal blocked.\n\n**Destructive.** `remove-file`, `remove-dir`, and `remove-dir-recursive`\npermanently delete data in the remote work directory — there is no trash/undo.\n`remove-dir-recursive` deletes an entire subtree in one call and is especially\ndangerous. Only run these after explicit user confirmation of the exact path.\n\n| Command                | Description                        |\n| ---------------------- | ---------------------------------- |\n| `put <path>`           | Upload file from stdin             |\n| `get <path>`           | Download file to stdout            |\n| `list-files [--json]`  | List directory                     |\n| `remove-file <path>`   | Delete a file                      |\n| `create-dir <path>`    | Create directory                   |\n| `remove-dir <path>`    | Remove empty directory             |\n| `remove-dir-recursive <path>` | Remove directory recursively |\n| `move-file <src> <dst>`| Move or rename                     |\n| `copy-file <src> <dst>`| Copy a file                        |\n| `file-info <path>`     | Get file metadata as JSON          |\n| `file-exists <path>`   | Check if file exists (true/false)  |\n| `file-hash <path>`     | Get SHA256 hash                    |\n| `disk-usage [path]`    | Get bytes used                     |\n| `search-files <glob>`  | Glob search                        |\n| `append-file <path>`   | Append stdin to a file             |\n\n```bash\n# List files\nscripts/mediaproc.sh \"list-files\"\n\n# List as JSON (size, modified, isDir, permissions)\nscripts/mediaproc.sh \"list-files --json\"\n\n# List subdirectory\nscripts/mediaproc.sh \"list-files project1\"\n\n# File operations\nscripts/mediaproc.sh \"create-dir project1\"\nscripts/mediaproc.sh \"move-file old.mp4 new.mp4\"\nscripts/mediaproc.sh \"copy-file input.mp4 backup.mp4\"\nscripts/mediaproc.sh \"file-info video.mp4\"\nscripts/mediaproc.sh \"file-exists video.mp4\"\nscripts/mediaproc.sh \"file-hash video.mp4\"\nscripts/mediaproc.sh \"search-files '*.mp4'\"\nscripts/mediaproc.sh \"disk-usage\"\nscripts/mediaproc.sh \"remove-dir-recursive project1\"\n```\n\n## Plugins\n\n- **frei0r** — Video effect plugins (used via `-vf frei0r=...`)\n- **LADSPA** — Audio effect plugins: SWH, TAP, CMT (used via `-af ladspa=...`)\n- **LV2** — Audio plugins (used via `-af lv2=...`)\n\n## Fonts\n\n2200+ fonts included covering emoji, CJK, Arabic, Thai, Indic, monospace, and more. Custom fonts can be mounted to `/usr/share/fonts/custom`.\n\nFile v2.0.10:_meta.json\n\n{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"mediaproc\",\n  \"version\": \"2.0.10\",\n  \"publishedAt\": 1785193752592\n}\n\nFile v2.0.10:references/setup.md\n\n# mediaproc setup\n\n## Quick Install\n\nThe installer creates `~/.mediaproc/` (docker-compose, authorized_keys, work\ndirectory) and drops a `mediaproc` command into `/usr/local/bin`. The container\nit stands up is a [lockbox](https://github.com/psyb0t/docker-lockbox)-hardened\nSSH sandbox (key-auth, whitelisted commands only — see the Security model in\nSKILL.md).\n\nBecause the installer runs as **root**, pin it to a released tag and read it\nbefore running — don't pipe a mutable `main` branch straight into a root shell:\n\n```bash\n# Pick a released tag: https://github.com/psyb0t/docker-mediaproc/releases\nREF=vX.Y.Z\ncurl -fsSL \"https://raw.githubusercontent.com/psyb0t/docker-mediaproc/${REF}/install.sh\" -o install.sh\nless install.sh            # review exactly what runs as root\nsudo bash install.sh\n```\n\n## Starting\n\n```bash\n# Add your SSH key\ncat ~/.ssh/id_rsa.pub >> ~/.mediaproc/authorized_keys\n\n# Basic start (detached)\nmediaproc start -d\n\n# With resource limits\nmediaproc start -d -c 4 -r 4g -s 2g\n\n# Custom port\nmediaproc start -d -p 2223\n\n# Custom fonts directory\nmediaproc start -d -f /path/to/fonts\n```\n\nAll flags persist to `~/.mediaproc/.env` — next `start` reuses the last values.\n\n## Management\n\n```bash\nmediaproc stop                # stop\nmediaproc upgrade             # pull latest image, asks to stop/restart\nmediaproc uninstall           # stop and remove everything\nmediaproc status              # show status\nmediaproc logs                # show container logs\n```\n\n## Configuration\n\n| Flag | Env var            | Default    | Description           |\n| ---- | ------------------ | ---------- | --------------------- |\n| `-p` | `MEDIAPROC_PORT`   | `2222`     | SSH port              |\n| `-f` | `MEDIAPROC_FONTS_DIR` | `./fonts` | Custom fonts directory |\n| `-c` | `MEDIAPROC_CPUS`   | `0`        | CPU limit (0 = unlimited) |\n| `-r` | `MEDIAPROC_MEMORY` | `0`        | RAM limit (0 = unlimited) |\n| `-s` | `MEDIAPROC_SWAP`   | `0`        | Swap limit (0 = no swap)  |\n\nThe skill's client side (`scripts/mediaproc.sh`) connects using `MEDIAPROC_HOST` /\n`MEDIAPROC_PORT`, pointing at an instance set up as above. The server-side\nallow-list constrains which commands run, but not who you're trusting — only\npoint `MEDIAPROC_HOST` at a mediaproc instance you or a trusted operator control;\nwhoever runs that instance can see every file transferred through it.\n\n`MEDIAPROC_HOST` is read from the environment at call time with no validation\nbeyond \"does SSH connect\" — treat it like any other trusted config value, not\nuntrusted runtime input. Provision it the same way you'd provision a secret or\na connection string (your shell profile, an env file under your control, your\ndeployment config), not from a value an untrusted caller can set. If something\nelse can inject `MEDIAPROC_HOST` into the environment the skill runs in, it can\nredirect every `put`/`get` and command to a host of its choosing.\n\nFile v2.0.10:skill-card.md\n\n## Description: <br>\nProcess media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[psyb0t](https://clawhub.ai/user/psyb0t) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and media operators use this skill to upload, inspect, transcode, filter, and retrieve media files through a trusted mediaproc SSH instance. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Files and commands are sent to the configured remote mediaproc host, so an untrusted host can observe transferred media and requested operations. <br>\nMitigation: Set MEDIAPROC_HOST from trusted configuration and connect only to an instance operated by the user or an explicitly trusted operator. <br>\nRisk: The setup flow can involve running a server installer as root. <br>\nMitigation: Pin the installer to a released tag and review it before execution. <br>\nRisk: Remote delete commands can permanently remove files from the instance work directory. <br>\nMitigation: Confirm exact paths with the user before using remove-file, remove-dir, or remove-dir-recursive. <br>\n\n\n## Reference(s): <br>\n- [mediaproc setup](references/setup.md) <br>\n- [docker-mediaproc](https://github.com/psyb0t/docker-mediaproc) <br>\n- [docker-lockbox](https://github.com/psyb0t/docker-lockbox) <br>\n- [docker-mediaproc releases](https://github.com/psyb0t/docker-mediaproc/releases) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, code, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown with inline shell commands and media-processing command examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May produce or retrieve media files through the configured mediaproc instance.] <br>\n\n## Skill Version(s): <br>\n2.0.10 (source: server release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v2.0.9: 5 files, 6564 bytes\n\nFiles: references/setup.md (2926b), scripts/mediaproc.sh (548b), skill-card.md (2255b), SKILL.md (8147b), _meta.json (128b)\n\nFile v2.0.9:SKILL.md\n\n---\nname: mediaproc\ndescription: Process media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. Use when the user wants to transcode video, process audio, manipulate images, or work with media files.\ncompatibility: Requires ssh and a running mediaproc instance. MEDIAPROC_HOST and MEDIAPROC_PORT env vars must be set.\nmetadata:\n  author: psyb0t\n  homepage: https://github.com/psyb0t/docker-mediaproc\n---\n\n# mediaproc\n\nLocked-down media processing over SSH. Built on [lockbox](https://github.com/psyb0t/docker-lockbox) — no shell access, no injection, no bullshit.\n\nFor installation and deployment, see [references/setup.md](references/setup.md).\n\n## Security model\n\nmediaproc is **not** a general-purpose shell, and `scripts/mediaproc.sh` is **not**\narbitrary remote code execution even though it forwards a free-form-looking command\nstring. The instance runs inside a [lockbox](https://github.com/psyb0t/docker-lockbox)-\nhardened container, and this skill only ever talks to an instance you (or your\noperator) already run and trust:\n\n- **Key-auth only** — SSH accepts public-key auth only (no passwords), connecting\n  as a restricted user. There is no interactive shell and no PTY.\n- **Server-side enforced allow-list, not documentation** — `scripts/mediaproc.sh`\n  passes its argument through to the SSH channel as-is, but the *remote* lockbox\n  dispatcher is what decides what runs, and it only ever executes the fixed set\n  documented below: `ffmpeg`, `ffprobe`, `sox`, `soxi`, `convert`, `identify`,\n  `magick`, plus lockbox's built-in, scoped file operations. This is an enforced\n  allow-list on the server, not a client-side convention — the wrapper cannot be\n  used to run anything outside that set. Any other command name is refused before\n  execution; the remote never spawns a shell, so there is no shell-injection\n  surface and no way to chain (`;`, `|`, `&&`, backticks, etc.) into a second\n  command.\n- **Work-dir confined** — every path resolves under the instance work directory\n  (`/work`); traversal is blocked. The sandbox cannot read or write your host\n  filesystem.\n- **Consumer-only** — this skill moves files to/from a running instance and runs\n  the whitelisted media tools on them. It never provisions, escalates, or installs\n  anything on your machine (server setup is a separate, operator-side step — see\n  setup.md).\n- **You must still trust the configured host** — `MEDIAPROC_HOST`/`MEDIAPROC_PORT`\n  point at a specific instance. The allow-list constrains *what* runs, not *where*;\n  if `MEDIAPROC_HOST` is pointed at an instance you don't control, that operator\n  still sees every file you `put`/`get` and every command you send. Only point\n  this skill at a mediaproc instance you or a trusted operator run.\n\n## SSH Wrapper\n\nUse `scripts/mediaproc.sh` for all commands. It handles host, port, and host key acceptance via `MEDIAPROC_HOST` and `MEDIAPROC_PORT` env vars.\n\nThe `<command>` argument looks free-form but is not arbitrary execution: the\nwrapper does no shell evaluation of it — it passes the whole string as a single\nargument over the SSH channel — and it is the *remote* lockbox dispatcher that\nenforces the allow-list from the Security model above, server-side, on every\ninvocation. There is no local or remote shell in the loop, so there's no\ninjection/chaining surface (`;`, `|`, `&&`, backticks, etc. are inert; the\ndispatcher just refuses anything that isn't the fixed command name it expects).\n\n```bash\nscripts/mediaproc.sh <command> [args]\nscripts/mediaproc.sh <command> < input_file\nscripts/mediaproc.sh <command> > output_file\n```\n\n## Media Tools\n\n| Command    | Description                                  |\n| ---------- | -------------------------------------------- |\n| `ffmpeg`   | Video/audio encoding, transcoding, filtering |\n| `ffprobe`  | Media file analysis                          |\n| `sox`      | Audio processing                             |\n| `soxi`     | Audio file info                              |\n| `convert`  | Image conversion/manipulation (ImageMagick)  |\n| `identify` | Image file info (ImageMagick)                |\n| `magick`   | ImageMagick CLI                              |\n\n## Upload, Process, Download\n\n```bash\n# Upload\nscripts/mediaproc.sh \"put input.mp4\" < input.mp4\n\n# Transcode\nscripts/mediaproc.sh \"ffmpeg -i /work/input.mp4 -c:v libx264 /work/output.mp4\"\n\n# Download result\nscripts/mediaproc.sh \"get output.mp4\" > output.mp4\n\n# Clean up\nscripts/mediaproc.sh \"remove-file input.mp4\"\nscripts/mediaproc.sh \"remove-file output.mp4\"\n```\n\n## Video Operations\n\n```bash\n# Get video info as JSON\nscripts/mediaproc.sh \"ffprobe -v quiet -print_format json -show_format -show_streams /work/video.mp4\"\n\n# Apply frei0r glow effect\nscripts/mediaproc.sh \"ffmpeg -i /work/in.mp4 -vf frei0r=glow:0.5 /work/out.mp4\"\n\n# Extract audio from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -vn -acodec libmp3lame /work/audio.mp3\"\n\n# Create thumbnail from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -ss 00:00:05 -vframes 1 /work/thumb.jpg\"\n```\n\n## Audio Operations\n\n```bash\n# Convert audio format\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.mp3\"\n\n# Get audio info\nscripts/mediaproc.sh \"soxi /work/audio.wav\"\n\n# Normalize audio\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.wav norm\"\n```\n\n## Image Operations\n\n```bash\n# Resize image\nscripts/mediaproc.sh \"convert /work/input.png -resize 50% /work/output.png\"\n\n# Create thumbnail\nscripts/mediaproc.sh \"convert /work/input.jpg -thumbnail 200x200 /work/thumb.jpg\"\n\n# Get image info\nscripts/mediaproc.sh \"identify /work/image.png\"\n```\n\n## File Operations\n\nAll paths relative to the work directory. Traversal blocked.\n\n**Destructive.** `remove-file`, `remove-dir`, and `remove-dir-recursive`\npermanently delete data in the remote work directory — there is no trash/undo.