Scan Report
40 /100
affiliate-skills
45 AI-powered affiliate marketing skills for research, content, SEO, landing pages, distribution, analytics, automation, and meta stages
Skill contains documented but risky curl|bash remote execution pattern for Bun installation, with legitimate but undeclared shell spawning. No malicious behavior detected, but the execution patterns warrant caution.
Use with caution
Document all shell execution capabilities in allowed-tools. Consider replacing curl|bash with verified package manager installation. Hardcoded GitHub IPs should link to official documentation instead of embedding static values.
Findings 3 items
| Severity | Finding | Location |
|---|---|---|
| Medium | Remote Script Execution via Pipe-to-Shell | SKILL.md:39 |
| Low | Hardcoded GitHub Pages IP Addresses | skills/distribution/github-pages-deployer/SKILL.md:182 |
| Low | Process Environment Access Without Declaration | tools/src/server.ts:26 |
| Resource | Declared | Inferred | Status | Evidence |
|---|---|---|---|---|
| Filesystem | READ | READ | ✓ Aligned | SKILL.md:6 declares Read tool |
| Shell | WRITE | WRITE | ✓ Aligned | SKILL.md:6 declares Bash tool; CLI spawns bun daemon |
| Network | NONE | READ | ✗ Violation | tools/src/cli.ts:78, tools/src/api.ts:6 - Makes fetch calls to localhost and lis… |
| Environment | NONE | READ | ✗ Violation | tools/src/server.ts:26 reads AFFITOR_API_KEY from process.env |
1 Critical 4 High 97 findings
Critical Dangerous Command 危险 Shell 命令
curl -fsSL https://bun.sh/install | bash SKILL.md:39 High IP Address 硬编码 IP 地址
185.199.108.153 skills/distribution/github-pages-deployer/SKILL.md:182 High IP Address 硬编码 IP 地址
185.199.109.153 skills/distribution/github-pages-deployer/SKILL.md:183 High IP Address 硬编码 IP 地址
185.199.110.153 skills/distribution/github-pages-deployer/SKILL.md:184 High IP Address 硬编码 IP 地址
185.199.111.153 skills/distribution/github-pages-deployer/SKILL.md:185 Medium External URL 外部 URL
https://list.affitor.com/api/v1 API.md:5 Medium External URL 外部 URL
https://list.affitor.com/settings API.md:13 Medium External URL 外部 URL
https://heygen.com API.md:59 Medium External URL 外部 URL
https://list.affitor.com/api/v1/programs?q=AI+video&sort=top&limit=5 API.md:196 Medium External URL 外部 URL
https://list.affitor.com/api/v1/programs?q=AI&reward_type=cps_recurring&min_cookie_days=30&sort=top&limit=20 API.md:204 Medium External URL 外部 URL
https://list.affitor.com/api/v1/programs/3f2a1b4c-0000-0000-0000-000000000000 API.md:212 Medium External URL 外部 URL
https://list.affitor.com/api/v1/programs API.md:223 Medium External URL 外部 URL
https://list.affitor.com/api/v1/programs/$ API.md:261 Medium External URL 外部 URL
https://list.affitor.com/@[handle API.md:291 Medium External URL 外部 URL
https://list.affitor.com/@sonpiaz/heygen API.md:293 Medium External URL 外部 URL
https://list.affitor.com API.md:299 Medium External URL 外部 URL
https://list.affitor.com/skills CONTRIBUTING.md:103 Medium External URL 外部 URL
https://docs.anthropic.com/en/docs/claude-code QUICKSTART.md:11 Medium External URL 外部 URL
https://git-scm.com/ QUICKSTART.md:11 Medium External URL 外部 URL
https://chatgpt.com/gpts/editor QUICKSTART.md:39 Medium External URL 外部 URL
https://gemini.google.com QUICKSTART.md:77 Medium External URL 外部 URL
https://img.shields.io/badge/License-MIT-blue.svg README.md:7 Medium External URL 外部 URL
https://img.shields.io/badge/skills-45-brightgreen README.md:8 Medium External URL 外部 URL
https://img.shields.io/badge/standard-agentskills.io-purple README.md:9 Medium External URL 外部 URL
https://agentskills.io README.md:9 Medium External URL 外部 URL
https://affitor.com README.md:303 Medium External URL 外部 URL
https://bun.sh/install SKILL.md:39 Medium External URL 外部 URL
https://skills.sh docs/distribution-strategy.md:14 Medium External URL 外部 URL
