Affiliate Link Injector

ReviewAudited by ClawScan on May 10, 2026.

Overview

The skill matches its affiliate-linking purpose, but it can request account API keys and change public content while making strong legal-compliance claims.

Install or use this only if you are comfortable giving it scoped affiliate and publishing credentials. Test on copies or drafts, require explicit approval before any live post changes, keep backups, and independently verify FTC/legal disclosure wording.

Findings (4)

Artifact-based informational review of SKILL.md, metadata, install specs, static scan signals, and capability signals. ClawScan does not execute the skill or run runtime probes.

What this means

Incorrect matches or overbroad execution could add unwanted affiliate links, disclosures, or tracking URLs to live posts.

Why it was flagged

The skill advertises direct mutation of WordPress posts/pages and auto-insertion of affiliate links, which can change public content and monetization behavior.

Skill content
**WordPress** (direct post/page injection via REST API) ... one-click approval button to auto-inject links
Recommendation

Use this only on drafts or backed-up content, require explicit approval for each post/change, and keep a rollback copy before publishing updates.

What this means

A broadly scoped key could allow unintended edits or account access beyond the immediate affiliate-linking task.

Why it was flagged

The example asks the user to provide a WordPress REST API key, which may grant access to read or modify website content, without clear least-privilege guidance.

Skill content
WordPress URL: https://myblog.com
API key: [your WordPress REST API key]
Recommendation

Use a narrowly scoped, revocable application password or token; avoid pasting long-lived admin credentials; revoke the key after use.

What this means

Users may rely on generated disclosures as legally sufficient even when their jurisdiction, platform, or affiliate program requires different wording or placement.

Why it was flagged

The skill makes strong legal-compliance assurances without showing review provenance or limits, which could lead users to over-trust generated disclosures.

Skill content
Generates legally-reviewed disclosure statements ... Legal-safe (covers all affiliate relationships)
Recommendation

Treat disclosure text as a draft and have compliance/legal requirements verified before using it on public content.

What this means

Draft content, monetization strategy, or compliance notes could be shared with connected workspaces or providers.

Why it was flagged

The skill discloses third-party document and messaging integrations that may receive content excerpts, reports, or link suggestions.

Skill content
**Google Docs** (scan and suggest links for approval)
- **Slack** (send compliance reports and link suggestions)
Recommendation

Confirm which accounts/workspaces are connected and avoid sending confidential drafts unless those destinations are intended.