\n`remove-dir-recursive` deletes an entire subtree in one call and is especially\ndangerous. Only run these after explicit user confirmation of the exact path.\n\n| Command                | Description                        |\n| ---------------------- | ---------------------------------- |\n| `put <path>`           | Upload file from stdin             |\n| `get <path>`           | Download file to stdout            |\n| `list-files [--json]`  | List directory                     |\n| `remove-file <path>`   | Delete a file                      |\n| `create-dir <path>`    | Create directory                   |\n| `remove-dir <path>`    | Remove empty directory             |\n| `remove-dir-recursive <path>` | Remove directory recursively |\n| `move-file <src> <dst>`| Move or rename                     |\n| `copy-file <src> <dst>`| Copy a file                        |\n| `file-info <path>`     | Get file metadata as JSON          |\n| `file-exists <path>`   | Check if file exists (true/false)  |\n| `file-hash <path>`     | Get SHA256 hash                    |\n| `disk-usage [path]`    | Get bytes used                     |\n| `search-files <glob>`  | Glob search                        |\n| `append-file <path>`   | Append stdin to a file             |\n\n```bash\n# List files\nscripts/mediaproc.sh \"list-files\"\n\n# List as JSON (size, modified, isDir, permissions)\nscripts/mediaproc.sh \"list-files --json\"\n\n# List subdirectory\nscripts/mediaproc.sh \"list-files project1\"\n\n# File operations\nscripts/mediaproc.sh \"create-dir project1\"\nscripts/mediaproc.sh \"move-file old.mp4 new.mp4\"\nscripts/mediaproc.sh \"copy-file input.mp4 backup.mp4\"\nscripts/mediaproc.sh \"file-info video.mp4\"\nscripts/mediaproc.sh \"file-exists video.mp4\"\nscripts/mediaproc.sh \"file-hash video.mp4\"\nscripts/mediaproc.sh \"search-files '*.mp4'\"\nscripts/mediaproc.sh \"disk-usage\"\nscripts/mediaproc.sh \"remove-dir-recursive project1\"\n```\n\n## Plugins\n\n- **frei0r** — Video effect plugins (used via `-vf frei0r=...`)\n- **LADSPA** — Audio effect plugins: SWH, TAP, CMT (used via `-af ladspa=...`)\n- **LV2** — Audio plugins (used via `-af lv2=...`)\n\n## Fonts\n\n2200+ fonts included covering emoji, CJK, Arabic, Thai, Indic, monospace, and more. Custom fonts can be mounted to `/usr/share/fonts/custom`.\n\nFile v2.0.9:_meta.json\n\n{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"mediaproc\",\n  \"version\": \"2.0.9\",\n  \"publishedAt\": 1785165521335\n}\n\nFile v2.0.9:references/setup.md\n\n# mediaproc setup\n\n## Quick Install\n\nThe installer creates `~/.mediaproc/` (docker-compose, authorized_keys, work\ndirectory) and drops a `mediaproc` command into `/usr/local/bin`. The container\nit stands up is a [lockbox](https://github.com/psyb0t/docker-lockbox)-hardened\nSSH sandbox (key-auth, whitelisted commands only — see the Security model in\nSKILL.md).\n\nBecause the installer runs as **root**, pin it to a released tag and read it\nbefore running — don't pipe a mutable `main` branch straight into a root shell:\n\n```bash\n# Pick a released tag: https://github.com/psyb0t/docker-mediaproc/releases\nREF=vX.Y.Z\ncurl -fsSL \"https://raw.githubusercontent.com/psyb0t/docker-mediaproc/${REF}/install.sh\" -o install.sh\nless install.sh            # review exactly what runs as root\nsudo bash install.sh\n```\n\n## Starting\n\n```bash\n# Add your SSH key\ncat ~/.ssh/id_rsa.pub >> ~/.mediaproc/authorized_keys\n\n# Basic start (detached)\nmediaproc start -d\n\n# With resource limits\nmediaproc start -d -c 4 -r 4g -s 2g\n\n# Custom port\nmediaproc start -d -p 2223\n\n# Custom fonts directory\nmediaproc start -d -f /path/to/fonts\n```\n\nAll flags persist to `~/.mediaproc/.env` — next `start` reuses the last values.\n\n## Management\n\n```bash\nmediaproc stop                # stop\nmediaproc upgrade             # pull latest image, asks to stop/restart\nmediaproc uninstall           # stop and remove everything\nmediaproc status              # show status\nmediaproc logs                # show container logs\n```\n\n## Configuration\n\n| Flag | Env var            | Default    | Description           |\n| ---- | ------------------ | ---------- | --------------------- |\n| `-p` | `MEDIAPROC_PORT`   | `2222`     | SSH port              |\n| `-f` | `MEDIAPROC_FONTS_DIR` | `./fonts` | Custom fonts directory |\n| `-c` | `MEDIAPROC_CPUS`   | `0`        | CPU limit (0 = unlimited) |\n| `-r` | `MEDIAPROC_MEMORY` | `0`        | RAM limit (0 = unlimited) |\n| `-s` | `MEDIAPROC_SWAP`   | `0`        | Swap limit (0 = no swap)  |\n\nThe skill's client side (`scripts/mediaproc.sh`) connects using `MEDIAPROC_HOST` /\n`MEDIAPROC_PORT`, pointing at an instance set up as above. The server-side\nallow-list constrains which commands run, but not who you're trusting — only\npoint `MEDIAPROC_HOST` at a mediaproc instance you or a trusted operator control;\nwhoever runs that instance can see every file transferred through it.\n\n`MEDIAPROC_HOST` is read from the environment at call time with no validation\nbeyond \"does SSH connect\" — treat it like any other trusted config value, not\nuntrusted runtime input. Provision it the same way you'd provision a secret or\na connection string (your shell profile, an env file under your control, your\ndeployment config), not from a value an untrusted caller can set. If something\nelse can inject `MEDIAPROC_HOST` into the environment the skill runs in, it can\nredirect every `put`/`get` and command to a host of its choosing.\n\nFile v2.0.9:skill-card.md\n\n## Description: <br>\nProcess media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[psyb0t](https://clawhub.ai/user/psyb0t) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and media-processing users use this skill to upload media to a trusted mediaproc SSH host, run allowed ffmpeg, sox, and ImageMagick operations, and retrieve the processed files. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Media files and commands are sent to the configured mediaproc host, so an untrusted host operator could access uploaded content. <br>\nMitigation: Use only a mediaproc host you control or explicitly trust, and keep MEDIAPROC_HOST from untrusted input. <br>\nRisk: Remote delete commands can permanently remove files or directories in the mediaproc work directory. <br>\nMitigation: Confirm the exact remote path before using remove-file, remove-dir, or remove-dir-recursive. <br>\nRisk: The setup flow includes running an installer with elevated privileges. <br>\nMitigation: Pin the installer to a released tag and review it before running it as root. <br>\n\n\n## Reference(s): <br>\n- [mediaproc setup](references/setup.md) <br>\n- [docker-mediaproc](https://github.com/psyb0t/docker-mediaproc) <br>\n- [docker-mediaproc releases](https://github.com/psyb0t/docker-mediaproc/releases) <br>\n- [docker-lockbox](https://github.com/psyb0t/docker-lockbox) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Shell commands, Guidance, Configuration] <br>\n**Output Format:** [Markdown with shell command examples and setup guidance] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires ssh plus MEDIAPROC_HOST and MEDIAPROC_PORT pointing to a trusted mediaproc host.] <br>\n\n## Skill Version(s): <br>\n2.0.9 (source: ClawHub release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v2.0.8: 5 files, 6555 bytes\n\nFiles: references/setup.md (2926b), scripts/mediaproc.sh (548b), skill-card.md (2172b), SKILL.md (8147b), _meta.json (128b)\n\nFile v2.0.8:SKILL.md\n\n---\nname: mediaproc\ndescription: Process media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. Use when the user wants to transcode video, process audio, manipulate images, or work with media files.\ncompatibility: Requires ssh and a running mediaproc instance. MEDIAPROC_HOST and MEDIAPROC_PORT env vars must be set.\nmetadata:\n  author: psyb0t\n  homepage: https://github.com/psyb0t/docker-mediaproc\n---\n\n# mediaproc\n\nLocked-down media processing over SSH. Built on [lockbox](https://github.com/psyb0t/docker-lockbox) — no shell access, no injection, no bullshit.\n\nFor installation and deployment, see [references/setup.md](references/setup.md).\n\n## Security model\n\nmediaproc is **not** a general-purpose shell, and `scripts/mediaproc.sh` is **not**\narbitrary remote code execution even though it forwards a free-form-looking command\nstring. The instance runs inside a [lockbox](https://github.com/psyb0t/docker-lockbox)-\nhardened container, and this skill only ever talks to an instance you (or your\noperator) already run and trust:\n\n- **Key-auth only** — SSH accepts public-key auth only (no passwords), connecting\n  as a restricted user. There is no interactive shell and no PTY.\n- **Server-side enforced allow-list, not documentation** — `scripts/mediaproc.sh`\n  passes its argument through to the SSH channel as-is, but the *remote* lockbox\n  dispatcher is what decides what runs, and it only ever executes the fixed set\n  documented below: `ffmpeg`, `ffprobe`, `sox`, `soxi`, `convert`, `identify`,\n  `magick`, plus lockbox's built-in, scoped file operations. This is an enforced\n  allow-list on the server, not a client-side convention — the wrapper cannot be\n  used to run anything outside that set. Any other command name is refused before\n  execution; the remote never spawns a shell, so there is no shell-injection\n  surface and no way to chain (`;`, `|`, `&&`, backticks, etc.) into a second\n  command.\n- **Work-dir confined** — every path resolves under the instance work directory\n  (`/work`); traversal is blocked. The sandbox cannot read or write your host\n  filesystem.\n- **Consumer-only** — this skill moves files to/from a running instance and runs\n  the whitelisted media tools on them. It never provisions, escalates, or installs\n  anything on your machine (server setup is a separate, operator-side step — see\n  setup.md).\n- **You must still trust the configured host** — `MEDIAPROC_HOST`/`MEDIAPROC_PORT`\n  point at a specific instance. The allow-list constrains *what* runs, not *where*;\n  if `MEDIAPROC_HOST` is pointed at an instance you don't control, that operator\n  still sees every file you `put`/`get` and every command you send. Only point\n  this skill at a mediaproc instance you or a trusted operator run.\n\n## SSH Wrapper\n\nUse `scripts/mediaproc.sh` for all commands. It handles host, port, and host key acceptance via `MEDIAPROC_HOST` and `MEDIAPROC_PORT` env vars.\n\nThe `<command>` argument looks free-form but is not arbitrary execution: the\nwrapper does no shell evaluation of it — it passes the whole string as a single\nargument over the SSH channel — and it is the *remote* lockbox dispatcher that\nenforces the allow-list from the Security model above, server-side, on every\ninvocation. There is no local or remote shell in the loop, so there's no\ninjection/chaining surface (`;`, `|`, `&&`, backticks, etc. are inert; the\ndispatcher just refuses anything that isn't the fixed command name it expects).\n\n```bash\nscripts/mediaproc.sh <command> [args]\nscripts/mediaproc.sh <command> < input_file\nscripts/mediaproc.sh <command> > output_file\n```\n\n## Media Tools\n\n| Command    | Description                                  |\n| ---------- | -------------------------------------------- |\n| `ffmpeg`   | Video/audio encoding, transcoding, filtering |\n| `ffprobe`  | Media file analysis                          |\n| `sox`      | Audio processing                             |\n| `soxi`     | Audio file info                              |\n| `convert`  | Image conversion/manipulation (ImageMagick)  |\n| `identify` | Image file info (ImageMagick)                |\n| `magick`   | ImageMagick CLI                              |\n\n## Upload, Process, Download\n\n```bash\n# Upload\nscripts/mediaproc.sh \"put input.mp4\" < input.mp4\n\n# Transcode\nscripts/mediaproc.sh \"ffmpeg -i /work/input.mp4 -c:v libx264 /work/output.mp4\"\n\n# Download result\nscripts/mediaproc.sh \"get output.mp4\" > output.mp4\n\n# Clean up\nscripts/mediaproc.sh \"remove-file input.mp4\"\nscripts/mediaproc.sh \"remove-file output.mp4\"\n```\n\n## Video Operations\n\n```bash\n# Get video info as JSON\nscripts/mediaproc.sh \"ffprobe -v quiet -print_format json -show_format -show_streams /work/video.mp4\"\n\n# Apply frei0r glow effect\nscripts/mediaproc.sh \"ffmpeg -i /work/in.mp4 -vf frei0r=glow:0.5 /work/out.mp4\"\n\n# Extract audio from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -vn -acodec libmp3lame /work/audio.mp3\"\n\n# Create thumbnail from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -ss 00:00:05 -vframes 1 /work/thumb.jpg\"\n```\n\n## Audio Operations\n\n```bash\n# Convert audio format\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.mp3\"\n\n# Get audio info\nscripts/mediaproc.sh \"soxi /work/audio.wav\"\n\n# Normalize audio\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.wav norm\"\n```\n\n## Image Operations\n\n```bash\n# Resize image\nscripts/mediaproc.sh \"convert /work/input.png -resize 50% /work/output.png\"\n\n# Create thumbnail\nscripts/mediaproc.sh \"convert /work/input.jpg -thumbnail 200x200 /work/thumb.jpg\"\n\n# Get image info\nscripts/mediaproc.sh \"identify /work/image.png\"\n```\n\n## File Operations\n\nAll paths relative to the work directory. Traversal blocked.\n\n**Destructive.** `remove-file`, `remove-dir`, and `remove-dir-recursive`\npermanently delete data in the remote work directory — there is no trash/undo.