submit-program

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONEXTERNAL_DOWNLOADS
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill ingests untrusted data from the open web, which could contain instructions designed to manipulate the agent's output.
  • Ingestion points: The skill performs web_search operations in Step 2 to gather data from official affiliate pages and network listings.
  • Boundary markers: Absent. The instructions do not include specific delimiters or directives to the agent to ignore potentially malicious instructions found within the search results.
  • Capability inventory: The skill utilizes web_search to retrieve external data and produces structured markdown for user review.
  • Sanitization: Step 5 includes logic to validate the format and domain of user-provided affiliate links, though it does not sanitize the content retrieved via search results.
  • [EXTERNAL_DOWNLOADS]: The skill interacts with external sites and repositories as part of its primary function.
  • The skill fetches information from various external affiliate networks and pricing pages via web search.
  • It encourages users to contribute findings to the vendor's official GitHub repository (Affitor/affiliate-skills) and the community directory (openaffiliate.dev).
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 02:16 PM
Security Audit — agent-trust-hub — submit-program