https://clawhub.ai docs/distribution-strategy.md:15 Medium External URL 外部 URL
https://skillsmp.com docs/distribution-strategy.md:16 Medium External URL 外部 URL
https://lobehub.com/skills docs/distribution-strategy.md:17 Medium External URL 外部 URL
https://skild.sh docs/distribution-strategy.md:18 Medium External URL 外部 URL
https://skillpm.dev/registry docs/distribution-strategy.md:19 Medium External URL 外部 URL
https://agentskills.so docs/distribution-strategy.md:20 Medium External URL 外部 URL
https://news.ycombinator.com/show docs/distribution-strategy.md:57 Medium External URL 外部 URL
https://producthunt.com docs/distribution-strategy.md:58 Medium External URL 外部 URL
https://devhunt.org docs/distribution-strategy.md:59 Medium External URL 外部 URL
https://indiehackers.com docs/distribution-strategy.md:60 Medium External URL 外部 URL
https://betalist.com docs/distribution-strategy.md:61 Medium External URL 外部 URL
https://reddit.com/r/ClaudeAI docs/distribution-strategy.md:70 Medium External URL 外部 URL
https://hashnode.com docs/distribution-strategy.md:76 Medium External URL 外部 URL
https://medium.com docs/distribution-strategy.md:77 Medium External URL 外部 URL
https://hackernoon.com docs/distribution-strategy.md:78 Medium External URL 外部 URL
https://lobste.rs docs/distribution-strategy.md:79 Medium External URL 外部 URL
https://theresanaiforthat.com/submit/ docs/distribution-strategy.md:87 Medium External URL 外部 URL
https://www.toolify.ai/submit docs/distribution-strategy.md:88 Medium External URL 外部 URL
https://futurepedia.io docs/distribution-strategy.md:89 Medium External URL 外部 URL
https://futuretools.io docs/distribution-strategy.md:90 Medium External URL 外部 URL
https://aiagentsdirectory.com/submit-agent docs/distribution-strategy.md:91 Medium External URL 外部 URL
https://aiagentstore.ai docs/distribution-strategy.md:92 Medium External URL 外部 URL
https://aiagentslist.com/submit docs/distribution-strategy.md:93 Medium External URL 外部 URL
https://topai.tools docs/distribution-strategy.md:94 Medium External URL 外部 URL
https://tldr.tech/ai docs/distribution-strategy.md:102 Medium External URL 外部 URL
https://therundown.ai docs/distribution-strategy.md:103 Medium External URL 外部 URL
https://superhuman.ai docs/distribution-strategy.md:104 Medium External URL 外部 URL
https://bensbites.com docs/distribution-strategy.md:105 Medium External URL 外部 URL
https://console.dev docs/distribution-strategy.md:106 Medium External URL 外部 URL
https://changelog.com docs/distribution-strategy.md:107 Medium External URL 外部 URL
https://alternativeto.net/add-new-app/ docs/distribution-strategy.md:117 Medium External URL 外部 URL
https://openalternative.co/submit docs/distribution-strategy.md:118 Medium External URL 外部 URL
https://sourceforge.net/p/add_project docs/distribution-strategy.md:119 Medium External URL 外部 URL
https://libhunt.com docs/distribution-strategy.md:120 Medium External URL 外部 URL
https://opensourcealternative.to docs/distribution-strategy.md:121 Medium External URL 外部 URL
https://registry.modelcontextprotocol.io docs/distribution-strategy.md:141 Medium External URL 外部 URL
https://pulsemcp.com/servers docs/distribution-strategy.md:142 Medium External URL 外部 URL
https://smithery.ai docs/distribution-strategy.md:144 Medium External URL 外部 URL
https://glama.ai/mcp/servers docs/distribution-strategy.md:145 Medium External URL 外部 URL
https://chatgpt.com platforms/chatgpt.md:23 Medium External URL 外部 URL
https://notion.so/affiliates platforms/cursor.md:64 Medium External URL 外部 URL
https://aistudio.google.com platforms/gemini.md:57 Medium External URL 外部 URL
https://skills.sh/$REPO scripts/distribute.sh:87 Medium External URL 外部 URL
https://supertools.therundown.ai/submit scripts/distribute.sh:456 Medium External URL 外部 URL
https://producthunt.com/posts/new scripts/distribute.sh:464 Medium External URL 外部 URL
