SkillAgentSearch skills...

job-application-agent

Privacy-first job Agent Skill for Claude/Cursor/Codex: verified facts only, OS secrets, confirmed submissions.

Install / Use

npx skills add vaibhavarora14/job-application-agent

Installs into whichever agent you are using.

About this skill
📄

SKILL.md

Installable skill definition

Quality Score

85/100

Category

Automation

Supported Platforms

Claude Code
Cursor
OpenAI Codex

Our assessment of job-application-agent

job-application-agent scores 85/100 on our quality scale, 1972nd of 2,896 Automation skills we index.

Its SKILL.md is 8.6 KB long, well organised into 10 sections with 9 code examples: a thorough specification that gives an agent plenty to work with.

It has 156 GitHub stars, a meaningful sign that others use it.

Substance
29/30
Structure
20/20
Description
12/15
Adoption
9/20
Freshness
15/15

Maintenance, license and trust

  • The repository was last updated 2 days ago, so job-application-agent is actively maintained.
  • Our last check on 2026-09-25 found the source still online.
  • It is released under the MIT license, a permissive license that allows use, modification and commercial use with attribution.
  • Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.

Safety scan

No issues found

Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful.

AI review by kimi-k2.7-code on 2026-09-24. Automated pattern scan on 2026-09-24. It catches known dangerous patterns, not every risk — read a skill before letting an agent act on it.

job-application-agent compared with similar skills

All 4 of these similar skills score higher than job-application-agent; compare them before choosing.

SkillScoreStarsUpdatedFormat
job-application-agent (this skill)by vaibhavarora14851562d agoSKILL.md
Agent-Reachby Panniantong10094.8k1d agoCLAUDE.md
Scraplingby D4Vinci10086.5k1d agoMCP Server
rufloby ruvnet10074.2ktodayMCP Server
algorithmic-artby anthropics100177.9k17d agoSKILL.md

Frequently asked questions

How do I install job-application-agent?
Run npx skills add vaibhavarora14/job-application-agent. The install tabs above show the steps for each supported agent.
Which AI agents does job-application-agent work with?
It is written for Claude Code, Cursor and OpenAI Codex, as a SKILL.md file. Other agents that read the same format can often use it too.
Is job-application-agent safe to use?
Our scan of the whole file found no instruction hijacking, hidden characters, credential access, data exfiltration or destructive commands. An AI review of the same text found nothing harmful. It is MIT-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
Is job-application-agent still maintained?
The repository was last updated 2 days ago, so job-application-agent is actively maintained.
<div align="center">

💼 Job Application Agent

Find better roles, apply with verified facts, and learn from outcomes.

Validate npm MIT License Agent Skills

Get started · Safety · Privacy · Dashboard · Security

</div>

Job Application Agent is an Agent Skill that helps a coding agent discover, evaluate, complete, and track your own job applications. It uses one verified résumé, checks eligibility and duplicates, and records only confirmed submissions.

🚀 Get started

Install it:

npx job-application-agent@latest install

Then tell your coding agent:

Use job-application-agent to onboard my résumé and job preferences.

After onboarding, use natural commands:

search jobs
list discovery sources for India and global remote engineering
apply https://company.example/jobs/123
apply all relevant jobs from this thread: <URL>
run a round of 10
show attention queue
record outcome Company — Senior Engineer — interview

Requires Node.js 20 or newer and a browser-capable coding agent.

On Linux, profile storage uses the Secret Service via the secret-tool CLI. Install it with sudo apt-get install libsecret-tools (Debian/Ubuntu) or the equivalent package manager command for your distribution.

Unlike macOS Keychain or Windows Credential Manager, the Linux Secret Service has no always-running system daemon: a keyring daemon (GNOME Keyring, KWallet, or similar) must be running in the user session for secret-tool to store or read the profile. On a desktop login this is normally already the case; on headless servers, containers, or SSH-only sessions, start one explicitly (e.g. gnome-keyring-daemon --unlock --components=secrets) before first use.

✨ What it does

| Stage | Behavior | |---|---| | Discover | Searches a shared, versioned catalog of direct careers, ATS platforms, networks, feeds, and job boards, then verifies every lead at the employer. | | Qualify | Checks seniority, skills, location, authorization, compensation, and posting status. | | Apply | Fills forms and uploads one canonical résumé using verified facts only. | | Track | Deduplicates applications and records only visible submission confirmations. | | Improve | Reviews outcomes and proposes targeting changes without rewriting candidate facts. |

🤖 Choose your autonomy level

  • review-each — review every completed application before submission.
  • routine-auto — allow routine submissions while keeping sensitive and judgment-heavy steps with you.

