Is dowands/affiliatematic safe?
https://github.com/openclaw/skills/tree/main/skills/dowands/affiliatematic
Affiliatematic is a documentation-only affiliate marketing integration skill containing no executable code, no prompt injection, and no malicious installation behavior — the git clone was clean, canary files were untouched, and all network activity during installation was limited to expected GitHub and Ubuntu servers. The meaningful risks are downstream rather than direct: the skill guides users to embed unpinned third-party JavaScript from affiliatematic.com on their websites (creating a persistent supply chain attack surface), and it promotes an unverified service whose business model creates opportunity for affiliate commission theft via tag substitution.
Category Scores
Findings (6)
MEDIUM Unpinned Third-Party JavaScript Injection Recommended -20 ▶
The skill instructs the AI agent to guide users in embedding a