\n`remove-dir-recursive` deletes an entire subtree in one call and is especially\ndangerous. Only run these after explicit user confirmation of the exact path.\n\n| Command                | Description                        |\n| ---------------------- | ---------------------------------- |\n| `put <path>`           | Upload file from stdin             |\n| `get <path>`           | Download file to stdout            |\n| `list-files [--json]`  | List directory                     |\n| `remove-file <path>`   | Delete a file                      |\n| `create-dir <path>`    | Create directory                   |\n| `remove-dir <path>`    | Remove empty directory             |\n| `remove-dir-recursive <path>` | Remove directory recursively |\n| `move-file <src> <dst>`| Move or rename                     |\n| `copy-file <src> <dst>`| Copy a file                        |\n| `file-info <path>`     | Get file metadata as JSON          |\n| `file-exists <path>`   | Check if file exists (true/false)  |\n| `file-hash <path>`     | Get SHA256 hash                    |\n| `disk-usage [path]`    | Get bytes used                     |\n| `search-files <glob>`  | Glob search                        |\n| `append-file <path>`   | Append stdin to a file             |\n\n```bash\n# List files\nscripts/mediaproc.sh \"list-files\"\n\n# List as JSON (size, modified, isDir, permissions)\nscripts/mediaproc.sh \"list-files --json\"\n\n# List subdirectory\nscripts/mediaproc.sh \"list-files project1\"\n\n# File operations\nscripts/mediaproc.sh \"create-dir project1\"\nscripts/mediaproc.sh \"move-file old.mp4 new.mp4\"\nscripts/mediaproc.sh \"copy-file input.mp4 backup.mp4\"\nscripts/mediaproc.sh \"file-info video.mp4\"\nscripts/mediaproc.sh \"file-exists video.mp4\"\nscripts/mediaproc.sh \"file-hash video.mp4\"\nscripts/mediaproc.sh \"search-files '*.mp4'\"\nscripts/mediaproc.sh \"disk-usage\"\nscripts/mediaproc.sh \"remove-dir-recursive project1\"\n```\n\n## Plugins\n\n- **frei0r** — Video effect plugins (used via `-vf frei0r=...`)\n- **LADSPA** — Audio effect plugins: SWH, TAP, CMT (used via `-af ladspa=...`)\n- **LV2** — Audio plugins (used via `-af lv2=...`)\n\n## Fonts\n\n2200+ fonts included covering emoji, CJK, Arabic, Thai, Indic, monospace, and more. Custom fonts can be mounted to `/usr/share/fonts/custom`.\n\nFile v2.0.8:_meta.json\n\n{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"mediaproc\",\n  \"version\": \"2.0.8\",\n  \"publishedAt\": 1785158871063\n}\n\nFile v2.0.8:references/setup.md\n\n# mediaproc setup\n\n## Quick Install\n\nThe installer creates `~/.mediaproc/` (docker-compose, authorized_keys, work\ndirectory) and drops a `mediaproc` command into `/usr/local/bin`. The container\nit stands up is a [lockbox](https://github.com/psyb0t/docker-lockbox)-hardened\nSSH sandbox (key-auth, whitelisted commands only — see the Security model in\nSKILL.md).\n\nBecause the installer runs as **root**, pin it to a released tag and read it\nbefore running — don't pipe a mutable `main` branch straight into a root shell:\n\n```bash\n# Pick a released tag: https://github.com/psyb0t/docker-mediaproc/releases\nREF=vX.Y.Z\ncurl -fsSL \"https://raw.githubusercontent.com/psyb0t/docker-mediaproc/${REF}/install.sh\" -o install.sh\nless install.sh            # review exactly what runs as root\nsudo bash install.sh\n```\n\n## Starting\n\n```bash\n# Add your SSH key\ncat ~/.ssh/id_rsa.pub >> ~/.mediaproc/authorized_keys\n\n# Basic start (detached)\nmediaproc start -d\n\n# With resource limits\nmediaproc start -d -c 4 -r 4g -s 2g\n\n# Custom port\nmediaproc start -d -p 2223\n\n# Custom fonts directory\nmediaproc start -d -f /path/to/fonts\n```\n\nAll flags persist to `~/.mediaproc/.env` — next `start` reuses the last values.\n\n## Management\n\n```bash\nmediaproc stop                # stop\nmediaproc upgrade             # pull latest image, asks to stop/restart\nmediaproc uninstall           # stop and remove everything\nmediaproc status              # show status\nmediaproc logs                # show container logs\n```\n\n## Configuration\n\n| Flag | Env var            | Default    | Description           |\n| ---- | ------------------ | ---------- | --------------------- |\n| `-p` | `MEDIAPROC_PORT`   | `2222`     | SSH port              |\n| `-f` | `MEDIAPROC_FONTS_DIR` | `./fonts` | Custom fonts directory |\n| `-c` | `MEDIAPROC_CPUS`   | `0`        | CPU limit (0 = unlimited) |\n| `-r` | `MEDIAPROC_MEMORY` | `0`        | RAM limit (0 = unlimited) |\n| `-s` | `MEDIAPROC_SWAP`   | `0`        | Swap limit (0 = no swap)  |\n\nThe skill's client side (`scripts/mediaproc.sh`) connects using `MEDIAPROC_HOST` /\n`MEDIAPROC_PORT`, pointing at an instance set up as above. The server-side\nallow-list constrains which commands run, but not who you're trusting — only\npoint `MEDIAPROC_HOST` at a mediaproc instance you or a trusted operator control;\nwhoever runs that instance can see every file transferred through it.\n\n`MEDIAPROC_HOST` is read from the environment at call time with no validation\nbeyond \"does SSH connect\" — treat it like any other trusted config value, not\nuntrusted runtime input. Provision it the same way you'd provision a secret or\na connection string (your shell profile, an env file under your control, your\ndeployment config), not from a value an untrusted caller can set. If something\nelse can inject `MEDIAPROC_HOST` into the environment the skill runs in, it can\nredirect every `put`/`get` and command to a host of its choosing.\n\nFile v2.0.8:skill-card.md\n\n## Description: <br>\nProcess media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[psyb0t](https://clawhub.ai/user/psyb0t) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and media workflows use this skill to upload, inspect, transform, and retrieve video, audio, and image files through a configured mediaproc SSH instance. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Files and commands are sent to the configured mediaproc SSH host, so an untrusted host operator could see transferred media and requested operations. <br>\nMitigation: Only set MEDIAPROC_HOST and MEDIAPROC_PORT to an instance you control or a trusted operator runs. <br>\nRisk: Remote remove operations can permanently delete files or directories in the instance work directory. <br>\nMitigation: Confirm the exact target path before using remove-file, remove-dir, or remove-dir-recursive. <br>\nRisk: Server setup can involve running a root-level installer. <br>\nMitigation: Pin the installer to a released tag and review the installer before running it with elevated privileges. <br>\n\n\n## Reference(s): <br>\n- [mediaproc setup](references/setup.md) <br>\n- [mediaproc homepage](https://github.com/psyb0t/docker-mediaproc) <br>\n- [docker-lockbox](https://github.com/psyb0t/docker-lockbox) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Shell commands, Configuration, Guidance] <br>\n**Output Format:** [Markdown with inline bash commands] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Commands assume ssh is available and MEDIAPROC_HOST and MEDIAPROC_PORT point to a trusted mediaproc instance.] <br>\n\n## Skill Version(s): <br>\n2.0.8 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v2.0.7: 5 files, 6650 bytes\n\nFiles: references/setup.md (2926b), scripts/mediaproc.sh (548b), skill-card.md (2513b), SKILL.md (8147b), _meta.json (128b)\n\nFile v2.0.7:SKILL.md\n\n---\nname: mediaproc\ndescription: Process media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. Use when the user wants to transcode video, process audio, manipulate images, or work with media files.\ncompatibility: Requires ssh and a running mediaproc instance. MEDIAPROC_HOST and MEDIAPROC_PORT env vars must be set.\nmetadata:\n  author: psyb0t\n  homepage: https://github.com/psyb0t/docker-mediaproc\n---\n\n# mediaproc\n\nLocked-down media processing over SSH. Built on [lockbox](https://github.com/psyb0t/docker-lockbox) — no shell access, no injection, no bullshit.\n\nFor installation and deployment, see [references/setup.md](references/setup.md).\n\n## Security model\n\nmediaproc is **not** a general-purpose shell, and `scripts/mediaproc.sh` is **not**\narbitrary remote code execution even though it forwards a free-form-looking command\nstring. The instance runs inside a [lockbox](https://github.com/psyb0t/docker-lockbox)-\nhardened container, and this skill only ever talks to an instance you (or your\noperator) already run and trust:\n\n- **Key-auth only** — SSH accepts public-key auth only (no passwords), connecting\n  as a restricted user. There is no interactive shell and no PTY.\n- **Server-side enforced allow-list, not documentation** — `scripts/mediaproc.sh`\n  passes its argument through to the SSH channel as-is, but the *remote* lockbox\n  dispatcher is what decides what runs, and it only ever executes the fixed set\n  documented below: `ffmpeg`, `ffprobe`, `sox`, `soxi`, `convert`, `identify`,\n  `magick`, plus lockbox's built-in, scoped file operations. This is an enforced\n  allow-list on the server, not a client-side convention — the wrapper cannot be\n  used to run anything outside that set. Any other command name is refused before\n  execution; the remote never spawns a shell, so there is no shell-injection\n  surface and no way to chain (`;`, `|`, `&&`, backticks, etc.) into a second\n  command.\n- **Work-dir confined** — every path resolves under the instance work directory\n  (`/work`); traversal is blocked. The sandbox cannot read or write your host\n  filesystem.\n- **Consumer-only** — this skill moves files to/from a running instance and runs\n  the whitelisted media tools on them. It never provisions, escalates, or installs\n  anything on your machine (server setup is a separate, operator-side step — see\n  setup.md).\n- **You must still trust the configured host** — `MEDIAPROC_HOST`/`MEDIAPROC_PORT`\n  point at a specific instance. The allow-list constrains *what* runs, not *where*;\n  if `MEDIAPROC_HOST` is pointed at an instance you don't control, that operator\n  still sees every file you `put`/`get` and every command you send. Only point\n  this skill at a mediaproc instance you or a trusted operator run.\n\n## SSH Wrapper\n\nUse `scripts/mediaproc.sh` for all commands. It handles host, port, and host key acceptance via `MEDIAPROC_HOST` and `MEDIAPROC_PORT` env vars.\n\nThe `<command>` argument looks free-form but is not arbitrary execution: the\nwrapper does no shell evaluation of it — it passes the whole string as a single\nargument over the SSH channel — and it is the *remote* lockbox dispatcher that\nenforces the allow-list from the Security model above, server-side, on every\ninvocation. There is no local or remote shell in the loop, so there's no\ninjection/chaining surface (`;`, `|`, `&&`, backticks, etc. are inert; the\ndispatcher just refuses anything that isn't the fixed command name it expects).\n\n```bash\nscripts/mediaproc.sh <command> [args]\nscripts/mediaproc.sh <command> < input_file\nscripts/mediaproc.sh <command> > output_file\n```\n\n## Media Tools\n\n| Command    | Description                                  |\n| ---------- | -------------------------------------------- |\n| `ffmpeg`   | Video/audio encoding, transcoding, filtering |\n| `ffprobe`  | Media file analysis                          |\n| `sox`      | Audio processing                             |\n| `soxi`     | Audio file info                              |\n| `convert`  | Image conversion/manipulation (ImageMagick)  |\n| `identify` | Image file info (ImageMagick)                |\n| `magick`   | ImageMagick CLI                              |\n\n## Upload, Process, Download\n\n```bash\n# Upload\nscripts/mediaproc.sh \"put input.mp4\" < input.mp4\n\n# Transcode\nscripts/mediaproc.sh \"ffmpeg -i /work/input.mp4 -c:v libx264 /work/output.mp4\"\n\n# Download result\nscripts/mediaproc.sh \"get output.mp4\" > output.mp4\n\n# Clean up\nscripts/mediaproc.sh \"remove-file input.mp4\"\nscripts/mediaproc.sh \"remove-file output.mp4\"\n```\n\n## Video Operations\n\n```bash\n# Get video info as JSON\nscripts/mediaproc.sh \"ffprobe -v quiet -print_format json -show_format -show_streams /work/video.mp4\"\n\n# Apply frei0r glow effect\nscripts/mediaproc.sh \"ffmpeg -i /work/in.mp4 -vf frei0r=glow:0.5 /work/out.mp4\"\n\n# Extract audio from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -vn -acodec libmp3lame /work/audio.mp3\"\n\n# Create thumbnail from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -ss 00:00:05 -vframes 1 /work/thumb.jpg\"\n```\n\n## Audio Operations\n\n```bash\n# Convert audio format\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.mp3\"\n\n# Get audio info\nscripts/mediaproc.sh \"soxi /work/audio.wav\"\n\n# Normalize audio\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.wav norm\"\n```\n\n## Image Operations\n\n```bash\n# Resize image\nscripts/mediaproc.sh \"convert /work/input.png -resize 50% /work/output.png\"\n\n# Create thumbnail\nscripts/mediaproc.sh \"convert /work/input.jpg -thumbnail 200x200 /work/thumb.jpg\"\n\n# Get image info\nscripts/mediaproc.sh \"identify /work/image.png\"\n```\n\n## File Operations\n\nAll paths relative to the work directory. Traversal blocked.\n\n**Destructive.** `remove-file`, `remove-dir`, and `remove-dir-recursive`\npermanently delete data in the remote work directory — there is no trash/undo.\n`remove-dir-recursive` deletes an entire subtree in one call and is especially\ndangerous. Only run these after explicit user confirmation of the exact path.