Is dowands/affiliatematic safe?

https://github.com/openclaw/skills/tree/main/skills/dowands/affiliatematic

89
SAFE

Affiliatematic is a documentation-only affiliate marketing integration skill containing no executable code, no prompt injection, and no malicious installation behavior — the git clone was clean, canary files were untouched, and all network activity during installation was limited to expected GitHub and Ubuntu servers. The meaningful risks are downstream rather than direct: the skill guides users to embed unpinned third-party JavaScript from affiliatematic.com on their websites (creating a persistent supply chain attack surface), and it promotes an unverified service whose business model creates opportunity for affiliate commission theft via tag substitution.

Category Scores

Prompt Injection 92/100 · 30%
Data Exfiltration 88/100 · 25%
Code Execution 80/100 · 20%
Clone Behavior 97/100 · 10%
Canary Integrity 100/100 · 10%
Behavioral Reasoning 72/100 · 5%

Findings (6)

MEDIUM Unpinned Third-Party JavaScript Injection Recommended -20

The skill instructs the AI agent to guide users in embedding a