Resume Screener Pro

AdvisoryAudited by Static analysis on Apr 30, 2026.

Overview

No suspicious patterns detected.

Findings (0)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Private candidate information may be included in the conversation, and candidate-provided text could influence the generated screening output.

Why it was flagged

The skill expects the agent to process résumé and job-description content. This is central to the stated purpose, but résumés can contain personal and untrusted candidate-provided information; the artifacts do not show persistence or external sharing.

Skill content
输入 - 候选人简历(PDF/DOCX/TXT) - 岗位JD
Recommendation

Only upload résumés you are authorized to process, treat résumé text as evidence rather than instructions, and avoid retaining or sharing outputs beyond the hiring need.

What this means

An agent’s scores or recommendations could influence hiring outcomes if users over-trust them.

Why it was flagged

The skill is explicitly designed to produce final candidate recommendations. This is purpose-aligned, but hiring recommendations are high-impact advice and should not be treated as automated decisions.

Skill content
阶段四:最终推荐 ... 最终结论 ... 强烈推荐 / 推荐 / 谨慎推荐 / 不推荐
Recommendation

Use the output as decision support only; have qualified humans review the evidence, criteria, bias risks, and legal or HR compliance requirements before acting.

What this means

The version mismatch may make it harder to confirm exactly which version was reviewed or installed.

Why it was flagged

The supplied registry metadata and SKILL description identify version 3.0.0, while _meta.json reports 1.0.1. Because there is no executable code or install step, this is a packaging/provenance note rather than a security concern.

Skill content
"version": "1.0.1"
Recommendation

Verify the intended package/version with the publisher or registry before relying on it in a formal workflow.