resume-manager

Warn

Audited by Snyk on Feb 18, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W011: Third-party content exposure detected (indirect prompt injection risk).

  • Third-party content exposure detected (high risk: 0.70). The skill explicitly asks users to provide links to online resumes/LinkedIn profiles in Step 2 ("Provide a link to your online resume/LinkedIn profile") and to paste/share job descriptions in Step 3.1, and states it will extract and parse that content—i.e., ingesting untrusted public third‑party/user‑generated content.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Feb 18, 2026, 12:02 AM