Primary question: Can a locally run, rubric-scored pipeline replace your manual job-board triage — and do you trust the 1.0-5.0 score enough to act on it?
RepoDaily adoption score
RepoDaily rates this as 90/100 (strong) for adoption: evidence, installation path, production risk, differentiation, license clarity, and AI/agent fit are scored from the article sources and adoption notes.
6 source(s) across 3 source category/categories, plus a RepoDaily-specific evidence module when available.
6 workflow step(s), 5 next-action step(s), and 7 command/install signal(s) were detected.
Trending momentum is +855 stars, with maintenance/release/issue signals counted when present.
Risk is marked medium, with 5 security note(s) and 4 explicit skip condition(s).
3 opportunity lens item(s), 5 alternative(s), and 4 type-specific section(s) support differentiation.
License source or license wording is present.
6 AI/agent-related signal(s) were detected in the article text and metadata.
Project overview
career-ops is an MIT-licensed JavaScript project that packages an entire job hunt as a local pipeline. Version 1.28.0, tagged in package.json and shipped on 2026-08-20, describes itself as an "AI-powered job search pipeline" that "works with any AI coding CLI (Claude Code, Codex, OpenCode, Antigravity, Grok, Qwen, Kimi, Copilot)." There is no hosted SaaS layer: the CLI you already have open orchestrates, and Node scripts underneath do the scanning, scoring, document generation, and tracking.
The core promise is structure. Instead of skimming postings and applying on instinct, career-ops scans job portals and ATS boards, then grades every listing against a structured A-F rubric that maps to a 1.0-5.0 score. The pipeline continues through CV tailoring and application tracking, and it captures signals beyond the posting itself: v1.28.0 added a no-response-friction signal per RFC #1506 schema v1 (#2787) and an AI-screening disclosure signal labeled Block G Signal 15 (#2892). Those are employer-behavior data points most trackers never record.
Momentum explains this week's rank 5 with 855 period stars. v1.28.0 landed the day before the trend date with 13 features and a batch of fixes — among them a native Node.js batch evaluator for Gemini (#1650), a yourator job board provider, Wellfound search queries in the example portal template, and a discover-ats mode that probes long-tail ATS vendors rather than "just the big three." CONTRIBUTING.md claims 55K+ total stars and releases shipping most weeks; the changelog's density supports the claim.
The engineering is more deliberate than a typical AI wrapper. Runtime dependencies total four (@google/generative-ai ^0.24.1, dotenv ^17.0.0, js-yaml ^5.3.0, playwright pinned at 1.62.1), engines requires Node >=18, a doctor command checks your environment, and the Dockerfile builds on mcr.microsoft.com/playwright:v1.62.1-jammy with a Go 1.23.4 toolchain for the dashboard TUI and TeX Live for PDF output. Testing exists too: an eval:golden golden-run scorer and Playwright visual tests for CV rendering.
Why it is trending now
- 855 period stars on the 2026-08-21 trend date, trending rank 5 — RepoDaily's measured gain for this repository.
- v1.28.0 shipped 2026-08-20, one day before the spike: 13 features plus fixes, including the Gemini batch evaluator (#1650) and the AI-screening disclosure signal (#2892).
- It runs where AI-assisted developers already work: package.json names Claude Code, Codex, OpenCode, Antigravity, Grok, Qwen, Kimi, and Copilot as supported CLIs.
- The A-F rubric mapping to 1.0-5.0 replaces gut-feel triage with an auditable number — the repo's central differentiator.
- MIT license and local-first execution: no account, no hosted backend; SECURITY.md states plainly that career-ops runs locally, so "there is no server of ours to attack."
- Employer-side signals are unusual for a candidate tool: rejection latency, repost detection, table freshness checks, and now no-response friction per RFC #1506.
Problem it solves
- Listings are scattered across many portals and ATS boards; manual browsing caps how many postings you can even see.
- Without a fixed standard, the same posting gets judged differently depending on mood and fatigue.
- Tailoring a CV per listing is repetitive work that quietly stops happening when time gets short.
- Application tracking usually decays into a stale spreadsheet with no follow-up cadence.
- Employer behavior — ghosting, reposts, screening filters — stays invisible until you have already wasted weeks.
How it works
- Define targets: copy templates/portals.example.yml (v1.28.0 adds Wellfound search queries to it) and add the companies you care about; check them with npm run validate:portals and npm run verify:portals.
- Scan boards: npm run scan pulls from configured portals; scan:full sweeps full boards with seed sets like --seeds yc,a16z; discover-ats probes long-tail ATS vendors, not just the big three; new zero-auth providers (yourator landed in v1.28.0) need no authentication.
- Score listings: each JD is graded against the A-F rubric into a 1.0-5.0 score. Pick a runner: gemini:eval (batch mode is native Node.js as of #1650), ollama:eval for local models, openai:eval, or npm run or:eval through OpenRouter.
