基于 Pillow 的图像处理工具:缩放、裁剪、水印、格式转换与 Web 优化一次搞定。
设计与多媒体
mediaproc
在固定白名单的 SSH 沙箱里跑 ffmpeg、sox、ImageMagick 处理音视频和图片。
它能做什么
通过 SSH 包装脚本把文件上传到远端容器,执行白名单内的媒体命令,再把结果流回本地。远端仅接受公钥登录,没有 shell 也没有 PTY,只允许执行 ffmpeg、ffprobe、sox、soxi、convert、identify、magick 这一组固定工具。所有路径都限制在 /work 下,目录穿越以及 `;`、`|`、`&&`、反引号这类链式语法在服务端直接拒绝。同时提供 put、get、list、move、copy、hash、search 等文件操作,自带 2200+ 字体(emoji、CJK、阿拉伯、泰文、印地文、等宽等)。本技能只是客户端,不会在你机器上安装或启动任何服务。
什么时候用它
- 用 ffmpeg/ffprobe 转码或探测视频
- 用 sox 转换格式或归一化音频
- 用 ImageMagick 缩放、转换或查看图片信息
- 给媒体套 frei0r、LADSPA、LV2 插件效果
技能文档
mediaproc
Locked-down media processing over SSH. Built on lockbox — no shell access, no injection, no bullshit.
For installation and deployment, see references/setup.md.
Security model
mediaproc is not a general-purpose shell, and scripts/mediaproc.sh is not
arbitrary remote code execution even though it forwards a free-form-looking command
string. The instance runs inside a lockbox-
hardened container, and this skill only ever talks to an instance you (or your
operator) already run and trust:
- Key-auth only — SSH accepts public-key auth only (no passwords), connecting as a restricted user. There is no interactive shell and no PTY.
- Server-side enforced allow-list, not documentation —
scripts/mediaproc.shpasses its argument through to the SSH channel as-is, but the remote lockbox dispatcher is what decides what runs, and it only ever executes the fixed set documented below:ffmpeg,ffprobe,sox,soxi,convert,identify,magick, plus lockbox's built-in, scoped file operations. This is an enforced allow-list on the server, not a client-side convention — the wrapper cannot be used to run anything outside that set. Any other command name is refused before execution; the remote never spawns a shell, so there is no shell-injection surface and no way to chain (;,|,&&, backticks, etc.) into a second command. - Work-dir confined — every path resolves under the instance work directory
(
/work); traversal is blocked. The sandbox cannot read or write your host filesystem. - Consumer-only — this skill moves files to/from a running instance and runs the whitelisted media tools on them. It never provisions, escalates, or installs anything on your machine (server setup is a separate, operator-side step — see setup.md).
- You must still trust the configured host —
MEDIAPROC_HOST/MEDIAPROC_PORTpoint at a specific instance. The allow-list constrains what runs, not where; ifMEDIAPROC_HOSTis pointed at an instance you don't control, that operator still sees every file youput/getand every command you send. Only point this skill at a mediaproc instance you or a trusted operator run.
SSH Wrapper
Use scripts/mediaproc.sh for all commands. It handles host, port, and host key acceptance via MEDIAPROC_HOST and MEDIAPROC_PORT env vars.
The `` argument looks free-form but is not arbitrary execution: the
wrapper does no shell evaluation of it — it passes the whole string as a single
argument over the SSH channel — and it is the remote lockbox dispatcher that
enforces the allow-list from the Security model above, server-side, on every
invocation. There is no local or remote shell in the loop, so there's no
injection/chaining surface (;, |, &&, backticks, etc. are inert; the
dispatcher just refuses anything that isn't the fixed command name it expects).
