Back to skill

Security audit

Affiliate Marketing Auto

Security checks for vulnerabilities and agentic risk

Overview

This affiliate marketing skill is not overtly malicious, but it needs review because it handles affiliate credentials and raw click-tracking data with limited privacy guidance and flagged HTTP dependencies.

Review this skill before installing in production. Use least-privilege affiliate API keys, do not place real secrets directly in shared config or logs, upgrade the flagged npm dependencies, and add privacy controls before collecting click data such as IP addresses, user agents, referrers, or locations. Generated affiliate content should also be reviewed for required disclosures and platform policy compliance.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (27)

Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
93% confidence
Finding

The lockfile pins axios 1.13.6, and the provided advisory set includes multiple high-severity issues affecting request handling, proxy logic, and prototype-pollution-related attack chains. In a skill that appears to automate affiliate marketing and likely performs outbound HTTP requests and scraping, a vulnerable HTTP client materially increases risk of SSRF, credential leakage, request tampering, or response hijacking when processing attacker-influenced URLs or proxy settings.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: form-data==4.0.5 — 1 advisory(ies): CVE-2026-12143 (form-data: CRLF injection in form-data via unescaped multipart field names and f)

High
Category
Supply Chain
Confidence
88% confidence
Finding

form-data 4.0.5 is reported as vulnerable to CRLF injection through unescaped multipart field names/filenames. If any user-controlled values are used to construct multipart requests, an attacker may be able to smuggle or corrupt headers/body structure, potentially altering downstream requests or exfiltrating data.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: undici==7.24.3 — 12 advisory(ies): CVE-2026-6733 (undici vulnerable to HTTP response queue poisoning via keep-alive socket reuse); CVE-2026-13697 (undici vulnerable to cross-user information disclosure and parse-time crash via ); CVE-2026-16728 (undici vulnerable to downstream response desynchronization via retry interceptor) +9 more

High
Category
Supply Chain
Confidence
86% confidence
Finding

undici 7.24.3 is flagged with multiple high-severity HTTP parsing and connection-reuse issues, including response queue poisoning and information disclosure scenarios. Because cheerio depends on undici and this skill likely retrieves remote web content for scraping, malformed or attacker-controlled servers could exploit client-side HTTP desynchronization or data-mixing behaviors.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: axios==1.13.6 — 16 advisory(ies): CVE-2026-44494 (axios Vulnerable to Full Man-in-the-Middle via Prototype Pollution Gadget in `co); CVE-2026-44495 (axios Vulnerable to Credential Theft and Response Hijacking via Prototype Pollut); CVE-2025-62718 (Axios has a NO_PROXY Hostname Normalization Bypass that Leads to SSRF) +13 more

High
Category
Supply Chain
Confidence
96% confidence
Finding

The package permits axios versions covered by known advisories, including SSRF-related and request-handling issues. For an automation skill that discovers products, scrapes content, and tracks links over the network, a vulnerable HTTP client materially increases the risk of request forgery, credential leakage, response tampering, or other network-layer attacks depending on how axios is used in code.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
84% confidence
Finding

The README instructs users to configure affiliate API keys and later export reports to local paths, but it does not warn about secure secret storage, redaction in logs, access control for exported files, or the sensitivity of tracking and revenue data. In an agent skill context, users may paste real credentials into configs and allow autonomous workflows to write reports, increasing the chance of credential leakage, unsafe file placement, or exposure of business analytics data.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
86% confidence
Finding

The report promotes automated content generation, link tracking, and analytics/export features without disclosing operational, privacy, or compliance risks. In a marketing automation skill, these capabilities can process user, click, and conversion data and may lead operators to deploy tracking or generated content without considering consent, platform policy, or data-handling obligations.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

The file presents all user-facing instructions and examples in Chinese, but does not offer an alternative language or state that the skill is intended only for a Chinese-speaking or China-specific audience. This can violate language/locale policy when a skill forces a specific language without user opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

This markdown file presents all operational instructions, warnings, and publishing steps only in Chinese. Under the policy for natural-language violations, forcing a specific language without user opt-in is a reportable issue unless the locale constraint is explicitly justified, which is not present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The manifest description is written entirely in Chinese, and the listed feature names and some platform labels are also Chinese, which signals a language-specific skill presentation without any stated opt-in or locale justification. Under the policy rule, a skill should not implicitly force a specific language unless it offers choice or clearly documents a region-specific scope.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

