← Files Job Outreach CopilotARCHIVED FILE

skills/job-outreach-copilot/references/job_search_safety_privacy.md

2.63 KB · Oct 7, 2026 · 00:36 UTC

↓ Download file

# Job Search Safety and Privacy

## Purpose

Help the candidate communicate efficiently without exposing sensitive information or normalizing suspicious recruiting behavior.

## Sensitive information

Do not encourage the candidate to send recruiters:
- passwords;
- MFA/2FA codes;
- bank login credentials;
- full Social Security number in ordinary outreach;
- payment card data;
- crypto wallet seed phrases/private keys;
- security-question answers;
- copies of identity documents through an unverified channel;
- account recovery codes.

Legitimate onboarding can require sensitive identity/tax information, but the candidate should verify the employer and use the employer's official secure onboarding process rather than casual chat or an unverified email request.

## Common warning signs

Flag concrete signals such as:
- recruiter demands money, gift cards, crypto, or fees;
- candidate is asked to buy equipment and send money to a third party;
- unrealistic pay paired with minimal screening;
- pressure to move immediately to an unverified messaging app;
- email/domain does not match the claimed organization and no independent verification is available;
- sensitive identity/banking information requested unusually early;
- interview process exists only through text messages with no verifiable company presence;
- links or attachments appear suspicious;
- job details change materially after the candidate responds.

One signal alone may not prove fraud. Explain what is suspicious and how to verify.

## Verification steps

When warranted:
- verify the role on the company's official careers site;
- verify the recruiter/company domain independently;
- use official contact information rather than contact details supplied only in a suspicious message;
- inspect the exact sender domain, not just the display name;
- avoid paying money to receive a job;
- pause before sending sensitive documents.

## Privacy-conscious drafting

Outreach normally needs only:
- name;
- relevant professional background;
- role reference;
- professional contact method;
- resume/portfolio when appropriate.

Do not insert the candidate's home address, date of birth, SSN, passport/visa document numbers, or other unnecessary personal data into ordinary recruiter messages.

## Screenshots and attachments

Use only visible/supplied information.
Do not guess hidden email addresses, private profile details, or sender identity.

## Claims about scams

Do not state that a person/company is fraudulent unless evidence supports it.
Prefer:
- "This is a warning sign because..."
- "I would verify X before continuing."
- "The message alone doesn't prove fraud, but these details are unusual..."

SHA-256: eaa95b9098df2896ab6ca5c72e36efacb639aa00b4b7ae47d1a273579c682cc5