scripts/mediaproc.sh [args]
scripts/mediaproc.sh < input_file
scripts/mediaproc.sh > output_file
Media Tools
| Command | Description |
|---|---|
ffmpeg | Video/audio encoding, transcoding, filtering |
ffprobe | Media file analysis |
sox | Audio processing |
soxi | Audio file info |
convert | Image conversion/manipulation (ImageMagick) |
identify | Image file info (ImageMagick) |
magick | ImageMagick CLI |
Upload, Process, Download
# Upload
scripts/mediaproc.sh "put input.mp4" < input.mp4
# Transcode
scripts/mediaproc.sh "ffmpeg -i /work/input.mp4 -c:v libx264 /work/output.mp4"
# Download result
scripts/mediaproc.sh "get output.mp4" > output.mp4
# Clean up
scripts/mediaproc.sh "remove-file input.mp4"
scripts/mediaproc.sh "remove-file output.mp4"
Video Operations
# Get video info as JSON
scripts/mediaproc.sh "ffprobe -v quiet -print_format json -show_format -show_streams /work/video.mp4"
# Apply frei0r glow effect
scripts/mediaproc.sh "ffmpeg -i /work/in.mp4 -vf frei0r=glow:0.5 /work/out.mp4"
# Extract audio from video
scripts/mediaproc.sh "ffmpeg -i /work/video.mp4 -vn -acodec libmp3lame /work/audio.mp3"
# Create thumbnail from video
scripts/mediaproc.sh "ffmpeg -i /work/video.mp4 -ss 00:00:05 -vframes 1 /work/thumb.jpg"
Audio Operations
# Convert audio format
scripts/mediaproc.sh "sox /work/input.wav /work/output.mp3"
# Get audio info
scripts/mediaproc.sh "soxi /work/audio.wav"
# Normalize audio
scripts/mediaproc.sh "sox /work/input.wav /work/output.wav norm"
Image Operations
# Resize image
scripts/mediaproc.sh "convert /work/input.png -resize 50% /work/output.png"
# Create thumbnail
scripts/mediaproc.sh "convert /work/input.jpg -thumbnail 200x200 /work/thumb.jpg"
# Get image info
scripts/mediaproc.sh "identify /work/image.png"
File Operations
All paths relative to the work directory. Traversal blocked.
Destructive. remove-file, remove-dir, and remove-dir-recursive
permanently delete data in the remote work directory — there is no trash/undo.
remove-dir-recursive deletes an entire subtree in one call and is especially
dangerous. Only run these after explicit user confirmation of the exact path.
| Command | Description |
|---|---|
put | Upload file from stdin |
get | Download file to stdout |
list-files [--json] | List directory |
remove-file | Delete a file |
create-dir | Create directory |
remove-dir | Remove empty directory |
remove-dir-recursive | Remove directory recursively |
move-file | Move or rename |
copy-file | Copy a file |
file-info | Get file metadata as JSON |
file-exists | Check if file exists (true/false) |
file-hash | Get SHA256 hash |
disk-usage [path] | Get bytes used |
search-files | Glob search |
append-file | Append stdin to a file |
# List files
scripts/mediaproc.sh "list-files"
# List as JSON (size, modified, isDir, permissions)
scripts/mediaproc.sh "list-files --json"
# List subdirectory
scripts/mediaproc.sh "list-files project1"
# File operations
scripts/mediaproc.sh "create-dir project1"
scripts/mediaproc.sh "move-file old.mp4 new.mp4"
scripts/mediaproc.sh "copy-file input.mp4 backup.mp4"
scripts/mediaproc.sh "file-info video.mp4"
scripts/mediaproc.sh "file-exists video.mp4"
scripts/mediaproc.sh "file-hash video.mp4"
scripts/mediaproc.sh "search-files '*.mp4'"
scripts/mediaproc.sh "disk-usage"
scripts/mediaproc.sh "remove-dir-recursive project1"
Plugins
- frei0r — Video effect plugins (used via
-vf frei0r=...) - LADSPA — Audio effect plugins: SWH, TAP, CMT (used via
-af ladspa=...) - LV2 — Audio plugins (used via
-af lv2=...)
Fonts
2200+ fonts included covering emoji, CJK, Arabic, Thai, Indic, monospace, and more. Custom fonts can be mounted to /usr/share/fonts/custom.
相关技能
在智能体流程中通过 VAP Media API 生成与编辑图像、视频和音乐。
通过 VAP Media API,用同一把 Bearer 密钥生成与编辑图像、视频和音乐。
把图片上传到 img402.dev 并拿到公开链接,无需账号或 API key,1 MB 以下永久免费。
Create and manage Alibaba Cloud IMS video translation jobs via OpenAPI (subtitle/voice/face). Use when you need API-based video translation, status polling,...
逐跳排查代理、应用、依赖间的请求链路,定位并修复 Web 服务故障。