\n\n| Command                | Description                        |\n| ---------------------- | ---------------------------------- |\n| `put <path>`           | Upload file from stdin             |\n| `get <path>`           | Download file to stdout            |\n| `list-files [--json]`  | List directory                     |\n| `remove-file <path>`   | Delete a file                      |\n| `create-dir <path>`    | Create directory                   |\n| `remove-dir <path>`    | Remove empty directory             |\n| `remove-dir-recursive <path>` | Remove directory recursively |\n| `move-file <src> <dst>`| Move or rename                     |\n| `copy-file <src> <dst>`| Copy a file                        |\n| `file-info <path>`     | Get file metadata as JSON          |\n| `file-exists <path>`   | Check if file exists (true/false)  |\n| `file-hash <path>`     | Get SHA256 hash                    |\n| `disk-usage [path]`    | Get bytes used                     |\n| `search-files <glob>`  | Glob search                        |\n| `append-file <path>`   | Append stdin to a file             |\n\n```bash\n# List files\nscripts/mediaproc.sh \"list-files\"\n\n# List as JSON (size, modified, isDir, permissions)\nscripts/mediaproc.sh \"list-files --json\"\n\n# List subdirectory\nscripts/mediaproc.sh \"list-files project1\"\n\n# File operations\nscripts/mediaproc.sh \"create-dir project1\"\nscripts/mediaproc.sh \"move-file old.mp4 new.mp4\"\nscripts/mediaproc.sh \"copy-file input.mp4 backup.mp4\"\nscripts/mediaproc.sh \"file-info video.mp4\"\nscripts/mediaproc.sh \"file-exists video.mp4\"\nscripts/mediaproc.sh \"file-hash video.mp4\"\nscripts/mediaproc.sh \"search-files '*.mp4'\"\nscripts/mediaproc.sh \"disk-usage\"\nscripts/mediaproc.sh \"remove-dir-recursive project1\"\n```\n\n## Plugins\n\n- **frei0r** — Video effect plugins (used via `-vf frei0r=...`)\n- **LADSPA** — Audio effect plugins: SWH, TAP, CMT (used via `-af ladspa=...`)\n- **LV2** — Audio plugins (used via `-af lv2=...`)\n\n## Fonts\n\n2200+ fonts included covering emoji, CJK, Arabic, Thai, Indic, monospace, and more. Custom fonts can be mounted to `/usr/share/fonts/custom`.\n\nFile v2.0.7:_meta.json\n\n{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"mediaproc\",\n  \"version\": \"2.0.7\",\n  \"publishedAt\": 1785058201033\n}\n\nFile v2.0.7:references/setup.md\n\n# mediaproc setup\n\n## Quick Install\n\nThe installer creates `~/.mediaproc/` (docker-compose, authorized_keys, work\ndirectory) and drops a `mediaproc` command into `/usr/local/bin`. The container\nit stands up is a [lockbox](https://github.com/psyb0t/docker-lockbox)-hardened\nSSH sandbox (key-auth, whitelisted commands only — see the Security model in\nSKILL.md).\n\nBecause the installer runs as **root**, pin it to a released tag and read it\nbefore running — don't pipe a mutable `main` branch straight into a root shell:\n\n```bash\n# Pick a released tag: https://github.com/psyb0t/docker-mediaproc/releases\nREF=vX.Y.Z\ncurl -fsSL \"https://raw.githubusercontent.com/psyb0t/docker-mediaproc/${REF}/install.sh\" -o install.sh\nless install.sh            # review exactly what runs as root\nsudo bash install.sh\n```\n\n## Starting\n\n```bash\n# Add your SSH key\ncat ~/.ssh/id_rsa.pub >> ~/.mediaproc/authorized_keys\n\n# Basic start (detached)\nmediaproc start -d\n\n# With resource limits\nmediaproc start -d -c 4 -r 4g -s 2g\n\n# Custom port\nmediaproc start -d -p 2223\n\n# Custom fonts directory\nmediaproc start -d -f /path/to/fonts\n```\n\nAll flags persist to `~/.mediaproc/.env` — next `start` reuses the last values.\n\n## Management\n\n```bash\nmediaproc stop                # stop\nmediaproc upgrade             # pull latest image, asks to stop/restart\nmediaproc uninstall           # stop and remove everything\nmediaproc status              # show status\nmediaproc logs                # show container logs\n```\n\n## Configuration\n\n| Flag | Env var            | Default    | Description           |\n| ---- | ------------------ | ---------- | --------------------- |\n| `-p` | `MEDIAPROC_PORT`   | `2222`     | SSH port              |\n| `-f` | `MEDIAPROC_FONTS_DIR` | `./fonts` | Custom fonts directory |\n| `-c` | `MEDIAPROC_CPUS`   | `0`        | CPU limit (0 = unlimited) |\n| `-r` | `MEDIAPROC_MEMORY` | `0`        | RAM limit (0 = unlimited) |\n| `-s` | `MEDIAPROC_SWAP`   | `0`        | Swap limit (0 = no swap)  |\n\nThe skill's client side (`scripts/mediaproc.sh`) connects using `MEDIAPROC_HOST` /\n`MEDIAPROC_PORT`, pointing at an instance set up as above. The server-side\nallow-list constrains which commands run, but not who you're trusting — only\npoint `MEDIAPROC_HOST` at a mediaproc instance you or a trusted operator control;\nwhoever runs that instance can see every file transferred through it.\n\n`MEDIAPROC_HOST` is read from the environment at call time with no validation\nbeyond \"does SSH connect\" — treat it like any other trusted config value, not\nuntrusted runtime input. Provision it the same way you'd provision a secret or\na connection string (your shell profile, an env file under your control, your\ndeployment config), not from a value an untrusted caller can set. If something\nelse can inject `MEDIAPROC_HOST` into the environment the skill runs in, it can\nredirect every `put`/`get` and command to a host of its choosing.\n\nFile v2.0.7:skill-card.md\n\n## Description: <br>\nProcess media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[psyb0t](https://clawhub.ai/user/psyb0t) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers, operators, and media-focused agents use this skill to upload files to a trusted mediaproc instance, run whitelisted ffmpeg, sox, and ImageMagick operations, and retrieve processed media outputs. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Files and commands are sent to the configured mediaproc SSH host, so a host controlled by an untrusted operator can observe transferred media and requested operations. <br>\nMitigation: Set MEDIAPROC_HOST only to an instance controlled by the user or a trusted operator, and provision that environment value from controlled configuration. <br>\nRisk: The setup flow can involve running a root installer for the mediaproc container host. <br>\nMitigation: Pin the installer to a released tag and review the script before running it with elevated privileges. <br>\nRisk: Remote file deletion commands, especially recursive directory deletion, permanently remove data in the mediaproc work directory. <br>\nMitigation: Confirm the exact target path before running delete or recursive delete operations. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/psyb0t/skills/mediaproc) <br>\n- [Project homepage](https://github.com/psyb0t/docker-mediaproc) <br>\n- [mediaproc releases](https://github.com/psyb0t/docker-mediaproc/releases) <br>\n- [lockbox container hardening](https://github.com/psyb0t/docker-lockbox) <br>\n- [Setup reference](references/setup.md) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with shell command examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Outputs depend on the configured mediaproc SSH instance and the media files transferred through it.] <br>\n\n## Skill Version(s): <br>\n2.0.7 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v2.0.6: 5 files, 6581 bytes\n\nFiles: references/setup.md (2926b), scripts/mediaproc.sh (548b), skill-card.md (2282b), SKILL.md (8147b), _meta.json (128b)\n\nFile v2.0.6:SKILL.md\n\n---\nname: mediaproc\ndescription: Process media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. Use when the user wants to transcode video, process audio, manipulate images, or work with media files.\ncompatibility: Requires ssh and a running mediaproc instance. MEDIAPROC_HOST and MEDIAPROC_PORT env vars must be set.\nmetadata:\n  author: psyb0t\n  homepage: https://github.com/psyb0t/docker-mediaproc\n---\n\n# mediaproc\n\nLocked-down media processing over SSH. Built on [lockbox](https://github.com/psyb0t/docker-lockbox) — no shell access, no injection, no bullshit.\n\nFor installation and deployment, see [references/setup.md](references/setup.md).\n\n## Security model\n\nmediaproc is **not** a general-purpose shell, and `scripts/mediaproc.sh` is **not**\narbitrary remote code execution even though it forwards a free-form-looking command\nstring. The instance runs inside a [lockbox](https://github.com/psyb0t/docker-lockbox)-\nhardened container, and this skill only ever talks to an instance you (or your\noperator) already run and trust:\n\n- **Key-auth only** — SSH accepts public-key auth only (no passwords), connecting\n  as a restricted user. There is no interactive shell and no PTY.\n- **Server-side enforced allow-list, not documentation** — `scripts/mediaproc.sh`\n  passes its argument through to the SSH channel as-is, but the *remote* lockbox\n  dispatcher is what decides what runs, and it only ever executes the fixed set\n  documented below: `ffmpeg`, `ffprobe`, `sox`, `soxi`, `convert`, `identify`,\n  `magick`, plus lockbox's built-in, scoped file operations. This is an enforced\n  allow-list on the server, not a client-side convention — the wrapper cannot be\n  used to run anything outside that set. Any other command name is refused before\n  execution; the remote never spawns a shell, so there is no shell-injection\n  surface and no way to chain (`;`, `|`, `&&`, backticks, etc.) into a second\n  command.\n- **Work-dir confined** — every path resolves under the instance work directory\n  (`/work`); traversal is blocked. The sandbox cannot read or write your host\n  filesystem.\n- **Consumer-only** — this skill moves files to/from a running instance and runs\n  the whitelisted media tools on them. It never provisions, escalates, or installs\n  anything on your machine (server setup is a separate, operator-side step — see\n  setup.md).\n- **You must still trust the configured host** — `MEDIAPROC_HOST`/`MEDIAPROC_PORT`\n  point at a specific instance. The allow-list constrains *what* runs, not *where*;\n  if `MEDIAPROC_HOST` is pointed at an instance you don't control, that operator\n  still sees every file you `put`/`get` and every command you send. Only point\n  this skill at a mediaproc instance you or a trusted operator run.\n\n## SSH Wrapper\n\nUse `scripts/mediaproc.sh` for all commands. It handles host, port, and host key acceptance via `MEDIAPROC_HOST` and `MEDIAPROC_PORT` env vars.\n\nThe `<command>` argument looks free-form but is not arbitrary execution: the\nwrapper does no shell evaluation of it — it passes the whole string as a single\nargument over the SSH channel — and it is the *remote* lockbox dispatcher that\nenforces the allow-list from the Security model above, server-side, on every\ninvocation. There is no local or remote shell in the loop, so there's no\ninjection/chaining surface (`;`, `|`, `&&`, backticks, etc. are inert; the\ndispatcher just refuses anything that isn't the fixed command name it expects).\n\n```bash\nscripts/mediaproc.sh <command> [args]\nscripts/mediaproc.sh <command> < input_file\nscripts/mediaproc.sh <command> > output_file\n```\n\n## Media Tools\n\n| Command    | Description                                  |\n| ---------- | -------------------------------------------- |\n| `ffmpeg`   | Video/audio encoding, transcoding, filtering |\n| `ffprobe`  | Media file analysis                          |\n| `sox`      | Audio processing                             |\n| `soxi`     | Audio file info                              |\n| `convert`  | Image conversion/manipulation (ImageMagick)  |\n| `identify` | Image file info (ImageMagick)                |\n| `magick`   | ImageMagick CLI                              |\n\n## Upload, Process, Download\n\n```bash\n# Upload\nscripts/mediaproc.sh \"put input.mp4\" < input.mp4\n\n# Transcode\nscripts/mediaproc.sh \"ffmpeg -i /work/input.mp4 -c:v libx264 /work/output.mp4\"\n\n# Download result\nscripts/mediaproc.sh \"get output.mp4\" > output.mp4\n\n# Clean up\nscripts/mediaproc.sh \"remove-file input.mp4\"\nscripts/mediaproc.sh \"remove-file output.mp4\"\n```\n\n## Video Operations\n\n```bash\n# Get video info as JSON\nscripts/mediaproc.sh \"ffprobe -v quiet -print_format json -show_format -show_streams /work/video.mp4\"\n\n# Apply frei0r glow effect\nscripts/mediaproc.sh \"ffmpeg -i /work/in.mp4 -vf frei0r=glow:0.5 /work/out.mp4\"\n\n# Extract audio from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -vn -acodec libmp3lame /work/audio.mp3\"\n\n# Create thumbnail from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -ss 00:00:05 -vframes 1 /work/thumb.jpg\"\n```\n\n## Audio Operations\n\n```bash\n# Convert audio format\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.mp3\"\n\n# Get audio info\nscripts/mediaproc.sh \"soxi /work/audio.wav\"\n\n# Normalize audio\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.wav norm\"\n```\n\n## Image Operations\n\n```bash\n# Resize image\nscripts/mediaproc.sh \"convert /work/input.png -resize 50% /work/output.png\"\n\n# Create thumbnail\nscripts/mediaproc.sh \"convert /work/input.jpg -thumbnail 200x200 /work/thumb.jpg\"\n\n# Get image info\nscripts/mediaproc.sh \"identify /work/image.png\"\n```\n\n## File Operations\n\nAll paths relative to the work directory. Traversal blocked.\n\n**Destructive.** `remove-file`, `remove-dir`, and `remove-dir-recursive`\npermanently delete data in the remote work directory — there is no trash/undo.\n`remove-dir-recursive` deletes an entire subtree in one call and is especially\ndangerous. Only run these after explicit user confirmation of the exact path.