Skip to content

QortexOS Entering Public Beta Q3 Sign-Up Today ->

Prompt Injection Arrives by Résumé

Candidate résumés are untrusted input the moment a model ranks them, and controlled tests show one appended sentence can reorder a tightly bunched shortlist while nothing in the pipeline alerts.

Robert Griffin7 min read
Prompt Injection Arrives by Résumé

A screening system is most exploitable on the quiet days. When thirty qualified applicants sit within a rank or two of each other and exactly one of them has read an article about hidden white text, a single self-promotional sentence can reorder the shortlist while every component in the pipeline reports normal operation. Nothing alerts, and a different person gets the interview slot.

Every résumé that reaches a language model is text an outside party wrote, controls, and can aim. The screener reads that text as evidence about the applicant; the applicant is free to write it as an instruction to the screener. Security teams have tracked this class of attack in chatbots and document pipelines for years under the name prompt injection, and it now arrives through a channel most hiring managers have never had reason to classify as a channel. For an SMB or an MSP that routed candidate triage through an assistant last quarter, the exposure fits in one sentence: a document that used to be a static artifact for a human reader is now untrusted external input entering a runtime that acts on it.

What the Ranking Task Actually Demands

Asking a model to screen is asking it to produce a strict order over people who all belong in the conversation, from documents written to look alike. The separation has to come from somewhere. One recent controlled evaluation measured what happens when a candidate supplies that separation deliberately. The setup was plain enough to reason about: the model is provided with a fixed IT support specialist job description and a pool of ten résumés, and is asked to output a strict ranking of all candidates. The appended text came in two forms that differ in their level of directness, a descriptive injection, which provides an evaluative statement about the candidate, and an instructive injection, which explicitly directs the model's decision. Two measures carry the result: rank gain measures how a résumé's position changes under prompt injection relative to the non-injection baseline, and success rate captures how often injection leads to an improvement in rank.

The two forms of appended text did not land the same way.

The descriptive line was the milder of the two intrusions and the more instructive result. DeepSeek gave the injected résumé an average rank gain of 4.158 with an average success rate of 86.2 percent, roughly four positions in a field of ten bought with a sentence that added no qualification the applicant did not already have. The GPT model was far less vulnerable to the same descriptive injection, with an average rank gain of only 0.638 and a success rate of 7.4 percent, and that resistance held right up to the point where the appended text stopped describing and started instructing. Under the instructive variant, the same model became substantially more susceptible, with an average rank gain of 2.364 and a success rate of 59.7 percent.

Saturation Cuts Both Ways

Resistance to one phrasing is a narrow property. It moves with the next model release or the next sentence an applicant decides to try. In that evaluation the magnitudes came out of a synthetic design built on one role and ten-candidate pools, so the numbers a live pipeline would produce are different numbers. The part worth holding on to is where the vulnerability concentrates: quality compressed, manipulation rare, decisions made at a threshold where one position matters.

The advantage does not survive crowding. As injection becomes more prevalent in the same pool, those rank gains shrink toward zero and success rates drop sharply, approaching zero once roughly 80 percent or more of résumés are injected. The mechanism is competition for a fixed set of top positions; once every résumé carries the same push, the push has stopped functioning as a signal. Read quickly, that looks like a problem that solves itself as candidates catch on.

That reading deserves a second look.

The advantage fades because everyone is manipulating, not because manipulation stops working.

It solves itself only in the crowded case, and it solves itself for the wrong reason. The advantage fades because everyone is manipulating, not because manipulation stops working. Below that point the exposure is live, and it is at its largest at exactly the prevalence a single curious applicant produces. How common the practice has become in any given applicant pool is not something this evidence settles, and an operator reviewing a stack of applications has no way to observe it from the outside either. What is knowable is the shape of the risk: a thin layer of manipulation over a tightly bunched field is the condition in which one appended sentence moves a person up the list.

Evaluations that focus on isolated attacks can substantially mischaracterize system vulnerability by ignoring congestion and interaction effects among candidates. The operator's version of that caution runs in both directions. A single-injection test shows the exposure at close to its full size, while a heavily saturated test shows a pipeline that looks resilient largely because the manipulators are canceling each other out. Either result read alone gives a false picture, and the low-prevalence reading is the one attached to the consequence.

The Inversion That Never Fires an Alert

The experience gap in that testbed was drawn to be legible. Two tiers were constructed: high-quality candidates with 10 years of experience (HQ) and low-quality candidates with 5 years of experience (LQ). Both tiers clear the posting on their own merits, because the job description specifies a minimum requirement of 5 years of experience, so all candidates in that setting meet the baseline qualification threshold. That is the ordinary shape of a real applicant pool, a field of people who would each be a defensible hire, sorted at the margin by whatever the system finds to separate them.

With both tiers in one pool, prompt injection is less effective on average. Experience does most of the sorting, which is the half of the picture an operator can rest on. The other half is that for candidates near decision thresholds, injected self-promotional language can shift the model's evaluation in favor of an LQ résumé, occasionally allowing it to outrank an HQ résumé. The distortion lands at the shortlist boundary, which is the one place in the process where a single position changes anyone's outcome.

None of that presents as an incident. A ranked list arrives, someone interviews the top five, the requisition closes. The cost surfaces later and in a different vocabulary, when a rejected applicant's counsel asks how the ranking was produced, or when an enterprise buyer's vendor review asks the same question about the process behind the team that will handle their data. An operator who can answer with written criteria and a review trail is carrying a priced risk. An operator answering from memory is carrying an unpriced one.

Controls That Make a Screen Defensible

The measures that hold up under review are short enough to list.

  • The response is ordinary engineering discipline pointed at a new input surface. Treat every résumé and cover letter as adversarial text entering a runtime, with the posture already applied to an inbound attachment from a stranger. Score structured evidence: years in role, certifications, employment dates, credentials that can be checked against something other than the applicant's own adjectives. Keep free-form self-assessment out of the ranking signal, and require the system to emit the criteria and the reasoning behind each position so the order can be audited by the person accountable for it.
  • Put human review at the shortlist boundary, where the distortion concentrates and where being wrong is most expensive. Exercise the pipeline in both conditions, once with a single manipulated résumé and once with most of the pool manipulated. The single-injection run is where the exposure shows up; the saturated run is where the pipeline will look calm, and neither result substitutes for the other. Keep the internal framing accurate as well: the model is one component inside a screening architecture, and the discipline lives in how evidence gets extracted and in who owns the borderline calls.

The return on that discipline shows up outside the hiring process.

A screening process with written criteria and structured evidence, where every borderline call carries a named reviewer, is one an operator can defend to a rejected candidate's counsel and to an enterprise buyer running a vendor review before signing. That second audience is the one worth pricing. Procurement is increasingly gated on governance evidence, and a process that can produce its criteria and its review trail on request shortens that review rather than stalling inside it, which is the commercial return on discipline that was built in before the question arrived. The standard we hold for AI in security is the standard for AI in hiring: the work has to be observable and explainable to the person accountable for the outcome.

Insight-Powered, Future Driven

Build a Shortlist You Can Defend

Qualsis helps small and medium businesses operate with the insight, rigor, and accountability the largest enterprises take for granted.