Workopia

v1.0.2

Search jobs, build professional resumes, and get career advice using Workopia's MCP server. Use when users ask about job searching, finding jobs, resume buil...

0· 48·0 current·0 all-time
MIT-0
Download zip
LicenseMIT-0 · Free to use, modify, and redistribute. No attribution required.
Security Scan
Capability signals
CryptoCan make purchases
These labels describe what authority the skill may exercise. They are separate from suspicious or malicious moderation verdicts.
VirusTotalVirusTotal
Benign
View report →
OpenClawOpenClaw
Benign
high confidence
Purpose & Capability
Name/description (job search, resume building, career advice) match the instructions: the SKILL.md tells the agent to add a remote MCP server (https://workopia.io/api/mcp-gpt) and then use three tools (job_tool, resume_tool, career_tool). There are no unrelated environment variables or binaries required.
Instruction Scope
The runtime instructions are limited: they only instruct adding a remote MCP server and using the listed tools. The SKILL.md does not instruct the agent to read local config files, credentials, or unrelated paths. Important privacy note: using the skill will send user-provided content (job queries, resume text/files) to the external Workopia MCP endpoint — this is expected for the stated purpose but means PII may be transmitted to that server.
Install Mechanism
Instruction-only skill with no install spec and no code files — nothing is downloaded or written to disk by an installer. This is the lowest-risk install profile.
Credentials
No environment variables, credentials, or config paths are requested — proportional to the described purpose. The SKILL.md claims no logging or storage and no auth is required; these privacy/security guarantees are plausible but cannot be verified from the instruction-only manifest alone.
Persistence & Privilege
always is false and the skill does not request persistent system-wide privileges or modify other skill configs. Autonomous invocation is allowed by default (normal for skills) but does not combine with any other elevated privilege here.
Assessment
This skill is coherent with its stated purpose, but it operates by sending user queries and any resume text/files to an external MCP server (https://workopia.io/api/mcp-gpt). Before installing or enabling it: (1) review Workopia's privacy policy and contact info; (2) test the skill only with non-sensitive data first (avoid pasting full SSNs, private addresses, or confidential company details); (3) prefer providing resume text rather than uploading raw files if you want to reduce accidental metadata leakage; and (4) if you need stronger guarantees, ask the vendor for an auditable data-handling statement or consider running a comparable tool you control locally. The SKILL.md's privacy claims cannot be independently verified from this manifest alone.

Like a lobster shell, security has layers — review code before you run it.

latestvk974qnr60726fzpxb9w30vyyw984dqk1

License

MIT-0
Free to use, modify, and redistribute. No attribution required.

Runtime requirements

🦞 Clawdis

Comments