Applicant Screening Zh

Security checks across static analysis, malware telemetry, and agentic risk

Overview

This is a coherent instruction-only resume screening skill with no code, credentials, install steps, persistence, or hidden execution shown.

This skill appears safe to install as an instruction-only resume screening aid. Use it only with applicant data you are authorized to process, review its scoring for fairness and accuracy, and avoid treating automated rankings as final hiring decisions.

Static analysis

No static analysis findings were reported for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal

Risk analysis

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

The agent may read uploaded resume documents to produce screening reports.

Why it was flagged

The skill relies on document parsing and structure-analysis tools. This is expected for resume screening, but users should ensure only intended applicant documents are processed.

Skill content
Tools Required
- extract_text_from_pdf
- extract_text_from_docx
- analyze_document_structure
Recommendation

Use trusted document-extraction tools and provide only the resumes and job requirements intended for the screening task.

What this means

Applicant personal information could appear in the agent context or generated reports.

Why it was flagged

The skill processes resumes and produces candidate comparison outputs, which may include personal applicant information. The artifact does not show persistence or sharing, but the data is sensitive by nature.

Skill content
"帮我筛选这5份简历" ... "自动生成候选人对比表与面试优先级"
Recommendation

Avoid unnecessary personal details, follow applicable privacy and hiring rules, and do not store or share generated reports beyond approved recipients.