by waooAI
首家工业级全流程 AI 影视生产平台。Industry-first professional AI Agent platform for controllable film & video production. From shorts to live-action with Hollywood-standard workflows.
# Add to your Claude Code skills
git clone https://github.com/waooAI/waoowaooLast scanned: 5/7/2026
{
"issues": [
{
"type": "npm-audit",
"message": "@aws-sdk/xml-builder: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@hono/node-server: @hono/node-server: Middleware bypass via repeated slashes in serveStatic",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@prisma/config: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "@remotion/bundler: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@remotion/cli: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@remotion/studio-server: Vulnerability found",
"severity": "low"
},
{
"type": "npm-audit",
"message": "@vitest/coverage-v8: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@vitest/mocker: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "@xmldom/xmldom: xmldom: Uncontrolled recursion in XML serialization leads to DoS",
"severity": "high"
},
{
"type": "npm-audit",
"message": "ajv: ajv has ReDoS when using `$data` option",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ajv-formats: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "brace-expansion: brace-expansion: Zero-step sequence causes process hang and memory exhaustion",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "bullmq: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "conf: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "cos-nodejs-sdk-v5: Vulnerability found",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "defu: defu: Prototype pollution via `__proto__` key in defaults argument",
"severity": "high"
},
{
"type": "npm-audit",
"message": "effect: Effect `AsyncLocalStorage` context lost/contaminated inside Effect fibers under concurrent load with RPC",
"severity": "high"
},
{
"type": "npm-audit",
"message": "esbuild: esbuild enables any website to send any requests to the development server and read the response",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "express-rate-limit: express-rate-limit: IPv4-mapped IPv6 addresses bypass per-client rate limiting on servers with dual-stack network",
"severity": "high"
},
{
"type": "npm-audit",
"message": "fast-xml-parser: fast-xml-parser has an entity encoding bypass via regex injection in DOCTYPE entity names",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "flatted: flatted vulnerable to unbounded recursion DoS in parse() revive phase",
"severity": "high"
},
{
"type": "npm-audit",
"message": "form-data: form-data uses unsafe random function in form-data for choosing boundary",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "glob: glob CLI: Command injection via -c/--cmd executes matches with shell:true",
"severity": "high"
},
{
"type": "npm-audit",
"message": "hono: Hono vulnerable to Prototype Pollution possible through __proto__ key allowed in parseBody({ dot: true })",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "ip-address: ip-address has XSS in Address6 HTML-emitting methods",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "js-yaml: js-yaml has prototype pollution in merge (<<)",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "lodash: Lodash has Prototype Pollution Vulnerability in `_.unset` and `_.omit` functions",
"severity": "high"
},
{
"type": "npm-audit",
"message": "minimatch: minimatch has a ReDoS via repeated wildcards with non-matching literal in pattern",
"severity": "high"
},
{
"type": "npm-audit",
"message": "next: Next Server Actions Source Code Exposure ",
"severity": "high"
},
{
"type": "npm-audit",
"message": "next-auth: NextAuthjs Email misdelivery Vulnerability",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "next-intl: next-intl has an open redirect vulnerability",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "path-to-regexp: path-to-regexp vulnerable to Denial of Service via sequential optional groups",
"severity": "high"
},
{
"type": "npm-audit",
"message": "picomatch: Picomatch: Method Injection in POSIX Character Classes causes incorrect Glob Matching",
"severity": "high"
},
{
"type": "npm-audit",
"message": "postcss: PostCSS has XSS via Unescaped </style> in its CSS Stringify Output",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "preact: Preact has JSON VNode Injection issue",
"severity": "high"
},
{
"type": "npm-audit",
"message": "prisma: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "qs: qs's arrayLimit bypass in comma parsing allows denial of service",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "request: Server-Side Request Forgery in Request",
"severity": "critical"
},
{
"type": "npm-audit",
"message": "rollup: Rollup 4 has Arbitrary File Write via Path Traversal",
"severity": "high"
},
{
"type": "npm-audit",
"message": "serialize-javascript: Serialize JavaScript is Vulnerable to RCE via RegExp.flags and Date.prototype.toISOString()",
"severity": "high"
},
{
"type": "npm-audit",
"message": "tar: node-tar has a race condition leading to uninitialized memory exposure",
"severity": "high"
},
{
"type": "npm-audit",
"message": "terser-webpack-plugin: Vulnerability found",
"severity": "high"
},
{
"type": "npm-audit",
"message": "tough-cookie: tough-cookie Prototype Pollution vulnerability",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "underscore: Underscore has unlimited recursion in _.flatten and _.isEqual, potential for DoS attack",
"severity": "high"
},
{
"type": "npm-audit",
"message": "undici: Undici: Malicious WebSocket 64-bit length overflows parser and crashes the client",
"severity": "high"
},
{
"type": "npm-audit",
"message": "uuid: uuid: Missing buffer bounds check in v3/v5/v6 when buf is provided",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vite: Vite Vulnerable to Path Traversal in Optimized Deps `.map` Handling",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vite-node: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "vitest: Vulnerability found",
"severity": "medium"
},
{
"type": "npm-audit",
"message": "webpack: webpack buildHttp: allowedUris allow-list bypass via URL userinfo (@) leading to build-time SSRF behavior",
"severity": "low"
}
],
"status": "FAILED",
"scannedAt": "2026-05-07T06:34:51.100Z",
"semgrepRan": false,
"npmAuditRan": true,
"pipAuditRan": true
}See how waoowaoo compares with popular alternatives.
