Privacy-first job Agent Skill for Claude/Cursor/Codex: verified facts only, OS secrets, confirmed submissions.
# Add to your Claude Code skills
git clone https://github.com/vaibhavarora14/job-application-agentGuides for using ai agents skills like job-application-agent.
Last scanned: 8/19/2026
{
"issues": [],
"status": "PASSED",
"scannedAt": "2026-08-19T04:36:09.039Z",
"npmAuditRan": true,
"pipAuditRan": true,
"promptInjectionRan": true
}See how job-application-agent compares with popular alternatives.
job-application-agent is an open-source ai agents skill for AI coding assistants such as Claude Code, Codex CLI, and ChatGPT, built by vaibhavarora14. Privacy-first job Agent Skill for Claude/Cursor/Codex: verified facts only, OS secrets, confirmed submissions. It has 153 GitHub stars.
Yes. job-application-agent passed SkillsLLM's automated security scan — a dependency vulnerability audit plus prompt-injection heuristics — with no high-severity issues. You can read the full report in the Security Report section on this page.
Clone the repository with "git clone https://github.com/vaibhavarora14/job-application-agent" and add it to your Claude Code skills directory (see the Installation section above).
job-application-agent is primarily written in JavaScript. It is open-source under vaibhavarora14 on GitHub, so you can review or fork the full source.
Yes. SkillsLLM lists many other AI Agents skills you can browse and compare side by side. Open the AI Agents category from the badge at the top of this page, or use the Related Skills and comparison links further down to weigh job-application-agent against similar tools.
No comments yet. Be the first to share your thoughts!
Based on votes and bookmarks from developers who liked this skill
⚠️ Third-Party Software Notice
This skill is third-party open-source software developed and hosted independently on GitHub. SkillsLLM is an informational directory and does not control or maintain the underlying repository.
Any security checks, ratings, or warnings displayed by SkillsLLM are automated and limited in scope. They do not constitute a security certification or guarantee that the software is safe, error-free, or free from malicious code, vulnerabilities, compromised dependencies, or prompt-injection risks.
Review the source code, permissions, dependencies, and configuration before installing or running any third-party skill. Use is at your own risk. To the maximum extent permitted by applicable law, SkillsLLM is not liable for losses arising from third-party software.
Get started · Privacy in 30 seconds · Safety · Privacy · Where to find it · Dashboard · Security
npx job-application-agent@latest install
npx skills add vaibhavarora14/job-application-agent
Job Application Agent is an Agent Skill that helps a coding agent discover, evaluate, complete, and track your own job applications. It uses one verified résumé, checks eligibility and duplicates, and records only confirmed submissions.
Install it with either:
npx job-application-agent@latest install
npx skills add vaibhavarora14/job-application-agent
Then tell your coding agent:
Use job-application-agent to onboard my résumé and job preferences.
After onboarding, use natural commands:
search jobs
list discovery sources for India and global remote engineering
apply https://company.example/jobs/123
apply all relevant jobs from this thread: <URL>
run a round of 10
show attention queue
record outcome Company — Senior Engineer — interview
Requires Node.js 20 or newer and a browser-capable coding agent.
Setup templates are available for Hermes Agent, Grok Bot, and OpenClaw:
npx job-application-agent@latest platforms
npx job-application-agent@latest platforms hermes
Replace hermes with grok or openclaw for that guide. These commands print
instructions only; they do not install a Bot, change agent settings, or access
candidate state. Browse the platform guides.
Each template starts in review mode and requires browser validation on its host.
The Grok Bot native share link is pending; use the setup prompt in the guide.
The existing installer also supports Codex, Claude Code, Cursor, Copilot, and
Gemini skill directories when present.
On Linux, profile storage uses the Secret Service via the secret-tool CLI. Install it with sudo apt-get install libsecret-tools (Debian/Ubuntu) or the equivalent package manager command for your distribution.
Unlike macOS Keychain or Windows Credential Manager, the Linux Secret Service has no always-running system daemon: a keyring daemon (GNOME Keyring, KWallet, or similar) must be running in the user session for secret-tool to store or read the profile. On a desktop login this is normally already the case; on headless servers, containers, or SSH-only sessions, start one explicitly (e.g. gnome-keyring-daemon --unlock --components=secrets) before first use.