\n\n| Command                | Description                        |\n| ---------------------- | ---------------------------------- |\n| `put <path>`           | Upload file from stdin             |\n| `get <path>`           | Download file to stdout            |\n| `list-files [--json]`  | List directory                     |\n| `remove-file <path>`   | Delete a file                      |\n| `create-dir <path>`    | Create directory                   |\n| `remove-dir <path>`    | Remove empty directory             |\n| `remove-dir-recursive <path>` | Remove directory recursively |\n| `move-file <src> <dst>`| Move or rename                     |\n| `copy-file <src> <dst>`| Copy a file                        |\n| `file-info <path>`     | Get file metadata as JSON          |\n| `file-exists <path>`   | Check if file exists (true/false)  |\n| `file-hash <path>`     | Get SHA256 hash                    |\n| `disk-usage [path]`    | Get bytes used                     |\n| `search-files <glob>`  | Glob search                        |\n| `append-file <path>`   | Append stdin to a file             |\n\n```bash\n# List files\nscripts/mediaproc.sh \"list-files\"\n\n# List as JSON (size, modified, isDir, permissions)\nscripts/mediaproc.sh \"list-files --json\"\n\n# List subdirectory\nscripts/mediaproc.sh \"list-files project1\"\n\n# File operations\nscripts/mediaproc.sh \"create-dir project1\"\nscripts/mediaproc.sh \"move-file old.mp4 new.mp4\"\nscripts/mediaproc.sh \"copy-file input.mp4 backup.mp4\"\nscripts/mediaproc.sh \"file-info video.mp4\"\nscripts/mediaproc.sh \"file-exists video.mp4\"\nscripts/mediaproc.sh \"file-hash video.mp4\"\nscripts/mediaproc.sh \"search-files '*.mp4'\"\nscripts/mediaproc.sh \"disk-usage\"\nscripts/mediaproc.sh \"remove-dir-recursive project1\"\n```\n\n## Plugins\n\n- **frei0r** — Video effect plugins (used via `-vf frei0r=...`)\n- **LADSPA** — Audio effect plugins: SWH, TAP, CMT (used via `-af ladspa=...`)\n- **LV2** — Audio plugins (used via `-af lv2=...`)\n\n## Fonts\n\n2200+ fonts included covering emoji, CJK, Arabic, Thai, Indic, monospace, and more. Custom fonts can be mounted to `/usr/share/fonts/custom`.\n\nFile v2.0.6:_meta.json\n\n{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"mediaproc\",\n  \"version\": \"2.0.6\",\n  \"publishedAt\": 1785021708216\n}\n\nFile v2.0.6:references/setup.md\n\n# mediaproc setup\n\n## Quick Install\n\nThe installer creates `~/.mediaproc/` (docker-compose, authorized_keys, work\ndirectory) and drops a `mediaproc` command into `/usr/local/bin`. The container\nit stands up is a [lockbox](https://github.com/psyb0t/docker-lockbox)-hardened\nSSH sandbox (key-auth, whitelisted commands only — see the Security model in\nSKILL.md).\n\nBecause the installer runs as **root**, pin it to a released tag and read it\nbefore running — don't pipe a mutable `main` branch straight into a root shell:\n\n```bash\n# Pick a released tag: https://github.com/psyb0t/docker-mediaproc/releases\nREF=vX.Y.Z\ncurl -fsSL \"https://raw.githubusercontent.com/psyb0t/docker-mediaproc/${REF}/install.sh\" -o install.sh\nless install.sh            # review exactly what runs as root\nsudo bash install.sh\n```\n\n## Starting\n\n```bash\n# Add your SSH key\ncat ~/.ssh/id_rsa.pub >> ~/.mediaproc/authorized_keys\n\n# Basic start (detached)\nmediaproc start -d\n\n# With resource limits\nmediaproc start -d -c 4 -r 4g -s 2g\n\n# Custom port\nmediaproc start -d -p 2223\n\n# Custom fonts directory\nmediaproc start -d -f /path/to/fonts\n```\n\nAll flags persist to `~/.mediaproc/.env` — next `start` reuses the last values.\n\n## Management\n\n```bash\nmediaproc stop                # stop\nmediaproc upgrade             # pull latest image, asks to stop/restart\nmediaproc uninstall           # stop and remove everything\nmediaproc status              # show status\nmediaproc logs                # show container logs\n```\n\n## Configuration\n\n| Flag | Env var            | Default    | Description           |\n| ---- | ------------------ | ---------- | --------------------- |\n| `-p` | `MEDIAPROC_PORT`   | `2222`     | SSH port              |\n| `-f` | `MEDIAPROC_FONTS_DIR` | `./fonts` | Custom fonts directory |\n| `-c` | `MEDIAPROC_CPUS`   | `0`        | CPU limit (0 = unlimited) |\n| `-r` | `MEDIAPROC_MEMORY` | `0`        | RAM limit (0 = unlimited) |\n| `-s` | `MEDIAPROC_SWAP`   | `0`        | Swap limit (0 = no swap)  |\n\nThe skill's client side (`scripts/mediaproc.sh`) connects using `MEDIAPROC_HOST` /\n`MEDIAPROC_PORT`, pointing at an instance set up as above. The server-side\nallow-list constrains which commands run, but not who you're trusting — only\npoint `MEDIAPROC_HOST` at a mediaproc instance you or a trusted operator control;\nwhoever runs that instance can see every file transferred through it.\n\n`MEDIAPROC_HOST` is read from the environment at call time with no validation\nbeyond \"does SSH connect\" — treat it like any other trusted config value, not\nuntrusted runtime input. Provision it the same way you'd provision a secret or\na connection string (your shell profile, an env file under your control, your\ndeployment config), not from a value an untrusted caller can set. If something\nelse can inject `MEDIAPROC_HOST` into the environment the skill runs in, it can\nredirect every `put`/`get` and command to a host of its choosing.\n\nFile v2.0.6:skill-card.md\n\n## Description: <br>\nProcess media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[psyb0t](https://clawhub.ai/user/psyb0t) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and media-processing users use this skill to upload media to a trusted mediaproc SSH host, run allow-listed ffmpeg, sox, and ImageMagick operations, and download the resulting files. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: Files and commands are sent to whichever mediaproc SSH host is configured. <br>\nMitigation: Set MEDIAPROC_HOST only from trusted configuration and point it only at a mediaproc instance controlled by the user or a trusted operator. <br>\nRisk: Remote delete operations can permanently remove data in the mediaproc work directory. <br>\nMitigation: Require explicit confirmation of the exact path before running remove-file, remove-dir, or remove-dir-recursive. <br>\nRisk: The setup installer runs with root privileges. <br>\nMitigation: Pin the installer to a released tag and review the downloaded script before running it with sudo. <br>\n\n\n## Reference(s): <br>\n- [mediaproc setup](references/setup.md) <br>\n- [ClawHub mediaproc release](https://clawhub.ai/psyb0t/skills/mediaproc) <br>\n- [docker-mediaproc homepage](https://github.com/psyb0t/docker-mediaproc) <br>\n- [docker-lockbox](https://github.com/psyb0t/docker-lockbox) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [text, markdown, shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown guidance with inline shell commands] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [The shell wrapper requires MEDIAPROC_HOST and MEDIAPROC_PORT and sends media files and commands to the configured SSH host.] <br>\n\n## Skill Version(s): <br>\n2.0.6 (source: ClawHub release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v2.0.5: 5 files, 6096 bytes\n\nFiles: references/setup.md (2385b), scripts/mediaproc.sh (548b), skill-card.md (2351b), SKILL.md (7482b), _meta.json (128b)\n\nFile v2.0.5:SKILL.md\n\n---\nname: mediaproc\ndescription: Process media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. Use when the user wants to transcode video, process audio, manipulate images, or work with media files.\ncompatibility: Requires ssh and a running mediaproc instance. MEDIAPROC_HOST and MEDIAPROC_PORT env vars must be set.\nmetadata:\n  author: psyb0t\n  homepage: https://github.com/psyb0t/docker-mediaproc\n---\n\n# mediaproc\n\nLocked-down media processing over SSH. Built on [lockbox](https://github.com/psyb0t/docker-lockbox) — no shell access, no injection, no bullshit.\n\nFor installation and deployment, see [references/setup.md](references/setup.md).\n\n## Security model\n\nmediaproc is **not** a general-purpose shell, and `scripts/mediaproc.sh` is **not**\narbitrary remote code execution even though it forwards a free-form-looking command\nstring. The instance runs inside a [lockbox](https://github.com/psyb0t/docker-lockbox)-\nhardened container, and this skill only ever talks to an instance you (or your\noperator) already run and trust:\n\n- **Key-auth only** — SSH accepts public-key auth only (no passwords), connecting\n  as a restricted user. There is no interactive shell and no PTY.\n- **Server-side enforced allow-list, not documentation** — `scripts/mediaproc.sh`\n  passes its argument through to the SSH channel as-is, but the *remote* lockbox\n  dispatcher is what decides what runs, and it only ever executes the fixed set\n  documented below: `ffmpeg`, `ffprobe`, `sox`, `soxi`, `convert`, `identify`,\n  `magick`, plus lockbox's built-in, scoped file operations. This is an enforced\n  allow-list on the server, not a client-side convention — the wrapper cannot be\n  used to run anything outside that set. Any other command name is refused before\n  execution; the remote never spawns a shell, so there is no shell-injection\n  surface and no way to chain (`;`, `|`, `&&`, backticks, etc.) into a second\n  command.\n- **Work-dir confined** — every path resolves under the instance work directory\n  (`/work`); traversal is blocked. The sandbox cannot read or write your host\n  filesystem.\n- **Consumer-only** — this skill moves files to/from a running instance and runs\n  the whitelisted media tools on them. It never provisions, escalates, or installs\n  anything on your machine (server setup is a separate, operator-side step — see\n  setup.md).\n- **You must still trust the configured host** — `MEDIAPROC_HOST`/`MEDIAPROC_PORT`\n  point at a specific instance. The allow-list constrains *what* runs, not *where*;\n  if `MEDIAPROC_HOST` is pointed at an instance you don't control, that operator\n  still sees every file you `put`/`get` and every command you send. Only point\n  this skill at a mediaproc instance you or a trusted operator run.\n\n## SSH Wrapper\n\nUse `scripts/mediaproc.sh` for all commands. It handles host, port, and host key acceptance via `MEDIAPROC_HOST` and `MEDIAPROC_PORT` env vars.\n\nThe `<command>` argument looks free-form but is not arbitrary execution: the\nremote lockbox dispatcher enforces the allow-list from the Security model above,\nserver-side, on every invocation.\n\n```bash\nscripts/mediaproc.sh <command> [args]\nscripts/mediaproc.sh <command> < input_file\nscripts/mediaproc.sh <command> > output_file\n```\n\n## Media Tools\n\n| Command    | Description                                  |\n| ---------- | -------------------------------------------- |\n| `ffmpeg`   | Video/audio encoding, transcoding, filtering |\n| `ffprobe`  | Media file analysis                          |\n| `sox`      | Audio processing                             |\n| `soxi`     | Audio file info                              |\n| `convert`  | Image conversion/manipulation (ImageMagick)  |\n| `identify` | Image file info (ImageMagick)                |\n| `magick`   | ImageMagick CLI                              |\n\n## Upload, Process, Download\n\n```bash\n# Upload\nscripts/mediaproc.sh \"put input.mp4\" < input.mp4\n\n# Transcode\nscripts/mediaproc.sh \"ffmpeg -i /work/input.mp4 -c:v libx264 /work/output.mp4\"\n\n# Download result\nscripts/mediaproc.sh \"get output.mp4\" > output.mp4\n\n# Clean up\nscripts/mediaproc.sh \"remove-file input.mp4\"\nscripts/mediaproc.sh \"remove-file output.mp4\"\n```\n\n## Video Operations\n\n```bash\n# Get video info as JSON\nscripts/mediaproc.sh \"ffprobe -v quiet -print_format json -show_format -show_streams /work/video.mp4\"\n\n# Apply frei0r glow effect\nscripts/mediaproc.sh \"ffmpeg -i /work/in.mp4 -vf frei0r=glow:0.5 /work/out.mp4\"\n\n# Extract audio from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -vn -acodec libmp3lame /work/audio.mp3\"\n\n# Create thumbnail from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -ss 00:00:05 -vframes 1 /work/thumb.jpg\"\n```\n\n## Audio Operations\n\n```bash\n# Convert audio format\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.mp3\"\n\n# Get audio info\nscripts/mediaproc.sh \"soxi /work/audio.wav\"\n\n# Normalize audio\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.wav norm\"\n```\n\n## Image Operations\n\n```bash\n# Resize image\nscripts/mediaproc.sh \"convert /work/input.png -resize 50% /work/output.png\"\n\n# Create thumbnail\nscripts/mediaproc.sh \"convert /work/input.jpg -thumbnail 200x200 /work/thumb.jpg\"\n\n# Get image info\nscripts/mediaproc.sh \"identify /work/image.png\"\n```\n\n## File Operations\n\nAll paths relative to the work directory. Traversal blocked.