waoowaoo is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by waooAI. 首家工业级全流程 AI 影视生产平台。Industry-first professional AI Agent platform for controllable film & video production. From shorts to live-action with Hollywood-standard workflows. It has 14,198 GitHub stars.
waoowaoo failed SkillsLLM's automated security scan, which flagged one or more high-severity issues. Review the Security Report section carefully before using it.
Clone the repository with "git clone https://github.com/waooAI/waoowaoo" and add it to your Claude Code skills directory (see the Installation section above).
waoowaoo is primarily written in TypeScript. It is open-source under waooAI on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh waoowaoo against similar tools.
No comments yet. Be the first to share your thoughts!
Requires a passing catalog security scan. Resolve the flagged issues and resubmit to enable featuring.
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
[!IMPORTANT] Preview release: we are iterating rapidly, and some bugs and rough edges remain. Join the community to share feedback and follow updates.
WeChat / community
This preview exposes OpenRouter configuration. Available models include GPT Image 2, Nano Banana variants, Seedance variants, and MiniMax H3 / H3 Max. Availability and charges depend on the provider. H3 Max currently accepts a single first frame in this application, not a first/last-frame pair. Music and voiceover controls are not included in this preview.
The application UI currently supports Chinese and English. Japanese and Korean are README translations.
Copy the following into a local coding assistant with terminal access. It will inspect your machine, install the required dependencies, and configure Docker for you. You may need to approve an operating-system installer or start Docker Desktop yourself.
Install the self-hosted preview of https://github.com/waooAI/waoowaoo on my computer.
Read the repository README, docs/INSTALL.md, and the selected GitHub Release first.
Use a published preview release and its prebuilt Docker images. Pin both the
application and the Codex runtime to the release's immutable image digests.
Check my OS, CPU architecture, Docker Engine/Desktop, Compose v2, Git, and flock;
install missing dependencies using the appropriate OS tools, with approval where required.
Use a new installation directory and preserve all existing containers, files, and data.
Generate unique local secrets and configure .env without printing or uploading secrets.
Follow the existing Worker bootstrap procedure; do not invent a second startup path.
Include docker/caddy/Caddyfile from the same release. Use the default Compose HTTPS entry:
SELF_HOSTED_HOST=localhost, SELF_HOSTED_HTTPS_PORT=1443; APP_HOST_PORT=13000 only redirects HTTP.
The overlay derives NEXTAUTH_URL; preserve Caddy's /data and /config named volumes.
Export only root.crt, explain its trust implications, and obtain my explicit approval
before helping me trust it on the browser's host OS (Windows trust is separate from WSL).
Never export root.key or bypass TLS checks. Verify https://localhost:1443 has no certificate
warning and the browser actually uses h2, including event streams across multiple tabs.
SSE tab concurrency is not the AI task concurrency limit.
Verify container health and that the application opens, then tell me the local URL.
Guide me to enter my OpenRouter API key in the application; do not request it in chat.
Do not start paid AI generations without my approval. If the release lacks a required
image or my platform is unsupported, explain the blocker instead of claiming success.
The release Compose setup starts Caddy automatically. After approving local certificate trust, open https://localhost:1443; port 13000 only redirects HTTP. Source development with npm run dev remains at http://localhost:3001.
The recommended distribution is prebuilt Docker images. You do not need to install Node.js, MySQL, Redis, Temporal, or FFmpeg on your host for this path; application dependencies run in containers. The complete installation instructions for your assistant and manual setup are in docs/INSTALL.md.
After launching, open your profile’s API configuration and add your OpenRouter API key. Provider calls are paid through your own account. Keep API keys out of chat and support logs.
Project data and media use local database and private MinIO storage; prompts and references are sent to the provider for requested AI tasks. Supported inline image references do not require a public media URL.
For manual setup, source builds, backups, and upgrades, see the installation guide.
This project is maintained by the core team. You are welcome to:
Starting with v0.5.0-beta.1, this distribution is licensed under Elastic License 2.0. Personal use, internal business use, modification, and redistribution are permitted subject to its terms. Providing third parties with hosted or managed access to a substantial set of the software’s features requires separate permission. Earlier releases retain their original licenses; third-party components retain their respective licenses. This is source-available software, not OSI-approved open source.
Made with ❤️ by waoowaoo team