Four review lenses stop the model from pretending it is an ATS
Cyber Resume Reviewer organizes its work around machine-read, human-skim, human-believe, and human-act checks. Those labels sound tidy, but the important part is what the skill refuses to infer. Keyword overlap cannot become a qualification claim, a fit percentage, an ATS score, or a forecast of an interview. A listed skill without an example is described as uncorroborated in the document, not false.
That restraint fits cybersecurity resumes, where a small wording change can turn "supported" into "led" or a lab exercise into production experience. The skill tells the agent to preserve employers, dates, role boundaries, credential status, team attribution, and the setting in which work occurred. It also separates candidate facts, employer requirements, reviewer inference, and unknowns. That is the main reason to use it instead of dropping a resume into a generic chat.
v4.1 is a portable skill package, not a resume application
Release v4.1 packages the same material in two forms: a root-level .skill archive and a wrapped ZIP for Claude's uploader. The repository documents installation for Codex, Claude Code, Claude web, ChatGPT desktop, Gemini CLI, and Gemini Spark. Each surface handles directories, uploads, permissions, and invocation differently. There is no web interface here, no applicant database, and no recruiter dashboard.
The package itself contains a large instruction file, role and evidence references, report templates, a text analyzer, a JSON validator, and a PDF renderer. A typical request can ask for a full review, a short review, a job-description fit report, exact edits, or a complete rewrite. Scoring is optional and applies to the document, not the candidate's worth or hiring odds. That boundary is unusually explicit.
What happened when we ran it
Our sandbox did not run commit 263acc3. Although GitHub classifies the repository as Python, our runner found no supported executable ecosystem for this package, and the repository has no Dockerfile for a container path. We therefore have no measured installation, build, or test outcome. Saying that the Python helpers passed would be fiction.
This result also reflects the shape of the project. The product is primarily an Agent Skill consumed by another host, while Python supports analysis, validation, packaging, and PDF creation. The repository does include a smoke-test command in its maintainer guide, and its publishing workflow runs that check before assembling release archives. We did not execute that path, so it remains upstream evidence rather than our result.
A styled PDF requires more than copying the skill
The lightest setup is an archive copied into the correct skills folder. The complete report path is heavier. Its README calls for Python 3.9 or newer, PyYAML, Beautiful Soup, a Markdown converter, WeasyPrint or wkhtmltopdf, and Poppler utilities including pdftoppm, pdftotext, pdfinfo, and pdffonts. The renderer creates page images so the agent can inspect every page before delivery.
If those tools are unavailable, the instructions allow a Markdown-only result and require the agent to say that PDF generation was unavailable. This is sensible failure behavior, though it means two people using the same skill on different hosts may receive different artifacts. Pasted resume text has a similar limit: content can be reviewed, while layout and original reading order must be marked not assessed.
The truth rules do more work than the templates
The strongest material sits in the constraints. Live candidate data must stay out of reusable examples, logs, fixtures, and source history. A job description cannot donate experience to the candidate. Metrics are optional, and the agent is told not to manufacture numbers merely to sharpen a bullet. Even the visual design cannot smuggle in a claim through proficiency bars, letter grades, match rings, or traffic-light judgments.
There are practical tradeoffs. A careful review needs the original file, a target role or job description when tailoring matters, and a person willing to answer open questions. The skill cannot certify ATS acceptance because employer parsers differ. It also cannot replace hiring judgment, and it deliberately will not rank applicants. Buyers seeking automatic screening should walk away rather than remove the rules that make this package trustworthy.
A September 20 push shows maintenance, while adoption is still young
The repository was pushed on September 20, 2026, less than two weeks after its September 7 creation. GitHub showed 180 stars and one open issue-or-pull-request entry on October 1. That entry is a pull request about replacement text appearing in the original-text box, a narrow report correctness fix rather than evidence of broad user support.
The latest GitHub release is v4.1, published September 7 as the initial public release. Recent source activity and a release workflow are good signs, but they do not establish years of compatibility across every named host. Start with a redacted resume, inspect the Markdown, and compare the PDF against its source before trusting it with a real application. The skill's own rules ask you to make those checks, and our lab result gives no reason to skip them.