Back to skill

Security audit

ApplyTOP

Security checks for vulnerabilities and agentic risk

Overview

This skill is a disclosed guide for using the ApplyTop CLI/API, with expected authentication and credit-spending behavior clearly described.

Install only if you trust the ApplyTop service and npm package, and understand that the CLI can access your ApplyTop account data and CVs using your API key. Review credit usage before running cvs:tailor, cvs:cover-letter, or cvs:ats-score, and prefer an environment variable or logout flow if you do not want credentials left in ~/.applytop/credentials.json.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.