\n\n| Command                | Description                        |\n| ---------------------- | ---------------------------------- |\n| `put <path>`           | Upload file from stdin             |\n| `get <path>`           | Download file to stdout            |\n| `list-files [--json]`  | List directory                     |\n| `remove-file <path>`   | Delete a file                      |\n| `create-dir <path>`    | Create directory                   |\n| `remove-dir <path>`    | Remove empty directory             |\n| `remove-dir-recursive <path>` | Remove directory recursively |\n| `move-file <src> <dst>`| Move or rename                     |\n| `copy-file <src> <dst>`| Copy a file                        |\n| `file-info <path>`     | Get file metadata as JSON          |\n| `file-exists <path>`   | Check if file exists (true/false)  |\n| `file-hash <path>`     | Get SHA256 hash                    |\n| `disk-usage [path]`    | Get bytes used                     |\n| `search-files <glob>`  | Glob search                        |\n| `append-file <path>`   | Append stdin to a file             |\n\n```bash\n# List files\nscripts/mediaproc.sh \"list-files\"\n\n# List as JSON (size, modified, isDir, permissions)\nscripts/mediaproc.sh \"list-files --json\"\n\n# List subdirectory\nscripts/mediaproc.sh \"list-files project1\"\n\n# File operations\nscripts/mediaproc.sh \"create-dir project1\"\nscripts/mediaproc.sh \"move-file old.mp4 new.mp4\"\nscripts/mediaproc.sh \"copy-file input.mp4 backup.mp4\"\nscripts/mediaproc.sh \"file-info video.mp4\"\nscripts/mediaproc.sh \"file-exists video.mp4\"\nscripts/mediaproc.sh \"file-hash video.mp4\"\nscripts/mediaproc.sh \"search-files '*.mp4'\"\nscripts/mediaproc.sh \"disk-usage\"\nscripts/mediaproc.sh \"remove-dir-recursive project1\"\n```\n\n## Plugins\n\n- **frei0r** — Video effect plugins (used via `-vf frei0r=...`)\n- **LADSPA** — Audio effect plugins: SWH, TAP, CMT (used via `-af ladspa=...`)\n- **LV2** — Audio plugins (used via `-af lv2=...`)\n\n## Fonts\n\n2200+ fonts included covering emoji, CJK, Arabic, Thai, Indic, monospace, and more. Custom fonts can be mounted to `/usr/share/fonts/custom`.\n\nFile v2.0.5:_meta.json\n\n{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"mediaproc\",\n  \"version\": \"2.0.5\",\n  \"publishedAt\": 1785018102083\n}\n\nFile v2.0.5:references/setup.md\n\n# mediaproc setup\n\n## Quick Install\n\nThe installer creates `~/.mediaproc/` (docker-compose, authorized_keys, work\ndirectory) and drops a `mediaproc` command into `/usr/local/bin`. The container\nit stands up is a [lockbox](https://github.com/psyb0t/docker-lockbox)-hardened\nSSH sandbox (key-auth, whitelisted commands only — see the Security model in\nSKILL.md).\n\nBecause the installer runs as **root**, pin it to a released tag and read it\nbefore running — don't pipe a mutable `main` branch straight into a root shell:\n\n```bash\n# Pick a released tag: https://github.com/psyb0t/docker-mediaproc/releases\nREF=vX.Y.Z\ncurl -fsSL \"https://raw.githubusercontent.com/psyb0t/docker-mediaproc/${REF}/install.sh\" -o install.sh\nless install.sh            # review exactly what runs as root\nsudo bash install.sh\n```\n\n## Starting\n\n```bash\n# Add your SSH key\ncat ~/.ssh/id_rsa.pub >> ~/.mediaproc/authorized_keys\n\n# Basic start (detached)\nmediaproc start -d\n\n# With resource limits\nmediaproc start -d -c 4 -r 4g -s 2g\n\n# Custom port\nmediaproc start -d -p 2223\n\n# Custom fonts directory\nmediaproc start -d -f /path/to/fonts\n```\n\nAll flags persist to `~/.mediaproc/.env` — next `start` reuses the last values.\n\n## Management\n\n```bash\nmediaproc stop                # stop\nmediaproc upgrade             # pull latest image, asks to stop/restart\nmediaproc uninstall           # stop and remove everything\nmediaproc status              # show status\nmediaproc logs                # show container logs\n```\n\n## Configuration\n\n| Flag | Env var            | Default    | Description           |\n| ---- | ------------------ | ---------- | --------------------- |\n| `-p` | `MEDIAPROC_PORT`   | `2222`     | SSH port              |\n| `-f` | `MEDIAPROC_FONTS_DIR` | `./fonts` | Custom fonts directory |\n| `-c` | `MEDIAPROC_CPUS`   | `0`        | CPU limit (0 = unlimited) |\n| `-r` | `MEDIAPROC_MEMORY` | `0`        | RAM limit (0 = unlimited) |\n| `-s` | `MEDIAPROC_SWAP`   | `0`        | Swap limit (0 = no swap)  |\n\nThe skill's client side (`scripts/mediaproc.sh`) connects using `MEDIAPROC_HOST` /\n`MEDIAPROC_PORT`, pointing at an instance set up as above. The server-side\nallow-list constrains which commands run, but not who you're trusting — only\npoint `MEDIAPROC_HOST` at a mediaproc instance you or a trusted operator control;\nwhoever runs that instance can see every file transferred through it.\n\nFile v2.0.5:skill-card.md\n\n## Description: <br>\nProcess media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[psyb0t](https://clawhub.ai/user/psyb0t) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this skill to upload media to a trusted mediaproc instance, run allow-listed ffmpeg, sox, and ImageMagick operations, and download processed outputs. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: A mediaproc operator can see files transferred through the configured host and the commands sent to it. <br>\nMitigation: Set MEDIAPROC_HOST and MEDIAPROC_PORT only to an instance operated by you or a trusted operator. <br>\nRisk: The setup installer runs as root when provisioning the mediaproc server. <br>\nMitigation: Pin the installer to a released tag, review it before execution, and avoid piping a mutable branch directly into sudo. <br>\nRisk: remove-file and remove-dir-recursive permanently delete content inside the remote work directory. <br>\nMitigation: Confirm target paths before deletion and keep separate backups for media that must be preserved. <br>\n\n\n## Reference(s): <br>\n- [mediaproc setup](artifact/references/setup.md) <br>\n- [docker-mediaproc](https://github.com/psyb0t/docker-mediaproc) <br>\n- [docker-lockbox](https://github.com/psyb0t/docker-lockbox) <br>\n- [docker-mediaproc releases](https://github.com/psyb0t/docker-mediaproc/releases) <br>\n- [ClawHub skill page](https://clawhub.ai/psyb0t/skills/mediaproc) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Shell commands, Configuration, Guidance, Markdown] <br>\n**Output Format:** [Markdown with inline bash code blocks] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Commands require ssh plus MEDIAPROC_HOST and MEDIAPROC_PORT pointing at a trusted mediaproc instance.] <br>\n\n## Skill Version(s): <br>\n2.0.5 (source: server-resolved release metadata) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v2.0.3: 5 files, 5324 bytes\n\nFiles: references/setup.md (1995b), scripts/mediaproc.sh (548b), skill-card.md (2117b), SKILL.md (6331b), _meta.json (128b)\n\nFile v2.0.3:SKILL.md\n\n---\nname: mediaproc\ndescription: Process media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. Use when the user wants to transcode video, process audio, manipulate images, or work with media files.\ncompatibility: Requires ssh and a running mediaproc instance. MEDIAPROC_HOST and MEDIAPROC_PORT env vars must be set.\nmetadata:\n  author: psyb0t\n  homepage: https://github.com/psyb0t/docker-mediaproc\n---\n\n# mediaproc\n\nLocked-down media processing over SSH. Built on [lockbox](https://github.com/psyb0t/docker-lockbox) — no shell access, no injection, no bullshit.\n\nFor installation and deployment, see [references/setup.md](references/setup.md).\n\n## Security model\n\nmediaproc is **not** a general-purpose shell. The instance runs inside a\n[lockbox](https://github.com/psyb0t/docker-lockbox)-hardened container, and this\nskill only ever talks to an instance you (or your operator) already run and trust:\n\n- **Key-auth only** — SSH accepts public-key auth only (no passwords), connecting\n  as a restricted user. There is no interactive shell and no PTY.\n- **Whitelisted binaries** — the SSH channel dispatches only a fixed allow-list\n  (`ffmpeg`, `ffprobe`, `sox`, `soxi`, `convert`, `identify`, `magick`) plus\n  lockbox's built-in, scoped file operations. Anything else is refused; the remote\n  never spawns a shell, so there is no shell-injection surface.\n- **Work-dir confined** — every path resolves under the instance work directory\n  (`/work`); traversal is blocked. The sandbox cannot read or write your host\n  filesystem.\n- **Consumer-only** — this skill moves files to/from a running instance and runs\n  the whitelisted media tools on them. It never provisions, escalates, or installs\n  anything on your machine (server setup is a separate, operator-side step — see\n  setup.md).\n\n## SSH Wrapper\n\nUse `scripts/mediaproc.sh` for all commands. It handles host, port, and host key acceptance via `MEDIAPROC_HOST` and `MEDIAPROC_PORT` env vars.\n\n```bash\nscripts/mediaproc.sh <command> [args]\nscripts/mediaproc.sh <command> < input_file\nscripts/mediaproc.sh <command> > output_file\n```\n\n## Media Tools\n\n| Command    | Description                                  |\n| ---------- | -------------------------------------------- |\n| `ffmpeg`   | Video/audio encoding, transcoding, filtering |\n| `ffprobe`  | Media file analysis                          |\n| `sox`      | Audio processing                             |\n| `soxi`     | Audio file info                              |\n| `convert`  | Image conversion/manipulation (ImageMagick)  |\n| `identify` | Image file info (ImageMagick)                |\n| `magick`   | ImageMagick CLI                              |\n\n## Upload, Process, Download\n\n```bash\n# Upload\nscripts/mediaproc.sh \"put input.mp4\" < input.mp4\n\n# Transcode\nscripts/mediaproc.sh \"ffmpeg -i /work/input.mp4 -c:v libx264 /work/output.mp4\"\n\n# Download result\nscripts/mediaproc.sh \"get output.mp4\" > output.mp4\n\n# Clean up\nscripts/mediaproc.sh \"remove-file input.mp4\"\nscripts/mediaproc.sh \"remove-file output.mp4\"\n```\n\n## Video Operations\n\n```bash\n# Get video info as JSON\nscripts/mediaproc.sh \"ffprobe -v quiet -print_format json -show_format -show_streams /work/video.mp4\"\n\n# Apply frei0r glow effect\nscripts/mediaproc.sh \"ffmpeg -i /work/in.mp4 -vf frei0r=glow:0.5 /work/out.mp4\"\n\n# Extract audio from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -vn -acodec libmp3lame /work/audio.mp3\"\n\n# Create thumbnail from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -ss 00:00:05 -vframes 1 /work/thumb.jpg\"\n```\n\n## Audio Operations\n\n```bash\n# Convert audio format\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.mp3\"\n\n# Get audio info\nscripts/mediaproc.sh \"soxi /work/audio.wav\"\n\n# Normalize audio\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.wav norm\"\n```\n\n## Image Operations\n\n```bash\n# Resize image\nscripts/mediaproc.sh \"convert /work/input.png -resize 50% /work/output.png\"\n\n# Create thumbnail\nscripts/mediaproc.sh \"convert /work/input.jpg -thumbnail 200x200 /work/thumb.jpg\"\n\n# Get image info\nscripts/mediaproc.sh \"identify /work/image.png\"\n```\n\n## File Operations\n\nAll paths relative to the work directory. Traversal blocked.\n\n| Command                | Description                        |\n| ---------------------- | ---------------------------------- |\n| `put <path>`           | Upload file from stdin             |\n| `get <path>`           | Download file to stdout            |\n| `list-files [--json]`  | List directory                     |\n| `remove-file <path>`   | Delete a file                      |\n| `create-dir <path>`    | Create directory                   |\n| `remove-dir <path>`    | Remove empty directory             |\n| `remove-dir-recursive <path>` | Remove directory recursively |\n| `move-file <src> <dst>`| Move or rename                     |\n| `copy-file <src> <dst>`| Copy a file                        |\n| `file-info <path>`     | Get file metadata as JSON          |\n| `file-exists <path>`   | Check if file exists (true/false)  |\n| `file-hash <path>`     | Get SHA256 hash                    |\n| `disk-usage [path]`    | Get bytes used                     |\n| `search-files <glob>`  | Glob search                        |\n| `append-file <path>`   | Append stdin to a file             |\n\n```bash\n# List files\nscripts/mediaproc.sh \"list-files\"\n\n# List as JSON (size, modified, isDir, permissions)\nscripts/mediaproc.sh \"list-files --json\"\n\n# List subdirectory\nscripts/mediaproc.sh \"list-files project1\"\n\n# File operations\nscripts/mediaproc.sh \"create-dir project1\"\nscripts/mediaproc.sh \"move-file old.mp4 new.mp4\"\nscripts/mediaproc.sh \"copy-file input.mp4 backup.mp4\"\nscripts/mediaproc.sh \"file-info video.mp4\"\nscripts/mediaproc.sh \"file-exists video.mp4\"\nscripts/mediaproc.sh \"file-hash video.mp4\"\nscripts/mediaproc.sh \"search-files '*.mp4'\"\nscripts/mediaproc.sh \"disk-usage\"\nscripts/mediaproc.sh \"remove-dir-recursive project1\"\n```\n\n## Plugins\n\n- **frei0r** — Video effect plugins (used via `-vf frei0r=...`)\n- **LADSPA** — Audio effect plugins: SWH, TAP, CMT (used via `-af ladspa=...`)\n- **LV2** — Audio plugins (used via `-af lv2=...`)\n\n## Fonts\n\n2200+ fonts included covering emoji, CJK, Arabic, Thai, Indic, monospace, and more. Custom fonts can be mounted to `/usr/share/fonts/custom`.\n\nFile v2.0.3:_meta.json\n\n{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"mediaproc\",\n  \"version\": \"2.0.3\",\n  \"publishedAt\": 1784937743580\n}\n\nFile v2.0.3:references/setup.md\n\n# mediaproc setup\n\n## Quick Install\n\nThe installer creates `~/.mediaproc/` (docker-compose, authorized_keys, work\ndirectory) and drops a `mediaproc` command into `/usr/local/bin`. The container\nit stands up is a [lockbox](https://github.com/psyb0t/docker-lockbox)-hardened\nSSH sandbox (key-auth, whitelisted commands only — see the Security model in\nSKILL.md).\n\nBecause the installer runs as **root**, pin it to a released tag and read it\nbefore running — don't pipe a mutable `main` branch straight into a root shell:\n\n```bash\n# Pick a released tag: https://github.com/psyb0t/docker-mediaproc/releases\nREF=vX.Y.Z\ncurl -fsSL \"https://raw.githubusercontent.com/psyb0t/docker-mediaproc/${REF}/install.sh\" -o install.sh\nless install.sh            # review exactly what runs as root\nsudo bash install.sh\n```\n\n## Starting\n\n```bash\n# Add your SSH key\ncat ~/.ssh/id_rsa.pub >> ~/.mediaproc/authorized_keys\n\n# Basic start (detached)\nmediaproc start -d\n\n# With resource limits\nmediaproc start -d -c 4 -r 4g -s 2g\n\n# Custom port\nmediaproc start -d -p 2223\n\n# Custom fonts directory\nmediaproc start -d -f /path/to/fonts\n```\n\nAll flags persist to `~/.mediaproc/.env` — next `start` reuses the last values.