For durable autonomy across resumable or scheduled runs:

echo '{"mode":"routine-auto"}' | node ~/.agents/skills/job-application-agent/scripts/job-application.mjs autonomy grant --stdin

Check or revoke it at any time:

node ~/.agents/skills/job-application-agent/scripts/job-application.mjs autonomy status
node ~/.agents/skills/job-application-agent/scripts/job-application.mjs autonomy revoke

🛡️ Safety

The agent pauses for:

  • passwords, SSO, MFA, and CAPTCHA;
  • legal attestations and government identifiers;
  • demographic or voluntary self-identification questions;
  • unclear work authorization, sponsorship, location, or compensation;
  • claims that cannot be verified from your profile or résumé;
  • browser or operating-system permission prompts.

It never reads browser cookies or session files, bypasses access controls, or counts a filled form as a submission.

🧭 How it works

flowchart LR
    A["Verified résumé + profile"] --> B["Find active roles"]
    B --> C["Check fit + duplicates"]
    C --> D["Fill truthful application"]
    D --> E{"Needs you?"}
    E -- Yes --> F["Attention queue"]
    E -- No --> G["Submit"]
    F --> G
    G --> H["Confirm + record"]

The bundled CLI handles private profile storage, résumé import, scoring, duplicate checks, resumable rounds, attention queues, and application/outcome ledgers. The coding agent handles discovery and browser interaction under the rules in SKILL.md.

Discovery combines the reviewed SOURCES.json catalog with an anonymous community registry. Every confirmed application automatically contributes its canonical public job URL, company, role, application channel, and provider; prior confirmed ledger entries backfill during later commands after a one-command disclosure grace period. Jobs, repeatable boards, and feeds are logged pending and become visible in the public dashboard or CLI only after maintainer review. Disable both forms of community sharing independently from analytics with sources sharing disable.

🔐 Privacy

| Data | Where it stays | |---|---| | Profile | macOS Keychain, Windows Credential Manager, or Linux Secret Service (libsecret) | | Résumé and ledgers | Owner-only local state directory | | Browser login | Existing browser session | | Community-sharing preference and delivery receipts | Owner-only local state directory | | Skill code | Version-controlled installation directory |

Candidate data, résumés, application history, credentials, and browser sessions are never committed to this repository.

Anonymous structured analytics are enabled by default to improve the agent. They may include job and workflow categories, but never candidate identity, résumé content, prompts, answers, browser data, IP addresses, or raw errors.

Anonymous community sharing is also enabled by default, separately from analytics. Confirmed applications share only a canonical public job URL, company, role, application channel, optional coarse discovery source, and derived provider URL—never candidate identity, answers, résumé, score, referral parameters, or submission timestamp. Repeatable discovery surfaces share their bounded catalog metadata through a maintainer-review queue. The registry stores no raw installation IDs; record-scoped contributor hashes are used only for deduplication and counts, never as identity or publication authority.

node ~/.agents/skills/job-application-agent/scripts/job-application.mjs telemetry status
node ~/.agents/skills/job-application-agent/scripts/job-application.mjs telemetry disable
node ~/.agents/skills/job-application-agent/scripts/job-application.mjs sources sharing status
node ~/.agents/skills/job-application-agent/scripts/job-application.mjs sources sharing disable
node ~/.agents/skills/job-application-agent/scripts/job-application.mjs sources jobs

See ANALYTICS.md for the event contract and retention policy, or view the public aggregate dashboard.

<details> <summary><strong>Installation and update details</strong></summary>

The installer places the skill at ~/.agents/skills/job-application-agent and enables automatic updates by default. Compatible vendor skill directories are also supported when they already exist.

npx job-application-agent@latest status
npx job-application-agent@latest update
npx job-application-agent@latest updates disable
npx job-application-agent@latest updates enable

Updates are staged and validated before replacement. Private candidate state lives outside the replaceable skill directory.

</details>

🧰 Develop

npm test

GitHub Actions validates the skill and runs the same test suite on every pull request. See CONTRIBUTING.md for the full local verification and review contract. To try the workflow without installing, paste SHARE_PROMPT.md into a new agent chat.

⚖️ Responsible use

Use this project only for your own job search. It does not guarantee interviews, offers, eligibility, or application accuracy. Never use it to impersonate another person, bypass CAPTCHA, evade access controls, or make deceptive claims.

Report privacy or security issues through the process in SECURITY.md. Do not open a public issue containing personal data or application records.

Released under the MIT License.

Related Skills

View on GitHub
GitHub Stars156
CategoryAutomation
Updated2d ago
Forks23

Languages

JavaScript

Trust signals

100/100

From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.

No cautions