affiliate-payout-audit

Pass

Audited by Gen Agent Trust Hub on Sep 13, 2026

Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
  • [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data exports from affiliate networks and billing systems, which represents a theoretical surface for indirect prompt injection.
  • Ingestion points: Processes affiliate platform exports and internal billing/CRM data in CSV or spreadsheet formats as defined in SKILL.md.
  • Boundary markers: The instructions do not explicitly mandate the use of specific delimiters or protective instructions when the agent interpolates external data into its context.
  • Capability inventory: The skill focuses on data analysis, recomputing commission math, and generating audit reports based on provided external exports.
  • Sanitization: The instructions do not specify validation or sanitization rules for the text content within the ingested data exports.
  • [NO_CODE]: The skill consists entirely of instructional Markdown files and evaluation data. It does not include any scripts, executables, or environment configuration files that could perform unauthorized actions.
Audit Metadata
Risk Level
SAFE
Analyzed
Sep 13, 2026, 09:17 PM
Security Audit — agent-trust-hub — affiliate-payout-audit