\n\n## Management\n\n```bash\nmediaproc stop                # stop\nmediaproc upgrade             # pull latest image, asks to stop/restart\nmediaproc uninstall           # stop and remove everything\nmediaproc status              # show status\nmediaproc logs                # show container logs\n```\n\n## Configuration\n\n| Flag | Env var            | Default    | Description           |\n| ---- | ------------------ | ---------- | --------------------- |\n| `-p` | `MEDIAPROC_PORT`   | `2222`     | SSH port              |\n| `-f` | `MEDIAPROC_FONTS_DIR` | `./fonts` | Custom fonts directory |\n| `-c` | `MEDIAPROC_CPUS`   | `0`        | CPU limit (0 = unlimited) |\n| `-r` | `MEDIAPROC_MEMORY` | `0`        | RAM limit (0 = unlimited) |\n| `-s` | `MEDIAPROC_SWAP`   | `0`        | Swap limit (0 = no swap)  |\n\nFile v2.0.3:skill-card.md\n\n## Description: <br>\nProcess media files including video, audio, and images through a locked-down SSH container with ffmpeg, sox, and ImageMagick. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[psyb0t](https://clawhub.ai/user/psyb0t) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and operators use mediaproc to inspect, transcode, convert, and manipulate media files on a configured remote mediaproc instance rather than running media tools directly on the local host. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The skill depends on a configured mediaproc SSH host, so uploaded files and processing commands are exposed to that remote sandbox. <br>\nMitigation: Install only when you control or trust the mediaproc host, and treat uploaded files as shared with that configured environment. <br>\nRisk: The optional installer runs with elevated privileges during server setup. <br>\nMitigation: Review the installer before running it with sudo and pin it to a released tag instead of a mutable branch. <br>\n\n\n## Reference(s): <br>\n- [ClawHub skill page](https://clawhub.ai/psyb0t/skills/mediaproc) <br>\n- [docker-mediaproc homepage](https://github.com/psyb0t/docker-mediaproc) <br>\n- [mediaproc setup](references/setup.md) <br>\n- [docker-lockbox](https://github.com/psyb0t/docker-lockbox) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [Shell commands, Guidance, Configuration] <br>\n**Output Format:** [Markdown with bash commands, file paths, and command examples] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [May upload media to and download processed media from the configured remote SSH sandbox.] <br>\n\n## Skill Version(s): <br>\n2.0.3 (source: server release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>\n\nArchive v2.0.1: 5 files, 4582 bytes\n\nFiles: references/setup.md (1477b), scripts/mediaproc.sh (548b), skill-card.md (2197b), SKILL.md (5181b), _meta.json (128b)\n\nFile v2.0.1:SKILL.md\n\n---\nname: mediaproc\ndescription: Process media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. Use when the user wants to transcode video, process audio, manipulate images, or work with media files.\ncompatibility: Requires ssh and a running mediaproc instance. MEDIAPROC_HOST and MEDIAPROC_PORT env vars must be set.\nmetadata:\n  author: psyb0t\n  homepage: https://github.com/psyb0t/docker-mediaproc\n---\n\n# mediaproc\n\nLocked-down media processing over SSH. Built on [lockbox](https://github.com/psyb0t/docker-lockbox) — no shell access, no injection, no bullshit.\n\nFor installation and deployment, see [references/setup.md](references/setup.md).\n\n## SSH Wrapper\n\nUse `scripts/mediaproc.sh` for all commands. It handles host, port, and host key acceptance via `MEDIAPROC_HOST` and `MEDIAPROC_PORT` env vars.\n\n```bash\nscripts/mediaproc.sh <command> [args]\nscripts/mediaproc.sh <command> < input_file\nscripts/mediaproc.sh <command> > output_file\n```\n\n## Media Tools\n\n| Command    | Description                                  |\n| ---------- | -------------------------------------------- |\n| `ffmpeg`   | Video/audio encoding, transcoding, filtering |\n| `ffprobe`  | Media file analysis                          |\n| `sox`      | Audio processing                             |\n| `soxi`     | Audio file info                              |\n| `convert`  | Image conversion/manipulation (ImageMagick)  |\n| `identify` | Image file info (ImageMagick)                |\n| `magick`   | ImageMagick CLI                              |\n\n## Upload, Process, Download\n\n```bash\n# Upload\nscripts/mediaproc.sh \"put input.mp4\" < input.mp4\n\n# Transcode\nscripts/mediaproc.sh \"ffmpeg -i /work/input.mp4 -c:v libx264 /work/output.mp4\"\n\n# Download result\nscripts/mediaproc.sh \"get output.mp4\" > output.mp4\n\n# Clean up\nscripts/mediaproc.sh \"remove-file input.mp4\"\nscripts/mediaproc.sh \"remove-file output.mp4\"\n```\n\n## Video Operations\n\n```bash\n# Get video info as JSON\nscripts/mediaproc.sh \"ffprobe -v quiet -print_format json -show_format -show_streams /work/video.mp4\"\n\n# Apply frei0r glow effect\nscripts/mediaproc.sh \"ffmpeg -i /work/in.mp4 -vf frei0r=glow:0.5 /work/out.mp4\"\n\n# Extract audio from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -vn -acodec libmp3lame /work/audio.mp3\"\n\n# Create thumbnail from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -ss 00:00:05 -vframes 1 /work/thumb.jpg\"\n```\n\n## Audio Operations\n\n```bash\n# Convert audio format\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.mp3\"\n\n# Get audio info\nscripts/mediaproc.sh \"soxi /work/audio.wav\"\n\n# Normalize audio\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.wav norm\"\n```\n\n## Image Operations\n\n```bash\n# Resize image\nscripts/mediaproc.sh \"convert /work/input.png -resize 50% /work/output.png\"\n\n# Create thumbnail\nscripts/mediaproc.sh \"convert /work/input.jpg -thumbnail 200x200 /work/thumb.jpg\"\n\n# Get image info\nscripts/mediaproc.sh \"identify /work/image.png\"\n```\n\n## File Operations\n\nAll paths relative to the work directory. Traversal blocked.\n\n| Command                | Description                        |\n| ---------------------- | ---------------------------------- |\n| `put <path>`           | Upload file from stdin             |\n| `get <path>`           | Download file to stdout            |\n| `list-files [--json]`  | List directory                     |\n| `remove-file <path>`   | Delete a file                      |\n| `create-dir <path>`    | Create directory                   |\n| `remove-dir <path>`    | Remove empty directory             |\n| `remove-dir-recursive <path>` | Remove directory recursively |\n| `move-file <src> <dst>`| Move or rename                     |\n| `copy-file <src> <dst>`| Copy a file                        |\n| `file-info <path>`     | Get file metadata as JSON          |\n| `file-exists <path>`   | Check if file exists (true/false)  |\n| `file-hash <path>`     | Get SHA256 hash                    |\n| `disk-usage [path]`    | Get bytes used                     |\n| `search-files <glob>`  | Glob search                        |\n| `append-file <path>`   | Append stdin to a file             |\n\n```bash\n# List files\nscripts/mediaproc.sh \"list-files\"\n\n# List as JSON (size, modified, isDir, permissions)\nscripts/mediaproc.sh \"list-files --json\"\n\n# List subdirectory\nscripts/mediaproc.sh \"list-files project1\"\n\n# File operations\nscripts/mediaproc.sh \"create-dir project1\"\nscripts/mediaproc.sh \"move-file old.mp4 new.mp4\"\nscripts/mediaproc.sh \"copy-file input.mp4 backup.mp4\"\nscripts/mediaproc.sh \"file-info video.mp4\"\nscripts/mediaproc.sh \"file-exists video.mp4\"\nscripts/mediaproc.sh \"file-hash video.mp4\"\nscripts/mediaproc.sh \"search-files '*.mp4'\"\nscripts/mediaproc.sh \"disk-usage\"\nscripts/mediaproc.sh \"remove-dir-recursive project1\"\n```\n\n## Plugins\n\n- **frei0r** — Video effect plugins (used via `-vf frei0r=...`)\n- **LADSPA** — Audio effect plugins: SWH, TAP, CMT (used via `-af ladspa=...`)\n- **LV2** — Audio plugins (used via `-af lv2=...`)\n\n## Fonts\n\n2200+ fonts included covering emoji, CJK, Arabic, Thai, Indic, monospace, and more. Custom fonts can be mounted to `/usr/share/fonts/custom`.\n\nFile v2.0.1:_meta.json\n\n{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"mediaproc\",\n  \"version\": \"2.0.1\",\n  \"publishedAt\": 1774871569971\n}\n\nFile v2.0.1:references/setup.md\n\n# mediaproc setup\n\n## Quick Install\n\n```bash\ncurl -fsSL https://raw.githubusercontent.com/psyb0t/docker-mediaproc/main/install.sh | sudo bash\n```\n\nThis creates `~/.mediaproc/` with docker-compose, authorized_keys, and work directory, then drops a `mediaproc` command into `/usr/local/bin`.\n\n## Starting\n\n```bash\n# Add your SSH key\ncat ~/.ssh/id_rsa.pub >> ~/.mediaproc/authorized_keys\n\n# Basic start (detached)\nmediaproc start -d\n\n# With resource limits\nmediaproc start -d -c 4 -r 4g -s 2g\n\n# Custom port\nmediaproc start -d -p 2223\n\n# Custom fonts directory\nmediaproc start -d -f /path/to/fonts\n```\n\nAll flags persist to `~/.mediaproc/.env` — next `start` reuses the last values.\n\n## Management\n\n```bash\nmediaproc stop                # stop\nmediaproc upgrade             # pull latest image, asks to stop/restart\nmediaproc uninstall           # stop and remove everything\nmediaproc status              # show status\nmediaproc logs                # show container logs\n```\n\n## Configuration\n\n| Flag | Env var            | Default    | Description           |\n| ---- | ------------------ | ---------- | --------------------- |\n| `-p` | `MEDIAPROC_PORT`   | `2222`     | SSH port              |\n| `-f` | `MEDIAPROC_FONTS_DIR` | `./fonts` | Custom fonts directory |\n| `-c` | `MEDIAPROC_CPUS`   | `0`        | CPU limit (0 = unlimited) |\n| `-r` | `MEDIAPROC_MEMORY` | `0`        | RAM limit (0 = unlimited) |\n| `-s` | `MEDIAPROC_SWAP`   | `0`        | Swap limit (0 = no swap)  |\n\nFile v2.0.1:skill-card.md\n\n## Description: <br>\nProcess media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. <br>\n\nThis skill is ready for commercial/non-commercial use. <br>\n\n## Publisher: <br>\n[psyb0t](https://clawhub.ai/user/psyb0t) <br>\n\n### License/Terms of Use: <br>\nMIT-0 <br>\n\n\n## Use Case: <br>\nDevelopers and engineers use this skill to run media-processing workflows over SSH, including video transcoding, audio processing, image conversion, file transfer, and remote media inspection. <br>\n\n### Deployment Geography for Use: <br>\nGlobal <br>\n\n## Known Risks and Mitigations: <br>\nRisk: The setup flow references an unpinned installer that may be run with root privileges. <br>\nMitigation: Download and inspect a pinned installer version before running it, and verify integrity where possible. <br>\nRisk: The SSH command interface can process and modify files on the configured mediaproc host. <br>\nMitigation: Use a dedicated SSH key, restrict host and port exposure, and only configure hosts you trust. <br>\nRisk: Recursive removal and uninstall actions can destroy media or working directories. <br>\nMitigation: Keep important media backed up and review destructive file operations before execution. <br>\n\n\n## Reference(s): <br>\n- [mediaproc setup](references/setup.md) <br>\n- [docker-mediaproc project](https://github.com/psyb0t/docker-mediaproc) <br>\n- [docker-lockbox project](https://github.com/psyb0t/docker-lockbox) <br>\n- [ClawHub skill page](https://clawhub.ai/psyb0t/skills/mediaproc) <br>\n\n\n## Skill Output: <br>\n**Output Type(s):** [shell commands, configuration, guidance] <br>\n**Output Format:** [Markdown with inline shell commands] <br>\n**Output Parameters:** [1D] <br>\n**Other Properties Related to Output:** [Requires ssh, MEDIAPROC_HOST, MEDIAPROC_PORT, and a running mediaproc instance.] <br>\n\n## Skill Version(s): <br>\n2.0.1 (source: ClawHub release evidence) <br>\n\n## Ethical Considerations: <br>\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment. <br>","readmeExcerpt":"Skill: mediaproc Owner: psyb0t Summary: Process media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. Use when the user wants to transcode video, process audio, manipulate images, or work with media files. Tags: latest:2.0.12 Version history: v2.0.12 | 2026-08-01T20:29:27.655Z | auto - Removed the skill-card.md file. - No changes to functionality or documentation conten","codeSnippets":[],"executableExamples":[{"language":"bash","snippet":"scripts/mediaproc.sh <command> [args]\nscripts/mediaproc.sh <command> < input_file\nscripts/mediaproc.sh <command> > output_file"},{"language":"bash","snippet":"# Upload\nscripts/mediaproc.sh \"put input.mp4\" < input.mp4\n\n# Transcode\nscripts/mediaproc.sh \"ffmpeg -i /work/input.mp4 -c:v libx264 /work/output.mp4\"\n\n# Download result\nscripts/mediaproc.sh \"get output.mp4\" > output.mp4\n\n# Clean up\nscripts/mediaproc.sh \"remove-file input.mp4\"\nscripts/mediaproc.sh \"remove-file output.mp4\""},{"language":"bash","snippet":"# Get video info as JSON\nscripts/mediaproc.sh \"ffprobe -v quiet -print_format json -show_format -show_streams /work/video.mp4\"\n\n# Apply frei0r glow effect\nscripts/mediaproc.sh \"ffmpeg -i /work/in.mp4 -vf frei0r=glow:0.5 /work/out.mp4\"\n\n# Extract audio from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -vn -acodec libmp3lame /work/audio.mp3\"\n\n# Create thumbnail from video\nscripts/mediaproc.sh \"ffmpeg -i /work/video.mp4 -ss 00:00:05 -vframes 1 /work/thumb.jpg\""},{"language":"bash","snippet":"# Convert audio format\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.mp3\"\n\n# Get audio info\nscripts/mediaproc.sh \"soxi /work/audio.wav\"\n\n# Normalize audio\nscripts/mediaproc.sh \"sox /work/input.wav /work/output.wav norm\""},{"language":"bash","snippet":"# Resize image\nscripts/mediaproc.sh \"convert /work/input.png -resize 50% /work/output.png\"\n\n# Create thumbnail\nscripts/mediaproc.sh \"convert /work/input.jpg -thumbnail 200x200 /work/thumb.jpg\"\n\n# Get image info\nscripts/mediaproc.sh \"identify /work/image.png\""},{"language":"bash","snippet":"# List files\nscripts/mediaproc.sh \"list-files\"\n\n# List as JSON (size, modified, isDir, permissions)\nscripts/mediaproc.sh \"list-files --json\"\n\n# List subdirectory\nscripts/mediaproc.sh \"list-files project1\"\n\n# File operations\nscripts/mediaproc.sh \"create-dir project1\"\nscripts/mediaproc.sh \"move-file old.mp4 new.mp4\"\nscripts/mediaproc.sh \"copy-file input.mp4 backup.mp4\"\nscripts/mediaproc.sh \"file-info video.mp4\"\nscripts/mediaproc.sh \"file-exists video.mp4\"\nscripts/mediaproc.sh \"file-hash video.mp4\"\nscripts/mediaproc.sh \"search-files '*.mp4'\"\nscripts/mediaproc.sh \"disk-usage\"\nscripts/mediaproc.sh \"remove-dir-recursive project1\""}],"parameters":null,"dependencies":[],"permissions":[],"extractedFiles":[{"path":"SKILL.md","content":"---\nname: mediaproc\ndescription: Process media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick. Use when the user wants to transcode video, process audio, manipulate images, or work with media files.