Skill flagged — suspicious patterns detected
ClawHub Security flagged this skill as suspicious. Review the scan results before using.
聘才猫(Pincaimao)简历优化
v1.0.1聘才猫 - 简历优化 Use when calling Pincaimao Resume Optimization API to automatically optimize or rewrite resume content based on a target job description. Requires...
⭐ 1· 92·0 current·0 all-time
by聘才猫(Pincaimao)@pincaimao
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
OpenClaw
Benign
high confidencePurpose & Capability
Name/description align with requirements: the skill needs an API key (PCM_RESUME_OPTIMIZE_KEY), curl and python3 to upload files and call the Pincaimao API. These requirements are proportional to a resume-upload / resume-optimize integration.
Instruction Scope
The SKILL.md instructs the agent to upload a local resume file and job description to https://api.pincaimao.com and to parse/return the 'answer' field. This is expected for this purpose but does mean user files and job descriptions are transmitted and stored on Pincaimao's COS; the doc also asks the user to ensure 'pincaimao-basic' is installed/loaded (no further detail provided), which is not enforced by metadata and is a minor oddity to verify.
Install Mechanism
Instruction-only skill with no install spec and no code files — lowest-risk install profile; it relies on existing curl and python3 binaries which are reasonable for the provided examples.
Credentials
Only a single service-specific API key (PCM_RESUME_OPTIMIZE_KEY) is required and used in the Authorization header. This is proportionate for a third-party resume optimization API.
Persistence & Privilege
always is false and there is no request to modify other skills or system-wide configs. The skill runs network calls scoped to the configured API key; no elevated persistence or privileges are requested.
Assessment
This skill appears to do what it says: it uploads resume files and job descriptions to Pincaimao's API and returns optimized resume content. Before installing or using it, confirm you trust https://www.pincaimao.com (uploads are stored on their COS and treated as sensitive), only provide the PCM_RESUME_OPTIMIZE_KEY you are comfortable granting access to, and be aware the agent will transmit user files to that external endpoint. Also note the SKILL.md references a separate 'pincaimao-basic' component — verify what that is and whether you need to install it. If you have privacy concerns, avoid uploading real personal data or create a restricted API key you can revoke later.Like a lobster shell, security has layers — review code before you run it.
latestvk9710mree4qmh7p37vpateaq018436kz
License
MIT-0
Free to use, modify, and redistribute. No attribution required.
Runtime requirements
✨ Clawdis
Binscurl, python3
EnvPCM_RESUME_OPTIMIZE_KEY
Primary envPCM_RESUME_OPTIMIZE_KEY
