affiliate-program-search

Pass

Audited by Gen Agent Trust Hub on Mar 20, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill retrieves structured data from list.affitor.com, which is the official domain of the skill's author. It also performs web searches to gather sentiment and ranking data from well-known services such as G2, Capterra, and Trustpilot. These network operations are strictly limited to the skill's primary research purpose.
  • [PROMPT_INJECTION]: Indirect Prompt Injection Surface: The skill ingests external content in the form of program descriptions and user reviews during the research phase.
  • Ingestion points: External data is sourced via the list.affitor.com API and general web searches as described in SKILL.md and references/scoring-criteria.md.
  • Boundary markers: Data is collected for scoring and ranking purposes without explicit instruction-boundary markers.
  • Capability inventory: The skill's capabilities are restricted to information retrieval, scoring, and presentation; it does not utilize any high-risk tools for command execution, file modification, or data exfiltration.
  • Sanitization: Data is used for analytical scoring and is not passed to sensitive execution sinks.
  • [SAFE]: The skill uses placeholders for API keys and provides clear instructions for users to manage their own credentials via the vendor's settings page, following standard security practices.
Audit Metadata
Risk Level
SAFE
Analyzed
Mar 20, 2026, 07:32 AM