mrkeyoor.com_
Thu 01 Oct 08:09 UTC
AI Toolsevaluationupdated 01 Oct 2026

cyber-resume-reviewer-skill review

Cyber Resume Reviewer is an Agent Skill that tells an AI assistant how to critique, tailor, score, or rewrite IT and cybersecurity resumes without inventing evidence. It can produce a Markdown report and a matching PDF, but it is a set of instructions, references, templates, and local helpers rather than a standalone hiring app.

Verdict

Our sandbox produced no install, build, or test result for commit 263acc3 because the runner found no supported executable ecosystem and the repo has no Dockerfile. Treat Cyber Resume Reviewer as a well-specified editorial workflow, not as lab-proven resume software. Use it when you already have a compatible agent host and value its strict evidence rules; choose a dedicated resume app when you need a visual editor, bulk screening, or a fixed runtime.

We ran it

Answers from our run

Did you run cyber-resume-reviewer-skill yourself?

No. Its code is Python, and it carries no manifest our lab installs from, and no Dockerfile, so there was nothing standard to install, build or test. This review is written from the repository's own documentation.

Who should not use cyber-resume-reviewer-skill?

Recruiters building candidate ranking or interview prediction software: the skill expressly refuses both jobs.

What are the alternatives to cyber-resume-reviewer-skill?

OpenResume, Reactive Resume, Resume Matcher. Treat Cyber Resume Reviewer as a well-specified editorial workflow, not as lab-proven resume software.

Setup3/5Archive setup is simple; the verified PDF path needs several tools
Docs5/5Host differences, limits, inputs, outputs, and PDF needs are explicit
Community2/5180 stars and one open pull request in a repo created in September
Maturity2/5A recent v4.1 release, but no executable result from our lab

Who it’s for

Security practitioners who want a candid resume review tied to a specific job description.
Career coaches who want exact edits while keeping employer, title, date, and scope claims faithful to the source.
Claude Code, Codex, Gemini CLI, or compatible Agent Skills users who can inspect the result before sending it.
Teams that want Markdown and PDF review artifacts from the same source text.

Who it’s NOT for

Recruiters building candidate ranking or interview prediction software: the skill expressly refuses both jobs.
ChatGPT web or mobile users expecting a direct upload from this repository: the README says those surfaces require plugin distribution, which the project does not provide.
Anyone submitting pasted text and expecting layout assurance: the skill marks visual layout and original-file parsing as not assessed without a PDF or DOCX.
Locked-down hosts that cannot execute Python or PDF tools: the styled report path needs code execution plus a renderer and several PDF inspection utilities.
High-volume screening systems that cannot support human review: the workflow requires factual traceability and page-by-page inspection of generated PDFs.

Setup reality

We did not run commit 263acc3 in our sandbox. The runner found no supported executable ecosystem for this Python-classified repository, and there was no Dockerfile to provide a fallback path, so we have no install, build, or test result to report.

The basic installation is copying a release archive into a host-specific skills directory or uploading it through a supported interface. A full styled PDF needs Python 3.9 or newer, Markdown or pandoc, a PDF renderer, and Poppler tools for page and font checks.

The host matters. Claude Code, Codex, Gemini CLI, Claude web, ChatGPT desktop, and Gemini Spark have different package and permission rules. Pasted text supports content review only; source-file parsing and layout checks need the original PDF or DOCX.

Four review lenses stop the model from pretending it is an ATS

Cyber Resume Reviewer organizes its work around machine-read, human-skim, human-believe, and human-act checks. Those labels sound tidy, but the important part is what the skill refuses to infer. Keyword overlap cannot become a qualification claim, a fit percentage, an ATS score, or a forecast of an interview. A listed skill without an example is described as uncorroborated in the document, not false.

That restraint fits cybersecurity resumes, where a small wording change can turn "supported" into "led" or a lab exercise into production experience. The skill tells the agent to preserve employers, dates, role boundaries, credential status, team attribution, and the setting in which work occurred. It also separates candidate facts, employer requirements, reviewer inference, and unknowns. That is the main reason to use it instead of dropping a resume into a generic chat.

v4.1 is a portable skill package, not a resume application

Release v4.1 packages the same material in two forms: a root-level .skill archive and a wrapped ZIP for Claude's uploader. The repository documents installation for Codex, Claude Code, Claude web, ChatGPT desktop, Gemini CLI, and Gemini Spark. Each surface handles directories, uploads, permissions, and invocation differently. There is no web interface here, no applicant database, and no recruiter dashboard.

