Borrowing it
Nothing to install: this file belongs to galiprandi/job-seeker. Take a copy, put it at the same path in your own repository, and replace the rules that are about this project with yours.
curl -O https://raw.githubusercontent.com/galiprandi/job-seeker/main/.agents/skills/referrals/SKILL.mdgit clone --depth 1 https://github.com/galiprandi/job-seekerWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/galiprandi/job-seeker/referrals)<a href="https://agentmods.dev/skills/galiprandi/job-seeker/referrals"><img src="https://agentmods.dev/badge/skills/galiprandi/job-seeker/referrals/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/galiprandi/job-seeker/referrals"><img src="https://agentmods.dev/badge/skills/galiprandi/job-seeker/referrals.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00055 | $0.01411 |
| Opus 5 | $0.00028 | $0.00705 |
| Sonnet 5 | $0.00011 | $0.00282 |
| Haiku 4.5 | $0.00006 | $0.00141 |
Grade A, and why
referrals scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured today.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 119 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Warm Sourcing & Referrals
Trigger
Keyword: referrals (or variants: "warm sourcing", "buscar contactos", "solicitar referido")
The user says referrals or launches warm sourcing for a target company/role. Also executed as step 0 of the apply and targets flows to maximize conversion.
Flow
0. Pre-flight
- Verify active browser session (see AGENTS.md "Browser session"):
node scripts/browser.js open <url> --headed(Gold Rule 5) if session closed - Load profile, university background, past companies, and job preferences from Postgres DB:
node scripts/db.js "SELECT data->'profile' AS profile, data->'job_preferences' AS prefs, data->'style_profile' AS style FROM users WHERE id = <user_id>" - Load strategy (see AGENTS.md "Strategy levels"):
Respect:node scripts/db.js "SELECT data->'strategy' AS strategy FROM users WHERE id = <user_id>"cold_outreach(gates the recruiter-outreach branch in step 3). Ifreferralsis not insources_active, the flow should not run standalone — when invoked as step 0 ofapply/targets, those flows handle the gate. - Load active preferences (see
memoryskill):node scripts/db.js "SELECT category, key, value, confidence, source FROM preferences WHERE user_id = <user_id> AND status = 'active' ORDER BY category, key"
1. Warm Contact & Recruiter Discovery
For a target company and role:
# Automated discovery script
node scripts/linkedin-warm-sourcing.js --company "<Company>" --role "<Role>" --json
The script searches for:
- 1st & 2nd degree connections currently working at
<Company> - University alumni (matching institutions from
users.data.profile.education) - Ex-colleagues (matching past employers from
users.data.profile.experience) - Recruiters & Hiring Managers assigned to the role/company
2. Referral Request Staging (Highest Conversion — Strategy #1)
If an internal contact, alumni, or ex-colleague is found:
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- today Changed 0607e57d15ad
- 11d ago First seen · 119 lines · 55 tokens per session scan A ab63cc114c16
referrals is a skill published in the GitHub repository galiprandi/job-seeker (26 stars, last pushed yesterday), licensed MIT. It adds 55 tokens to every session and 1,411 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
Application Form Filler
Fill out job application form fields with context-aware, tailored answers drawn from the candidate's CV and the job description.
ai-dev-jobs-mcp
Search 8,400+ AI and ML jobs across 489 companies, inspect listings and employers, match roles, and view salary and market stats via AI Dev Jobs MCP.
job-application-agent
Finds, evaluates, fills, submits, and tracks a candidate's own job applications using a verified resume, evidence-based targeting, secure local profile storage, and browser automation. Use for onboarding or migrating a job-search profile, searching active roles, assessing a posting, applying to an authorized URL or…
apply
Apply to a single job (URL or pasted page) with fit review, or score and apply the job links pasted into an apply campaign when no argument is given.
scan-inbox
Classify unscanned mailbox messages, fuzzy-match each to an existing application, and write the proposal back. The user approves in /inbox.
resume-campaign
Resume a paused JobPilot campaign by id. Re-flips the campaign to inprogress and replays the apply loop on any remaining approved jobs without re-asking for fit confirmation.