referral-program

Pass

Audited by Gen Agent Trust Hub on Sep 14, 2026

Risk Level: SAFENO_CODE
Full Analysis
  • [SAFE]: The skill consists exclusively of markdown instructions, strategic frameworks, and email templates. No executable scripts (.sh, .py, .js), binaries, or active configuration files are included in the package.
  • [INDIRECT_PROMPT_INJECTION]: The skill defines a workflow for ingesting user-provided business data (LTV, CAC, program metrics) to generate growth strategies.
  • Ingestion points: User-supplied context regarding program types, product fit, and available resources as requested in the "Before Starting" section of SKILL.md.
  • Boundary markers: Absent; the skill relies on natural language flow for data processing.
  • Capability inventory: No capabilities for file system modification, network exfiltration, or shell execution were identified.
  • Sanitization: No specific input sanitization or filtering logic is present, as the data is used solely for conversational advice.
  • [EXTERNAL_DOWNLOADS]: The skill mentions various third-party marketing tools (e.g., ReferralCandy, Ambassador, ShareASale). These are referenced for informational purposes as industry recommendations and are not associated with any automated network calls, API integrations, or software downloads within the skill's logic.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 14, 2026, 07:19 AM
Security Audit — agent-trust-hub — referral-program