resume-tailor
Warn
Audited by Snyk on May 18, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).
- Third-party content exposure detected (high risk: 0.90). The skill explicitly accepts a job description URL to be fetched and parsed (see "Required inputs" and "Phase 1 — JD ingestion" in SKILL.md), and it reads and uses that public/untrusted JD content to drive parsing, keyword planting, ATS decisions, drafting, rendering, and versioning—so arbitrary third‑party pages could materially influence agent behavior.
Issues (1)
W011
MEDIUMThird-party content exposure detected (indirect prompt injection risk).
Audit Metadata