For one person's agents across several trusted hosts, an optional private Cloudflare D1 backend with R2 (or a private Workers KV blob fallback) shares profile, résumé, application, outcome, round, answer, and attention state. Each host receives a separate revocable credential, and one renewable lease ensures only one host submits applications at a time. See CLOUD_STATE.md.
| Stage | Behavior |
|---|---|
| Discover | Searches a shared, versioned catalog of direct careers, ATS platforms, networks, feeds, and job boards, then verifies every lead at the employer. |
| Qualify | Checks seniority, skills, location, authorization, compensation, and posting status. |
| Apply | Fills forms and uploads one canonical résumé using verified facts only. |
| Track | Deduplicates applications and records only visible submission confirmations. |
| Improve | Reviews outcomes and proposes targeting changes without rewriting candidate facts. |
An optional outreach companion
qualifies contacts, stores drafts, prepares manual handoffs, and tracks replies
privately. Run job-application-agent outreach policy status to inspect it.
It is disabled by default, performs no automated LinkedIn/X access or sending,
and keeps outreach counts separate from applications. Cloud use requires the
outreach-tracking-v1 private-state migration; local use works with the managed
npm installation on Node 20 or later.
review-each — review every completed application before submission.routine-auto — allow routine submissions while keeping sensitive and judgment-heavy steps with you.For durable autonomy across resumable or scheduled runs:
echo '{"mode":"routine-auto"}' | node ~/.agents/skills/job-application-agent/scripts/job-application.mjs autonomy grant --stdin
Check or revoke it at any time:
node ~/.agents/skills/job-application-agent/scripts/job-application.mjs autonomy status
node ~/.agents/skills/job-application-agent/scripts/job-application.mjs autonomy revoke
The agent pauses for:
It never reads browser cookies or session files, bypasses access controls, or counts a filled form as a submission.
flowchart LR
A["Verified résumé + profile"] --> B["Find active roles"]
B --> C["Check fit + duplicates"]
C --> D["Fill truthful application"]
D --> E{"Needs you?"}
E -- Yes --> F["Attention queue"]
E -- No --> G["Submit"]
F --> G
G --> H["Confirm + record"]
The bundled CLI handles private profile storage, résumé import, scoring, duplicate checks, resumable rounds, attention queues, and application/outcome ledgers. The coding agent handles discovery and browser interaction under the rules in SKILL.md.
For text assists—JD parse, fit-score rationale, short why-company drafts—you can point an OpenAI-compatible client at Free.ai when your agent host supports a custom base URL and API key:
https://api.free.ai/v1FREE_AI_API_KEY from free.ai/accountqwen7bThis is optional and assistive only. The skill CLI does not call Free.ai; deterministic score, ledger, lease, and intent commands remain the source of truth. Free.ai is not the hosted cloud apply loop, headed browser fill/submit path, or Antigravity/Codex default. Prefer own-hardware models for the OSS/grant path—not premium third-party models. Details: FREE_AI.md.
Discovery combines the reviewed SOURCES.json catalog with an anonymous community registry. Every confirmed application automatically contributes its canonical public job URL, company, role, application channel, and provider; prior confirmed ledger entries backfill during later commands after a one-command disclosure grace period. Jobs, repeatable boards, and feeds are logged pending and become visible in the public dashboard or CLI only after maintainer review. Disable both forms of community sharing independently from analytics with sources sharing disable.
New rounds derive reviewed and qualified totals from private per-lead records, including rejection reasons and revision history. Delivery reconciliation subtracts verified failed emails from effective application totals without erasing history; email access is optional, and sent email without acknowledgement remains labelled receipt unknown. See accounting.
Rounds require recorded attempts across at least three distinct discovery sources, including a successful search, and source attribution for confirmed submissions. If more than 60% of submissions come from one source, the agent must explain the concentration. Blockers and empty results are reported; fit requirements never change to meet a source quota. See round coverage.
| Data | Where it stays |
|---|---|
| Profile | OS credential store, or private D1 with an owner-only local cache |
| Analytics name and email (unless opted out) | Private PostHog events after disclosure; local sharing preference in owner-only state |
| Résumé and ledgers | Owner-only local state, or private D1 plus private blob storage when configured |
| Browser login | Existing browser session |
| Community-sharing preference and delivery receipts | Owner-only local state directory |
| Skill code | Version-controlled installation directory |
Candidate data, résumés, application history, credentials, and browser sessions are never committed to this repository.
Private cloud state is opt-in and isolated from public analytics/community services