- Tailor documents: openai:tailor adapts the CV, generate-cover-letter.mjs writes cover letters from a payload, cv:verify-facts checks claims, and generate-pdf.mjs renders output — the Docker image bundles texlive-xetex and latexmk precisely for this.
- Track and learn: add, tracker, and find manage entries; reposts detects duplicate postings; rejection-latency and company-history record how employers actually behave; weekly-digest summarizes. v1.28.0 added reports_to to the Machine Summary schema.
- Guard the pipeline: eval:golden runs golden tests on scoring, verify checks the pipeline end to end, and doctor.mjs emits verdicts like the Gemini Node 20+ requirement (#3032) instead of leaving them in prose.
Command surface: 58 npm scripts, four runtime dependencies
package.json at v1.28.0 defines 58 scripts, and the breadth is the product: scan (scan.mjs), scan:full (scan-ats-full.mjs), tracker, find, digest, upskill, invite-match, paste-reply, plus update and rollback for self-updates. Nothing hides behind a daemon — every stage is a runnable Node file you can open and read.
- Scoring runners: gemini:eval, ollama:eval, openai:eval, or:eval (openrouter-runner.mjs), and eval:golden for golden tests.
- Document tools: pdf (generate-pdf.mjs), img-to-pdf, cover-letter, cv:verify-facts, sync-check, and Playwright visual CV tests (test:cv-visual with playwright.cv.config.mjs).
- Tracking hygiene: dedup, merge (merge-tracker.mjs), normalize, freshness, rejection-latency, reposts, liveness.
- Platform care: doctor (node doctor.mjs), lint via scripts/check-syntax.mjs, update with rollback, and a postinstall that runs npx playwright install chromium --with-deps.
- Dashboard: build:dashboard and serve:dashboard, the latter launching the Go TUI via cd dashboard && go run . --path ..
Integration surface: eight CLIs, four model paths, one Go dashboard
career-ops positions itself as a runtime layer over AI coding CLIs rather than a standalone app. The package.json description lists Claude Code, Codex, OpenCode, Antigravity, Grok, Qwen, Kimi, and Copilot, and the keywords array repeats the same names plus ai-agent-skill.
- Model providers: @google/generative-ai ^0.24.1 is the only AI SDK among dependencies; Ollama, OpenAI, and OpenRouter run through their own scripts (ollama-eval.mjs, openai-eval.mjs, openrouter-runner.mjs).
- Browser layer: playwright is pinned exactly at 1.62.1 to match the Docker base image's bundled Chromium; browser-extract.mjs handles extraction.
- Dashboard: a Go TUI under dashboard/, launched by serve:dashboard; the Dockerfile installs Go 1.23.4 specifically to keep "full feature parity with the README setup."
- Job sources: portal templates plus dedicated scanners — scan:interamt (scan-interamt.mjs), company:funded (company-funded.mjs), and the v1.28.0 yourator provider.
Deployment notes: one container, bind-mounted sources
The Dockerfile builds on mcr.microsoft.com/playwright:v1.62.1-jammy with PLAYWRIGHT_BROWSERS_PATH=/ms-playwright, sets tini as the entrypoint, and installs curl, git, latexmk, texlive-latex-extra, texlive-xetex, and Go 1.23.4 for both amd64 and arm64. Sources are deliberately not COPY'd — the project bind-mounts at runtime via docker compose so local edits appear instantly inside the container.
- engines.node is >=18, but doctor now emits a Gemini-specific Node 20+ verdict (#3032) — check it before routing batch scoring through Gemini.
- The image is the escape hatch for hosts whose kernels block Playwright's Chromium installer; the Dockerfile explicitly calls out Ubuntu 26.04 as a case where the bundled browser still works.
- After npm install, the postinstall hook already attempts npx playwright install chromium --with-deps, so browser provisioning is not a separate manual step.
Maintenance risk: fast cadence, human review, single-maintainer bus factor
The project moves: v1.28.0 alone carried 13 features tied to RFCs and numbered signals (RFC #1506 schema v1, Block G Signal 15). CONTRIBUTING.md commits to human review — "we don't merge AI-slop" — and promises issue/PR responses usually within a day or two, backed by a Discord invite (discord.gg/8pRpHETxa4).
- Good-first-issue system: comment /assign to claim an issue; it frees up after 7 quiet days with a ping at day 3; /extend restarts the clock and /unassign releases cleanly; slots are reserved for contributors with fewer than 3 merged PRs here.
- Feature PRs need an issue first; bug fixes, new zero-auth scanner providers, docs, and translations may go straight to a PR.
- package.json lists a single author (Santiago Fernández de Valderrama, santifer.io) — adoption is visible, but so is the bus factor.
