commission-calculator
Pass
Audited by Gen Agent Trust Hub on Mar 20, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADS
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill instructs the agent to retrieve affiliate program metadata (reward values, cookie durations) from an external endpoint at 'list.affitor.com'. This is documented as a primary data source for the skill's calculations.
- [EXTERNAL_DOWNLOADS]: The workflow incorporates automated web searches to estimate product pricing when not provided by the user. This is a common pattern for research-oriented agents to fill data gaps.
- [PROMPT_INJECTION]: The skill processes data from external sources (API and search results) which presents a surface for indirect prompt injection. However, the skill lacks high-risk capabilities such as file system modifications or unauthorized network transmissions, which limits the potential impact of such an attack.
Audit Metadata