Back to skill

Security audit

Affonso - Affiliate Marketing Software

Security checks for vulnerabilities and agentic risk

Overview

The skill fits its Affonso affiliate-management purpose, but it gives broad authenticated control over affiliate, commission, payout, tracking, and CLI endpoint settings without enough guardrails.

Review this skill before installing. Use a narrowly scoped Affonso API key, avoid passing secrets on the command line, do not set a custom base URL unless you fully trust the endpoint, and require explicit human approval before payout, commission, auto-approval, auto-payout, delete, or bulk configuration changes. Pin or otherwise verify the CLI package before use.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Insecure Skill Coding PracticesFinds exploitable flaws such as hardcoded secrets or command injection
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
Findings (2)

T08 · Insecure Dependencies

Error
Location
SKILL.md:10
Finding

Unpinned Third-Party CLI Dependency

Content
View full analysis
Remediation
View remediation

T09 · Insecure Skill Coding Practices

Error
Location
references/COMMAND_REFERENCE.md:5
Finding

Arbitrary API Base URL Can Receive Credentials and Sensitive Records

Content
View full analysis
` | API key for authentication | | `--base-url ` | Custom API base URL | | `--no-color` | Disable colored output | ``` Related persistent configuration is documented at lines 374–383: ```markdown ## config Manage CLI configuration. ### `config get ` Get a config value. Key must be `api-key` or `base-url`. ### `config set ` Set a config value. Key must be `api-key` or `base-url`. ``` ### Technical Analysis The Agent-facing command reference permits authenticated commands to use an arbitrary `--base-url`. It also permits the base URL to be stored persistently through `config set base-url`. The documentation does not impose an Affonso hostname allowlist, require HTTPS, warn that authentication material may be sent to the selected origin, or require user confirmation before changing the endpoint. If the underlying CLI attaches its API credential to requests made to the selected base URL, an attacker-controlled endpoint could receive the API key. Even if credential forwarding differs by command, command payloads can contain sensitive information, including: - Affiliate and referral names and email addresses. - External user, customer, subscription, and payment-intent identifiers. - Click IP addresses, user-agent strings, referrer URLs, and tracking parameters. - Commission amounts, payout status, payment methods, and payment references. - Program configuration and partner portal information. A custom endpoint can be legitimate for development or self-hosted deployments, but unrestricted use is not necessary for ordinary administration of the declared Affonso serv ...[truncated 2234 chars]
Remediation
View remediation
Vulnerability Patterns
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Trigger AbuseOverly Broad Trigger, Shadow Command Trigger, Keyword Baiting Trigger
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
Findings (15)

Ae1

High
Category
analysis-evasion
Confidence
100% confidence
Finding

Referenced artifact was not completely inspected

Content

Scanner excerpt · SKILL.md (reported line 52)May include surrounding context.

md
For full command details and options, see [references/COMMAND_REFERENCE.md](references/COMMAND_REFERENCE.md).

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The command reference explicitly documents collection of sensitive tracking and personal data such as referrer URLs, UTM parameters, sub-tracking fields, IP address, and user-agent, but provides no privacy, consent, retention, or lawful-use warning. In an agent context, this increases the risk that automation will collect or transmit personal data without user awareness or appropriate safeguards, creating privacy and compliance exposure.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/COMMAND_REFERENCE.md (reported line 318)May include surrounding context.

md
| `--description <text>` | Description |
| `--website-url <url>` | Website URL |
| `--logo-url <url>` | Logo URL |
| `--auto-approve` / `--no-auto-approve` | Enable/disable auto-approve |
| `--affiliate-links-enabled` / `--no-affiliate-links-enabled` | Enable/disable affiliate links |

### Sub-resource commands

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
65% confidence
Finding

Skill enables autonomous high-impact decisions without human-in-the-loop verification. Critical operations (destructive commands, financial transactions, data deletion) should require explicit user confirmation.

