Back to skill

Security audit

Affiliate Program Search

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed affiliate-program research helper that uses public web/API data and does not install code, access credentials, or make changes on the user's behalf.

Installers should know this skill may activate on broad monetization or niche-selection prompts and may steer the conversation toward affiliate-program recommendations. Verify commission rates, cookie windows, program terms, and platform rules before acting on its recommendations, especially because affiliate data and program terms can change.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
Findings (2)

Vague Triggers

Medium
Confidence
95% confidence
Finding
The skill’s trigger conditions are broad enough to activate on common product-selection, niche-picking, and monetization queries that may not specifically require this skill. Over-broad auto-triggering can cause unintended invocation, steering user workflows toward affiliate-marketing actions and external data retrieval in contexts where a narrower or different skill would be more appropriate.

Vague Triggers

Medium
Confidence
93% confidence
Finding
The skill enables implicit invocation without any visible trigger constraints, so the platform may activate it on broad or ambiguous user requests. In a research-oriented skill that influences commercial recommendations, this can cause unintended routing, irrelevant affiliate promotion, or invocation in contexts where the user did not clearly consent to affiliate-focused guidance.

VirusTotal

58/58 vendors flagged this skill as clean.

View on VirusTotal

Static analysis

No suspicious patterns detected.