T08 · Insecure Dependencies
- Location
SKILL.md:10- Finding
Unpinned Third-Party CLI Dependency
- Content
View full analysis
- Remediation
View remediation
Security audit
Security checks for vulnerabilities and agentic risk
The skill fits its Affonso affiliate-management purpose, but it gives broad authenticated control over affiliate, commission, payout, tracking, and CLI endpoint settings without enough guardrails.
Review this skill before installing. Use a narrowly scoped Affonso API key, avoid passing secrets on the command line, do not set a custom base URL unless you fully trust the endpoint, and require explicit human approval before payout, commission, auto-approval, auto-payout, delete, or bulk configuration changes. Pin or otherwise verify the CLI package before use.
SKILL.md:10Unpinned Third-Party CLI Dependency
references/COMMAND_REFERENCE.md:5Arbitrary API Base URL Can Receive Credentials and Sensitive Records
Referenced artifact was not completely inspected
For full command details and options, see [references/COMMAND_REFERENCE.md](references/COMMAND_REFERENCE.md).
The command reference explicitly documents collection of sensitive tracking and personal data such as referrer URLs, UTM parameters, sub-tracking fields, IP address, and user-agent, but provides no privacy, consent, retention, or lawful-use warning. In an agent context, this increases the risk that automation will collect or transmit personal data without user awareness or appropriate safeguards, creating privacy and compliance exposure.
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
| `--description <text>` | Description |
| `--website-url <url>` | Website URL |
| `--logo-url <url>` | Logo URL |
| `--auto-approve` / `--no-auto-approve` | Enable/disable auto-approve |
| `--affiliate-links-enabled` / `--no-affiliate-links-enabled` | Enable/disable affiliate links |
### Sub-resource commands
Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.
| `--description <text>` | Description |
| `--website-url <url>` | Website URL |
| `--logo-url <url>` | Logo URL |
| `--auto-approve` / `--no-auto-approve` | Enable/disable auto-approve |
| `--affiliate-links-enabled` / `--no-affiliate-links-enabled` | Enable/disable affiliate links |
### Sub-resource commands
The config set api-key <value> command instructs users to store a credential without warning about secret handling, shell history exposure, local persistence, or safer alternatives. In an agent or shared environment, this can lead to long-lived API key disclosure through logs, transcripts, process listings, or persisted configuration files.
This markdown file documents enabling tracking of referral email and name via --track-email and --track-name, but it does not include any warning about potential privacy or data-handling implications. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors that could affect user data or privacy.
The Groups and Creatives sections include delete <id> commands, but the documentation provides no warning that these actions are destructive or may be irreversible. For markdown files, SQP-2 requires warnings when documented behaviors could affect user data or system integrity.
The payout processing workflow shows commands to mark payouts as processing and completed, including a payment reference, without a clear warning that these actions alter financial records. Because this concerns money movement and settlement state, an agent following the recipe could incorrectly finalize payouts, causing accounting errors, duplicate payments, or fraudulent completion marking.
The explicit --auto-approve flag instructs the system to make acceptance decisions automatically rather than requiring operator approval. In the context of affiliate management, autonomous approval can directly weaken onboarding controls and make abuse at scale more likely if users adopt the example without understanding the risk.
--name "My Affiliate Program" \
--tagline "Earn commissions promoting our products" \
--website-url "https://example.com" \
--auto-approve
# Set commission structure
affonso program payment-terms update --json \
The explicit --auto-approve flag instructs the system to make acceptance decisions automatically rather than requiring operator approval. In the context of affiliate management, autonomous approval can directly weaken onboarding controls and make abuse at scale more likely if users adopt the example without understanding the risk.
--name "My Affiliate Program" \
--tagline "Earn commissions promoting our products" \
--website-url "https://example.com" \
--auto-approve
# Set commission structure
affonso program payment-terms update --json \
The description says to use the skill when the user asks about 'affiliate management, referral tracking, commission handling, or payout processing,' which is broad and lacks exclusion conditions or examples of when not to invoke it. While domain-related, the trigger scope is still ambiguous because it does not define whether general informational questions versus operational CLI actions should activate the skill.
The Fraud Rules section explains that block will automatically reject activity, but does not warn users that this can deny legitimate referrals or conversions if configured aggressively. In markdown guidance, irreversible or system-impacting behaviors should be accompanied by a user-facing warning.
This workflow includes approval and group-assignment commands that directly modify affiliate records, but it does not explicitly warn that these are state-changing operations. In an agent skill context, recipe-style documentation can be translated into actions too readily, increasing the chance of unintended approvals or reassignment of affiliates without deliberate user confirmation.
Updating a commission to approved changes payout-related state and may affect financial processing, but the workflow presents it as a routine step without emphasizing the consequence. In a financial operations skill, understated mutation steps are risky because an agent or operator may approve commissions prematurely or without required validation.
The program setup section contains multiple commands that modify live affiliate program settings, including payment terms, fraud rules, portal options, and restrictions, but it lacks an explicit warning about production impact. In an operational skill, bulk configuration examples can be executed too casually, leading to accidental policy changes, altered fraud posture, or misconfigured commissions.
No suspicious patterns detected.