All instructional text, comments, and console output are fixed to Chinese, which can violate language/locale policy when no user choice or documented locale constraint is provided. There is no indication that this skill is region-specific or that users can select their preferred language.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The example records IP address, user-agent, and referrer data for click tracking without any notice, consent flow, minimization guidance, or indication that this data may be personal data. In a marketing/tracking context, demonstrating silent collection normalizes privacy-invasive behavior and may lead downstream users to deploy tracking that violates privacy expectations or regulatory requirements.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
96% confidence
Finding

The package description is written entirely in Chinese and presents the skill as Chinese-language by default, with no indication that users can choose another language or locale. This can violate language/locale policy where skills should not force a specific language without explicit opt-in or documented regional justification.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

This JavaScript skill contains user-facing natural-language strings and comments in Chinese, including the module description and later console messages, but it does not indicate that the skill is China-region-specific or provide any user opt-in for language selection. Under the policy, forcing a specific language without user choice is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The review generator defaults language to zh-CN, which imposes a specific locale unless the caller explicitly overrides it. The policy requires offering a language choice or documenting a justified locale constraint, neither of which is present here.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The email generator sets language = 'zh-CN' by default, which creates a locale-specific behavior without explicit user selection. This is a natural-language policy concern because the file does not offer opt-in or justify the locale restriction.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

The video script generator defaults to zh-CN, enforcing a specific locale in generated content when no user choice is provided. There is no documented justification for this restriction or mechanism for explicit opt-in.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The code sets language: 'zh-CN' as the default for content generation, which imposes a specific language/locale on users unless they explicitly override it. Under the policy, forcing a language without user opt-in is a natural-language policy violation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
91% confidence
Finding

The module records IP addresses, user agents, referrers, and locations for every click, which are personal or potentially sensitive identifiers in many jurisdictions. There is no consent check, minimization, retention control, or notice mechanism in the code, so deploying this as-is can create privacy, compliance, and data exposure risk if the collected telemetry is mishandled or breached.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
89% confidence
Finding

This JavaScript file uses Chinese throughout its documentation comments and console output, which imposes a specific language on operators and users. The file does not provide any opt-in, localization mechanism, or justification that the skill is intended only for a Chinese-language environment.

Content

No source excerpt is available for this finding.

Natural-Language Policy Violations

Medium
Category
Not specified by scanner
Confidence
98% confidence
Finding

This JavaScript file contains user-facing comments and console output entirely in Chinese, including status, error, and test-result messages. Because the skill does not offer any language selection or document a justified locale restriction, it violates the language/locale policy for natural-language content.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
89% confidence
Finding

The document provides ready-to-run publishing commands for external marketplaces without clearly warning that they perform live release actions. This increases the chance of accidental publication, pricing changes, or marketplace listing modifications by a user who treats the commands as illustrative rather than production-affecting.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The example exports a report to a local path, which is a file-write operation. While the subsequent log confirms completion, there is no prior disclosure in comments or messaging that running this step will create files under ./exports.

Content

No source excerpt is available for this finding.

Known Vulnerable Dependency: follow-redirects==1.15.11 — 1 advisory(ies): CVE-2026-40895 (follow-redirects leaks Custom Authentication Headers to Cross-Domain Redirect Ta)

Low
Category
Supply Chain
Confidence
83% confidence
Finding

follow-redirects 1.15.11 is flagged for leaking custom authentication headers across cross-domain redirects. If this skill sends authenticated HTTP requests or API tokens while following redirects, an attacker-controlled redirect target could capture credentials or other sensitive headers.

Content

No source excerpt is available for this finding.

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
81% confidence
Finding

Using a caret range for axios allows automatic installation of newer matching releases, which can introduce unexpected supply-chain changes and makes builds less reproducible. In a skill that performs network automation for affiliate marketing, dependency compromise or silent behavioral drift could affect outbound requests, data handling, and link tracking.

Content

Scanner excerpt · package.json (reported line 22)May include surrounding context.

json
"author": "OpenClaw Community",
  "license": "MIT",
  "dependencies": {
    "axios": "^1.6.0",
    "cheerio": "^1.0.0-rc.12",
    "node-fetch": "^3.3.2"
  },

Unpinned Dependencies

Low
Category
Supply Chain
Confidence
79% confidence
Finding

Using a caret range for node-fetch similarly permits non-deterministic dependency resolution within the allowed semver range, increasing supply-chain risk and reducing reproducibility. Because this skill likely fetches external content and affiliate data, a compromised or problematic update could influence remote request behavior or expose sensitive traffic.

Content

Scanner excerpt · package.json (reported line 24)May include surrounding context.

json
"dependencies": {
    "axios": "^1.6.0",
    "cheerio": "^1.0.0-rc.12",
    "node-fetch": "^3.3.2"
  },
  "engines": {
    "node": ">=18.0.0"

Static analysis

No suspicious patterns detected.