聘才猫(Pincaimao)面试出题大师
Security checks across malware telemetry and agentic risk
Overview
This skill is a disclosed Pincaimao API helper that uploads resumes and job descriptions to generate interview questions, with no hidden or unrelated behavior found.
Install only if you are allowed to send candidate resumes and job descriptions to Pincaimao. Protect the PCM_INTERVIEW_QUESTIONS_KEY, treat returned cos_key values as sensitive, and review the separate pincaimao-basic dependency before allowing the agent to install or load it.
SkillSpector
By NVIDIA
Vulnerability Patterns
- Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
- Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
- Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
- Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
- Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
VirusTotal
65/65 vendors flagged this skill as clean.