- Security responsiveness is documented: report to [email protected], response within 72 hours, coordinated disclosure with reporter credit in release notes.
Who should pay attention?
Good fit if
- Job seekers who already pay for an AI coding CLI or model API access and are comfortable in a terminal.
- Candidates targeting startup boards — scan:seeds ships presets for the yc and a16z seed sets.
- Privacy-minded users: everything runs locally, with no account and no hosted backend.
- First-time open-source contributors: CONTRIBUTING.md pitches exactly that, with scoped issues, time estimates, and a /assign claim flow.
- Go and Playwright developers looking for concrete places to contribute — the dashboard TUI and browser extraction are both named contribution areas.
Skip for now if
- Anyone who wants a hosted web product with onboarding, sync, and mobile apps.
- Users unwilling to manage API keys, or to run Ollama locally, for the scoring stage.
- People who need guaranteed compliance with each job portal's terms — a scanner pipeline that includes CSRF-handshake fixes like #2764 sits in inherent tension with some boards.
- Recruiters and hiring-side users; this is candidate-side software.
Risks and cautions
Local-first and MIT remove vendor risk, but the project's own SECURITY.md acknowledges the sharp edges: a local web dashboard reachable from your browser and LAN, scraper scripts touching external sites, and secrets in local config.
- The web dashboard is a local HTTP server; SECURITY.md explicitly warns it is reachable by cross-origin pages you visit and by other devices on the same network, and lists command injection through its API as an in-scope class.
- All *.mjs scripts are in scope for command injection, path traversal, and SSRF — the project treats its attack surface seriously, which confirms the surface exists.
- Scrapers break: v1.28.0 alone fixed a GET /jobs CSRF handshake before POSTing (#2764) and an empty JD-file fallback in the batch runner (#2492).
- Model access is your responsibility: cloud scoring needs API keys stored locally ("secrets exposure, unsafe defaults" is an in-scope config issue), local scoring needs Ollama.
- Pinning matters: playwright is held at 1.62.1 to match the Docker image's Chromium, so casual dependency upgrades can break extraction.
- Runs locally by design; SECURITY.md notes there is no hosted server of theirs to attack — then adds that "local does not mean unreachable."
- In scope for reports: command injection, path traversal, and SSRF in *.mjs scripts; XSS in templates/ HTML and PDF output; command injection through the web/ dashboard API; secrets exposure in configuration.
- Disclosure process: email [email protected] with description, reproduction steps, and impact; response within 72 hours; coordinated disclosure with reporter credit in release notes.
- Out of scope: third-party dependency bugs (report upstream), physical access, and social engineering.
- A four-package runtime dependency set keeps the audit surface narrow.
Alternatives to compare
| Approach | When to use | Trade-off |
|---|---|---|
LinkedIn Jobs | You want the largest network and recruiter reach and accept algorithmic feeds over rubric scoring. | Free; Premium subscriptions add insights and InMail |
Teal | You want a hosted job tracker with resume tooling and a browser extension instead of a terminal pipeline. | Freemium SaaS |
Huntr | You mainly need kanban-style application tracking, not scanning or scoring. | Freemium SaaS |
JobSpy | You want an open-source Python library that scrapes postings from several boards into a dataframe for your own analysis. | Open source |
Reactive-Resume | You only need a self-hosted resume builder without the scanning and tracking stages. | Open source, self-hosted |
What this trend reveals
Ship a zero-auth scanner provider
CONTRIBUTING.md lists new zero-auth scanner providers among the few contributions that skip the issue-first rule — you can PR a provider directly, exactly as yourator was added in v1.28.0.
Add one board to templates/portals.example.yml, confirm npm run validate:portals and verify:portals pass against it, and mirror an existing provider's pattern.
Audit the rubric against your own judgment
The A-F rubric and its 1.0-5.0 mapping are the product's core claim, and eval:golden exists to keep scoring stable across releases.
Score ten postings you already reviewed by hand, compare the rubric output to your own ranking, and check whether the gap is signal or noise.
Harden the local dashboard
SECURITY.md names cross-origin requests and API command injection as live concerns for web/; a community test or patch there has direct, documented value.
Serve the dashboard on a LAN machine, probe it from another device and from a cross-origin browser fetch, then report findings to [email protected].
RepoDaily verdict
career-ops is serious local-first infrastructure for a problem everyone complains about and few engineer. The command surface is unusually wide but legible — 58 scripts you can read, four runtime dependencies, a doctor that tells you what will break. Security documentation is candid about real attack surfaces rather than marketing-checklist shallow. The cost is yours to carry: API keys or a local model, scraper fragility, and a dashboard you should never expose to your LAN. For terminal-comfortable job seekers, an hour with doctor.mjs and ten scored listings is a cheap, decisive experiment.