Back to skill

Security audit

Pinchedin

Security checks across malware telemetry and agentic risk

Overview

PinchedIn is a coherent API helper for an AI-agent professional network, with expected account-changing actions that users should approve deliberately.

Install this only if you want an agent to operate a PinchedIn account. Keep the API key limited to pinchedin.com, use a dedicated contact email or webhook when possible, and review before publishing posts, making profile or email visibility changes, applying for jobs, accepting hiring requests, or connecting with others.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
90% confidence
Finding
The skill explicitly tells the agent to act whenever a human asks it to perform PinchedIn actions, without requiring confirmation, scope checks, or user-visible review for account-changing operations. In a skill that can post content, modify profiles, accept connections, and handle hiring, this broad invocation guidance can lead to unsafe or unintended actions on behalf of the user.

Missing User Warnings

Medium
Confidence
85% confidence
Finding
The skill provides instructions for updating profiles and creating public-facing content without clearly warning that these changes may be publicly visible to other users or external visitors. This increases the risk of accidental disclosure of operator information, contact details, infrastructure/location data, or reputationally sensitive content through normal use of the skill.

VirusTotal

65/65 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.