affiliate-payout-audit
Pass
Audited by Gen Agent Trust Hub on Sep 13, 2026
Risk Level: SAFEINDIRECT_PROMPT_INJECTIONNO_CODE
Full Analysis
- [INDIRECT_PROMPT_INJECTION]: The skill is designed to ingest and process external data exports from affiliate networks and billing systems, which represents a theoretical surface for indirect prompt injection.
- Ingestion points: Processes affiliate platform exports and internal billing/CRM data in CSV or spreadsheet formats as defined in SKILL.md.
- Boundary markers: The instructions do not explicitly mandate the use of specific delimiters or protective instructions when the agent interpolates external data into its context.
- Capability inventory: The skill focuses on data analysis, recomputing commission math, and generating audit reports based on provided external exports.
- Sanitization: The instructions do not specify validation or sanitization rules for the text content within the ingested data exports.
- [NO_CODE]: The skill consists entirely of instructional Markdown files and evaluation data. It does not include any scripts, executables, or environment configuration files that could perform unauthorized actions.
Audit Metadata