resume-builder
Audited by Socket on Mar 7, 2026
1 alert found:
Obfuscated FileThe skill's footprint is coherent with its stated purpose: it focuses on structured data collection from the user and generates resume/LinkedIn content, saving outputs to local, well-scoped paths without evident external credential handling or autonomous real-world actions. The main concerns are around data protection of user-provided personal/professional information and ensuring that local files are stored securely and overwritten only with clear user intent. Overall, the design is BENIGN with low to moderate security risk, given proper handling of local data and trusted MCP endpoints. Maintain explicit prompts for sensitive actions and consider adding data-at-rest protections and explicit user consent for storing sensitive information.