Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add suxrobGM/jobpilot --skill review-resumegit clone --depth 1 https://github.com/suxrobGM/jobpilotWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/suxrobgm/jobpilot/review-resume)<a href="https://agentmods.dev/skills/suxrobgm/jobpilot/review-resume"><img src="https://agentmods.dev/badge/skills/suxrobgm/jobpilot/review-resume/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/suxrobgm/jobpilot/review-resume"><img src="https://agentmods.dev/badge/skills/suxrobgm/jobpilot/review-resume.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector warn
SkillSpector: 1 finding, up to medium
These are SkillSpector’s own severities. On a checked sample its high-severity flags on skills were ~96% false positives — a documented command, a public API, a “never do X” rule — so we show them as a caution to read, not a verdict. Why →
- medium Data Exfiltration · line 18 Data is being sent to an external URL. This could be legitimate telemetry or data exfiltration. Manual review is recommended.Fix: Verify the destination URL is trusted and necessary. Remove or replace with documented APIs. Ensure no secrets, tokens, or PII are transmitted.
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00028 | $0.00797 |
| Opus 5 | $0.00014 | $0.00398 |
| Sonnet 5 | $0.00006 | $0.00159 |
| Haiku 4.5 | $0.00003 | $0.00080 |
Grade A, and why
review-resume scanned grade A with 1 finding against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Makes network callslowCapability
Not a fault in itself. Listed so you know the mod talks to something, and to what.
curl -fsS -H "authorization: Bearer $JOBPILOT_API_TOKEN" "$JOBPILOT_API/api/resumes/$RESUME_ID" How it starts
The opening of the file, as written. The whole thing — 64 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Review Resume
Save one improved version of a base resume as a Suggested rewrite variant. The user accepts or discards it in the dashboard. Never write to the base resume.
Runs after extract-resume on upload: extraction is faithful to the PDF, this pass makes the document better.
Setup
Follow ../_shared/setup.md, then:
curl -fsS -H "authorization: Bearer $JOBPILOT_API_TOKEN" "$JOBPILOT_API/api/resumes/$RESUME_ID"
content: null → extraction hasn't run; say so and stop. Also Read the source PDF (path per ../_shared/setup.md) - extraction flattens two-column layouts and drops emphasis.
What to improve
For a human screener skimming, and the ATS parsing:
summary- what they do, at what level, two strongest specifics. Cut anything true of every candidate.basics.headline- a role title people search for, not a slogan.- Bullets - outcome first, consistent tense, no "Responsible for" / "Worked on" / "Helped with". Remove phrasing repeated across entries - one stock phrase in three roles flattens all three.
- Skill groups - consolidate. Past ~5 groups it reads as a keyword dump.
- Ordering - most relevant experience and projects first.
Then run the humanizer skill in embedded mode on the summary and bullets.
Rules
The user sees a diff and clicks accept, so the diff is the guard - not a server check:
- Wording, ordering, emphasis, grouping. Never facts. No employer, date, title, degree, school, or number absent from the extracted content or the source PDF. Not a rounded metric, not an inferred date, not a "Senior" added to a title.
diffNoteslists every change, one per line, specific enough to check:Summary: rewritten to lead with the HIPAA platform. A change not in the notes is one the user can't decline - if you can't list it, don't make it.- Keep every entry. Dropping or merging roles is
tailor-resume, which has server-side guards. - Don't touch
basicscontact fields. At onboarding the resume fills the profile, so it's the source of truth. - If the resume is already good, save nothing and say so. A suggestion the user rejects teaches them to ignore the next one.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 64 lines · 28 tokens per session scan A 9fd71aa11270
review-resume is a skill published in the GitHub repository suxrobGM/jobpilot (67 stars, last pushed yesterday), licensed MIT. It adds 28 tokens to every session and 797 once invoked, about $0.0001 per session on Opus 5. A static security scan graded it A with 1 finding (makes network calls). No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
resume
Generate a tailored resume AND cover letter for a job description via the native four-role Resume Team, score both against ATS and HR rubrics, create DOCX files, and update the tracker. Use when the user pastes a job description and wants a complete application package (resume plus cover letter) with dual scoring and…
cover-letter
Create a compelling one-page, human-voice cover letter for a job description and generate the final DOCX. Use when the user wants a cover letter only (no resume), pastes a JD and asks for a letter, or needs a letter to accompany an already-tailored resume. Runs the mandatory humanvoiceaudit before producing the DOCX.
tailor-resume
Tailor a resume to a job description via the native four-role Resume Team, evidence-match it against the job's requirements, create a DOCX, and update the tracker. Use when the user pastes a job description and wants a tailored resume only (no cover letter), targeting an evidence match that covers every must-have with…
batch-resume
Process multiple job descriptions from the batchjds folder into tailored application packages, each produced by the native Resume Team, with independent candidate-fit gates and ordered DOCX and tracker writes. Use when the user has several JDs to run at once, drops files in batchjds, or asks for batch or bulk resume…
search
This skill should be used when the user wants to check if a company or job URL is already in their tracker, or list all applications for a company. Triggers on phrases like "have I applied to [company]", "is [company] in tracker", "check [url]", "already applied [url]", "search [company]", "what jobs do I have at…
cover-letter
Generate a tailored cover letter for a job posting URL. Triggers on /cover-letter, "cover letter ", "generate cover letter for [company]", "write cover letter for [url]", "draft cover letter [company]".