resume-tailor

Warn

Audited by Snyk on May 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.90). The skill explicitly accepts a job description URL to be fetched and parsed (see "Required inputs" and "Phase 1 — JD ingestion" in SKILL.md), and it reads and uses that public/untrusted JD content to drive parsing, keyword planting, ATS decisions, drafting, rendering, and versioning—so arbitrary third‑party pages could materially influence agent behavior.

Issues (1)

W011
MEDIUM

Third-party content exposure detected (indirect prompt injection risk).

Audit Metadata
Risk Level
MEDIUM
Analyzed
May 18, 2026, 05:57 PM
Issues
1
Security Audit — snyk — resume-tailor