The package itself contains a large instruction file, role and evidence references, report templates, a text analyzer, a JSON validator, and a PDF renderer. A typical request can ask for a full review, a short review, a job-description fit report, exact edits, or a complete rewrite. Scoring is optional and applies to the document, not the candidate's worth or hiring odds. That boundary is unusually explicit.

What happened when we ran it

Our sandbox did not run commit 263acc3. Although GitHub classifies the repository as Python, our runner found no supported executable ecosystem for this package, and the repository has no Dockerfile for a container path. We therefore have no measured installation, build, or test outcome. Saying that the Python helpers passed would be fiction.

This result also reflects the shape of the project. The product is primarily an Agent Skill consumed by another host, while Python supports analysis, validation, packaging, and PDF creation. The repository does include a smoke-test command in its maintainer guide, and its publishing workflow runs that check before assembling release archives. We did not execute that path, so it remains upstream evidence rather than our result.

A styled PDF requires more than copying the skill

The lightest setup is an archive copied into the correct skills folder. The complete report path is heavier. Its README calls for Python 3.9 or newer, PyYAML, Beautiful Soup, a Markdown converter, WeasyPrint or wkhtmltopdf, and Poppler utilities including pdftoppm, pdftotext, pdfinfo, and pdffonts. The renderer creates page images so the agent can inspect every page before delivery.

If those tools are unavailable, the instructions allow a Markdown-only result and require the agent to say that PDF generation was unavailable. This is sensible failure behavior, though it means two people using the same skill on different hosts may receive different artifacts. Pasted resume text has a similar limit: content can be reviewed, while layout and original reading order must be marked not assessed.

The truth rules do more work than the templates

The strongest material sits in the constraints. Live candidate data must stay out of reusable examples, logs, fixtures, and source history. A job description cannot donate experience to the candidate. Metrics are optional, and the agent is told not to manufacture numbers merely to sharpen a bullet. Even the visual design cannot smuggle in a claim through proficiency bars, letter grades, match rings, or traffic-light judgments.

There are practical tradeoffs. A careful review needs the original file, a target role or job description when tailoring matters, and a person willing to answer open questions. The skill cannot certify ATS acceptance because employer parsers differ. It also cannot replace hiring judgment, and it deliberately will not rank applicants. Buyers seeking automatic screening should walk away rather than remove the rules that make this package trustworthy.

A September 20 push shows maintenance, while adoption is still young

The repository was pushed on September 20, 2026, less than two weeks after its September 7 creation. GitHub showed 180 stars and one open issue-or-pull-request entry on October 1. That entry is a pull request about replacement text appearing in the original-text box, a narrow report correctness fix rather than evidence of broad user support.

The latest GitHub release is v4.1, published September 7 as the initial public release. Recent source activity and a release workflow are good signs, but they do not establish years of compatibility across every named host. Start with a redacted resume, inspect the Markdown, and compare the PDF against its source before trusting it with a real application. The skill's own rules ask you to make those checks, and our lab result gives no reason to skip them.

Alternatives

ProjectWhat it isPick it when
OpenResumeA browser-based open-source resume builder with a resume parser.pick this instead when you need to create and export a resume in a visual web interface.
Reactive ResumeA self-hostable resume builder focused on editing, layout, and export.pick this instead when document design and self-hosted resume management matter more than an AI critique workflow.
Resume MatcherA local AI resume workspace for resumes, PDFs, and cover letters across many model providers.pick this instead when you want a full local application and broader model choice rather than a portable Agent Skill.

What people are saying

  1. [velocity-scout] mubix/cyber-resume-reviewer-skill

Sources

  1. Cyber Resume Reviewer README
  2. Cyber Resume Reviewer skill instructions
  3. Cyber Resume Reviewer v4.1 release
  4. Open pull request 1
  5. Skill publishing workflow

More ai tools reviews

unigit-ecosystem · handraw-style · souchastnik · dlssg_for_sm86 · glm-flash-offline-client · RuiC-card-skill · the whole board →