referral-abuse-guardrails
Installation
SKILL.md
Referral Abuse Guardrails
Define the guardrails that stop end customers from gaming a customer refer-a-friend program, and deliver them as a guardrail spec: rules with thresholds, verification gates, a reward-hold policy, an enforcement ladder, and monitoring signals. This skill protects whatever reward structure already exists - it never redesigns it.
No ratified standard covers consumer referral abuse. Borrow exactly four things, nothing more, and only as a mental model, never as a compliance claim:
- GIVT/SIVT shape (ad-measurement standards): a cheap deterministic tier plus an expensive corroborative tier.
- OWASP OAT-019 Account Creation: the automated slice only.
- Trust-and-safety enforcement-ladder principles: proportionality, consistency, transparency, for the enforcement section.
- Sybil-attack result, as the strategic frame: fake identities can never be fully detected without a central identity authority, so every guardrail is really a cost imposed on the abuser.
The goal is making abuse unprofitable, not catching everything.