\ncompatibility: Requires ssh and a running mediaproc instance. MEDIAPROC_HOST and MEDIAPROC_PORT env vars must be set.\nmetadata:\n  author: psyb0t\n  homepage: https://github.com/psyb0t/docker-mediaproc\n---\n\n# mediaproc\n\nLocked-down media processing over SSH. Built on [lockbox](https://github.com/psyb0t/docker-lockbox) — no shell access, no injection, no bullshit.\n\nFor installation and deployment, see [references/setup.md](references/setup.md).\n\n## Security model\n\nmediaproc is **not** a general-purpose shell, and `scripts/mediaproc.sh` is **not**\narbitrary remote code execution even though it forwards a free-form-looking command\nstring. The instance runs inside a [lockbox](https://github.com/psyb0t/docker-lockbox)-\nhardened container, and this skill only ever talks to an instance you (or your\noperator) already run and trust:\n\n- **Key-auth only** — SSH accepts public-key auth only (no passwords), connecting\n  as a restricted user. There is no interactive shell and no PTY.\n- **Server-side enforced allow-list, not documentation** — `scripts/mediaproc.sh`\n  passes its argument through to the SSH channel as-is, but the *remote* lockbox\n  dispatcher is what decides what runs, and it only ever executes the fixed set\n  documented below: `ffmpeg`, `ffprobe`, `sox`, `soxi`, `convert`, `identify`,\n  `magick`, plus lockbox's built-in, scoped file operations. This is an enforced\n  allow-list on the server, not a client-side convention — the wrapper cannot be\n  used to run anything outside that set. Any other command name is refused before\n  execution; the remote never spawns a shell, so there is no shell-injection\n  surface and no way to chain (`;`, `|`, `&&`, backticks, etc.) into a second\n  command.\n- **Work-dir confined** — every path resolves under the instance work directory\n  (`/work`); traversal is blocked. The sandbox cannot read or write your host\n  filesystem.\n- **Consumer-only** — this skill moves files to/from a running instance and runs\n  the whitelisted media tools on them. It never provisions, escalates, or installs\n  anything on your machine (server setup is a separate, operator-side step — see\n  setup.md).\n- **You must still trust the configured host** — `MEDIAPROC_HOST`/`MEDIAPROC_PORT`\n  point at a specific instance. The allow-list constrains *what* runs, not *where*;\n  if `MEDIAPROC_HOST` is pointed at an instance you don't control, that operator\n  still sees every file you `put`/`get` and every command you send. Only point\n  this skill at a mediaproc instance you or a trusted operator run.\n\n## SSH Wrapper\n\nUse `scripts/mediaproc.sh` for all commands. It handles host, port, and host key acceptance via `MEDIAPROC_HOST` and `MEDIAPROC_PORT` env vars.\n\nThe `<command>` argument looks free-form but is not"},{"path":"_meta.json","content":"{\n  \"ownerId\": \"kn79dhvmpjng4rp2jjk8k0v5xx80ccbk\",\n  \"slug\": \"mediaproc\",\n  \"version\": \"2.0.12\",\n  \"publishedAt\": 1785616167655\n}"},{"path":"references/setup.md","content":"# mediaproc setup\n\n## Quick Install\n\nThe installer creates `~/.mediaproc/` (docker-compose, authorized_keys, work\ndirectory) and drops a `mediaproc` command into `/usr/local/bin`. The container\nit stands up is a [lockbox](https://github.com/psyb0t/docker-lockbox)-hardened\nSSH sandbox (key-auth, whitelisted commands only — see the Security model in\nSKILL.md).\n\nBecause the installer runs as **root**, pin it to a released tag and read it\nbefore running — don't pipe a mutable `main` branch straight into a root shell:\n\n```bash\n# Pick a released tag: https://github.com/psyb0t/docker-mediaproc/releases\nREF=vX.Y.Z\ncurl -fsSL \"https://raw.githubusercontent.com/psyb0t/docker-mediaproc/${REF}/install.sh\" -o install.sh\nless install.sh            # review exactly what runs as root\nsudo bash install.sh\n```\n\n## Starting\n\n```bash\n# Add your SSH key\ncat ~/.ssh/id_rsa.pub >> ~/.mediaproc/authorized_keys\n\n# Basic start (detached)\nmediaproc start -d\n\n# With resource limits\nmediaproc start -d -c 4 -r 4g -s 2g\n\n# Custom port\nmediaproc start -d -p 2223\n\n# Custom fonts directory\nmediaproc start -d -f /path/to/fonts\n```\n\nAll flags persist to `~/.mediaproc/.env` — next `start` reuses the last values.\n\n## Management\n\n```bash\nmediaproc stop                # stop\nmediaproc upgrade             # pull latest image, asks to stop/restart\nmediaproc uninstall           # stop and remove everything\nmediaproc status              # show status\nmediaproc logs                # show container logs\n```\n\n## Configuration\n\n| Flag | Env var            | Default    | Description           |\n| ---- | ------------------ | ---------- | --------------------- |\n| `-p` | `MEDIAPROC_PORT`   | `2222`     | SSH port              |\n| `-f` | `MEDIAPROC_FONTS_DIR` | `./fonts` | Custom fonts directory |\n| `-c` | `MEDIAPROC_CPUS`   | `0`        | CPU limit (0 = unlimited) |\n| `-r` | `MEDIAPROC_MEMORY` | `0`        | RAM limit (0 = unlimited) |\n| `-s` | `MEDIAPROC_SWAP`   | `0`        | Swap limit (0 = no swap)  |\n\nThe skill's client side (`scripts/mediaproc.sh`) connects using `MEDIAPROC_HOST` /\n`MEDIAPROC_PORT`, pointing at an instance set up as above. The server-side\nallow-list constrains which commands run, but not who you're trusting — only\npoint `MEDIAPROC_HOST` at a mediaproc instance you or a trusted operator control;\nwhoever runs that instance can see every file transferred through it.\n\n`MEDIAPROC_HOST` is read from the environment at call time with no validation\nbeyond \"does SSH connect\" — treat it like any other trusted config value, not\nuntrusted runtime input. Provision it the same way you'd provision a secret or\na connection string (your shell profile, an env file under your control, your\ndeployment config), not from a value an untrusted caller can set. If something\nelse can inject `MEDIAPROC_HOST` into the environment the skill runs in, it can\nredirect every `put`/`get` and command to a host of its choosing."},{"path":"skill-card.md","content":"## Description:\n\nProcess media files (video, audio, images) via a locked-down SSH container with ffmpeg, sox, and imagemagick.\n\nThis skill is ready for commercial/non-commercial use.\n\n## Publisher:\n\n[psyb0t](https://clawhub.ai/user/psyb0t)\n\n### License/Terms of Use:\n\nMIT-0\n\n## Use Case:\n\nDevelopers and media-processing operators use this skill to upload media to a trusted mediaproc SSH instance, run allow-listed video, audio, image, and file operations, and retrieve processed outputs.\n\n### Deployment Geography for Use:\n\nGlobal\n\n## Known Risks and Mitigations:\n\nRisk: A remotely downloaded installer runs with root privileges during setup.\n\nMitigation: Pin the installer to a released tag or commit, inspect it before execution, and prefer checksum or signature verification before running it with sudo.\n\nRisk: Media files and commands are visible to the operator of the configured MEDIAPROC_HOST.\n\nMitigation: Use only a mediaproc instance you control or fully trust, and avoid processing sensitive media on untrusted hosts.\n\nRisk: The SSH wrapper accepts new host keys automatically on first connection.\n\nMitigation: Verify the SSH host key before processing sensitive media or connecting in higher-risk environments.\n\nRisk: Destructive file operations can permanently delete data in the remote work directory.\n\nMitigation: Require explicit confirmation of exact remote paths before remove-file, remove-dir, or remove-dir-recursive commands.\n\n## Reference(s):\n\n- [mediaproc setup](references/setup.md)\n- [docker-mediaproc](https://github.com/psyb0t/docker-mediaproc)\n- [docker-lockbox](https://github.com/psyb0t/docker-lockbox)\n- [docker-mediaproc releases](https://github.com/psyb0t/docker-mediaproc/releases)\n\n## Skill Output:\n\n**Output Type(s):** [Markdown, Shell commands, Configuration, Guidance]\n\n**Output Format:** [Markdown with inline shell commands and command examples]\n\n**Output Parameters:** [1D]\n\n**Other Properties Related to Output:** [Commands require ssh plus MEDIAPROC_HOST and MEDIAPROC_PORT pointing to a trusted running mediaproc instance.]\n\n## Skill Version(s):\n\n2.0.12 (source: ClawHub release metadata)\n\n## Ethical Considerations:\n\nUsers should evaluate whether this skill is appropriate for their environment, review any generated or modified files before relying on them, and apply their organization's safety, security, and compliance requirements before deployment."}],"languages":[],"docsSourceLabel":"CLAWHUB","editorialOverview":null,"editorialQuality":{"score":100,"threshold":65,"status":"thin","wordCount":1607,"uniquenessScore":43,"reasons":["uniqueness-below-45"]}},"media":{"evidence":{"source":"no-media","verified":false,"confidence":"low","updatedAt":"2026-10-09T09:28:53.471Z","emptyReason":"No screenshots, media assets, or demo links are available."},"primaryImageUrl":null,"mediaAssetCount":0,"assets":[],"demoUrl":null},"ownerResources":{"evidence":{"source":"unclaimed","verified":false,"confidence":"low","updatedAt":"2026-10-09T09:28:53.471Z","emptyReason":"This page has not been claimed by the agent owner."},"hasCustomPage":false,"customPageUpdatedAt":null,"customLinks":[],"structuredLinks":{"docsUrl":null,"demoUrl":null,"supportUrl":null,"pricingUrl":null,"statusUrl":null},"customPage":null},"relatedAgents":{"evidence":{"source":"protocol-neighbors","verified":false,"confidence":"medium","updatedAt":"2026-10-09T14:38:44.763Z","emptyReason":null},"items":[{"id":"b917f68a-ebff-438e-84f8-3f4b2494c0bc","entityType":"agent","canonicalPath":"/agent/activepieces-activepieces","slug":"activepieces-activepieces","name":"activepieces","description":"AI Agents & MCPs & AI Workflow Automation • (~400 MCP servers for AI agents) • AI Automation / AI Agent with MCPs • AI Workflows & AI Agents • MCPs for AI Agents","url":"https://github.com/activepieces/activepieces","homepage":"https://www.activepieces.com","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-15T02:22:12.426Z","createdAt":"2026-02-25T03:38:12.412Z","downloads":null},{"id":"5cb26759-3a39-483f-94cf-276a98c13bb8","entityType":"agent","canonicalPath":"/agent/cherryhq-cherry-studio","slug":"cherryhq-cherry-studio","name":"cherry-studio","description":"AI productivity studio with smart chat, autonomous agents, and 300+ assistants. Unified access to frontier LLMs","url":"https://github.com/CherryHQ/cherry-studio","homepage":"https://cherry-ai.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-11T14:38:40.986Z","createdAt":"2026-02-25T03:38:19.379Z","downloads":null},{"id":"8ebccd8e-3863-4187-8355-c3f14e1f9edf","entityType":"agent","canonicalPath":"/agent/iofficeai-aionui","slug":"iofficeai-aionui","name":"AionUi","description":"Free, local, open-source 24/7 Cowork app and OpenClaw for Gemini CLI, Claude Code, Codex, OpenCode, Qwen Code, Goose CLI, Auggie, and more | 🌟 Star if you like it!","url":"https://github.com/iOfficeAI/AionUi","homepage":"https://www.aionui.com","source":"GITHUB_REPOS","protocols":["MCP","OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-04-10T18:48:31.762Z","createdAt":"2026-02-25T03:38:16.584Z","downloads":null},{"id":"6f6582d0-5d76-4f0f-b81d-86520247950b","entityType":"agent","canonicalPath":"/agent/copilotkit-copilotkit","slug":"copilotkit-copilotkit","name":"CopilotKit","description":"The Frontend for Agents & Generative UI. React + Angular","url":"https://github.com/CopilotKit/CopilotKit","homepage":"https://docs.copilotkit.ai","source":"GITHUB_REPOS","protocols":["OPENCLAW"],"capabilities":[],"safetyScore":100,"overallRank":70,"updatedAt":"2026-03-25T09:50:57.846Z","createdAt":"2026-02-25T03:39:14.617Z","downloads":null}],"links":{"hub":"/agent","source":"/agent/source/clawhub","protocols":[{"label":"OpenClaw","href":"/agent/protocol/openclew"}]}}}