Content

Scanner excerpt · references/COMMAND_REFERENCE.md (reported line 318)May include surrounding context.

md
| `--description <text>` | Description |
| `--website-url <url>` | Website URL |
| `--logo-url <url>` | Logo URL |
| `--auto-approve` / `--no-auto-approve` | Enable/disable auto-approve |
| `--affiliate-links-enabled` / `--no-affiliate-links-enabled` | Enable/disable affiliate links |

### Sub-resource commands

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
97% confidence
Finding

The config set api-key <value> command instructs users to store a credential without warning about secret handling, shell history exposure, local persistence, or safer alternatives. In an agent or shared environment, this can lead to long-lived API key disclosure through logs, transcripts, process listings, or persisted configuration files.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
93% confidence
Finding

This markdown file documents enabling tracking of referral email and name via --track-email and --track-name, but it does not include any warning about potential privacy or data-handling implications. For markdown files, SQP-2 applies when descriptions omit warnings about behaviors that could affect user data or privacy.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
95% confidence
Finding

The Groups and Creatives sections include delete <id> commands, but the documentation provides no warning that these actions are destructive or may be irreversible. For markdown files, SQP-2 requires warnings when documented behaviors could affect user data or system integrity.

Content

No source excerpt is available for this finding.

Missing User Warnings

Medium
Category
Not specified by scanner
Confidence
94% confidence
Finding

The payout processing workflow shows commands to mark payouts as processing and completed, including a payment reference, without a clear warning that these actions alter financial records. Because this concerns money movement and settlement state, an agent following the recipe could incorrectly finalize payouts, causing accounting errors, duplicate payments, or fraudulent completion marking.

Content

No source excerpt is available for this finding.

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
85% confidence
Finding

The explicit --auto-approve flag instructs the system to make acceptance decisions automatically rather than requiring operator approval. In the context of affiliate management, autonomous approval can directly weaken onboarding controls and make abuse at scale more likely if users adopt the example without understanding the risk.

Content

Scanner excerpt · references/WORKFLOWS.md (reported line 88)May include surrounding context.

md
--name "My Affiliate Program" \
  --tagline "Earn commissions promoting our products" \
  --website-url "https://example.com" \
  --auto-approve

# Set commission structure
affonso program payment-terms update --json \

Autonomous Decision Making

Medium
Category
Excessive Agency
Confidence
80% confidence
Finding

The explicit --auto-approve flag instructs the system to make acceptance decisions automatically rather than requiring operator approval. In the context of affiliate management, autonomous approval can directly weaken onboarding controls and make abuse at scale more likely if users adopt the example without understanding the risk.

Content

Scanner excerpt · references/WORKFLOWS.md (reported line 88)May include surrounding context.

md
--name "My Affiliate Program" \
  --tagline "Earn commissions promoting our products" \
  --website-url "https://example.com" \
  --auto-approve

# Set commission structure
affonso program payment-terms update --json \

Vague Triggers

Low
Category
Not specified by scanner
Confidence
91% confidence
Finding

The description says to use the skill when the user asks about 'affiliate management, referral tracking, commission handling, or payout processing,' which is broad and lacks exclusion conditions or examples of when not to invoke it. While domain-related, the trigger scope is still ambiguous because it does not define whether general informational questions versus operational CLI actions should activate the skill.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
80% confidence
Finding

The Fraud Rules section explains that block will automatically reject activity, but does not warn users that this can deny legitimate referrals or conversions if configured aggressively. In markdown guidance, irreversible or system-impacting behaviors should be accompanied by a user-facing warning.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
88% confidence
Finding

This workflow includes approval and group-assignment commands that directly modify affiliate records, but it does not explicitly warn that these are state-changing operations. In an agent skill context, recipe-style documentation can be translated into actions too readily, increasing the chance of unintended approvals or reassignment of affiliates without deliberate user confirmation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
86% confidence
Finding

Updating a commission to approved changes payout-related state and may affect financial processing, but the workflow presents it as a routine step without emphasizing the consequence. In a financial operations skill, understated mutation steps are risky because an agent or operator may approve commissions prematurely or without required validation.

Content

No source excerpt is available for this finding.

Missing User Warnings

Low
Category
Not specified by scanner
Confidence
84% confidence
Finding

The program setup section contains multiple commands that modify live affiliate program settings, including payment terms, fraud rules, portal options, and restrictions, but it lacks an explicit warning about production impact. In an operational skill, bulk configuration examples can be executed too casually, leading to accidental policy changes, altered fraud posture, or misconfigured commissions.

Content

No source excerpt is available for this finding.

Static analysis

No suspicious patterns detected.