https://claude.ai/cli$ scripts/run-evals.sh:67 Medium External URL 外部 URL
https://synthesia.io shared/references/sample-api-response.json:32 Medium External URL 外部 URL
https://descript.com shared/references/sample-api-response.json:56 Medium External URL 外部 URL
https://invideo.io shared/references/sample-api-response.json:80 Medium External URL 外部 URL
https://pictory.ai shared/references/sample-api-response.json:104 Medium External URL 外部 URL
https://partner.product.com/your-affiliate-id skills/blog/affiliate-blog-builder/references/wordpress-deploy.md:60 Medium External URL 外部 URL
https://schema.org skills/blog/affiliate-blog-builder/references/wordpress-deploy.md:104 Medium External URL 外部 URL
https://app.netlify.com/drop skills/distribution/bio-link-deployer/SKILL.md:145 Medium External URL 外部 URL
https://www.heygen.com/?ref=YOUR_ID skills/distribution/bio-link-deployer/templates/bio-link.html:254 Medium External URL 外部 URL
https://www.semrush.com/?ref=YOUR_ID skills/distribution/bio-link-deployer/templates/bio-link.html:259 Medium External URL 外部 URL
https://www.jasper.ai/?ref=YOUR_ID skills/distribution/bio-link-deployer/templates/bio-link.html:264 Medium External URL 外部 URL
https://yourblog.com/best-ai-video-tools skills/distribution/bio-link-deployer/templates/bio-link.html:276 Medium External URL 外部 URL
https://yourblog.com/heygen-review skills/distribution/bio-link-deployer/templates/bio-link.html:281 Medium External URL 外部 URL
https://twitter.com/alexcreator skills/distribution/bio-link-deployer/templates/bio-link.html:293 Medium External URL 外部 URL
https://youtube.com/@alexcreator skills/distribution/bio-link-deployer/templates/bio-link.html:298 Medium External URL 外部 URL
https://alexmarketer.github.io/heygen-landing skills/distribution/github-pages-deployer/SKILL.md:299 Medium External URL 外部 URL
https://www.heygen.com/?ref=YOUR_AFFILIATE_ID skills/landing/landing-page-creator/templates/comparison.html:423 Medium External URL 外部 URL
https://www.synthesia.io skills/landing/landing-page-creator/templates/comparison.html:453 Medium External URL 外部 URL
https://www.colossyan.com skills/landing/landing-page-creator/templates/comparison.html:482 Medium External URL 外部 URL
https://www.anthropic.com/engineering/agent-skills spec/README.md:51 Info Email 邮箱地址
[email protected] docs/distribution-strategy.md:102 Info Email 邮箱地址
[email protected] docs/distribution-strategy.md:105 Info Email 邮箱地址
[email protected] docs/distribution-strategy.md:106 Info Email 邮箱地址
[email protected] docs/distribution-strategy.md:107 File Tree
149 files · 907.4 KB · 22579 lines Markdown 92f · 17452L
HTML 3f · 1294L
JSON 4f · 1281L
TypeScript 5f · 856L
Shell 2f · 721L
Text 32f · 672L
JavaScript 2f · 263L
YAML 9f · 40L
├─
▾
docs
│ ├─
▾
launch-content
│ │ ├─
devto-article.md
Markdown
│ │ ├─
linkedin-post.md
Markdown
│ │ ├─
reddit-claudeai.md
Markdown
│ │ ├─
show-hn.md
Markdown
│ │ └─
twitter-thread.md
Markdown
│ ├─
▾
pr-templates
│ │ ├─
awesome-list-pr-body.md
Markdown
│ │ └─
list-entries.md
Markdown
│ ├─
affiliate-funnel-overview.md
Markdown
│ ├─
distribution-strategy.md
Markdown
│ ├─
sdd-review-prompt.md
Markdown
│ └─
skill-roadmap.md
Markdown
├─
▾
evals
│ └─
evals.json
JSON
├─
▾
platforms
│ ├─
chatgpt.md
Markdown
│ ├─
cursor.md
Markdown
│ ├─
gemini.md
Markdown
│ └─
openclaw.md
Markdown
├─
▾
prompts
│ └─
bootstrap.md
Markdown
├─
▾
scripts
│ ├─
distribute.sh
Shell
│ ├─
fix-frontmatter.js
JavaScript
│ ├─
generate-registry.js
JavaScript
│ └─
run-evals.sh
Shell
├─
▾
shared
│ └─
▾
references
│ ├─
affiliate-glossary.md
Markdown
│ ├─
affitor-branding.md
Markdown
│ ├─
case-studies.md
Markdown
│ ├─
flywheel-connections.md
Markdown
│ ├─
ftc-compliance.md
Markdown
│ ├─
offer-frameworks.md
Markdown
│ ├─
platform-rules.md
Markdown
│ ├─
sample-api-response.json
JSON
│ └─
seo-strategy.md
Markdown
├─
▾
skills
│ ├─
▾
analytics
│ │ ├─
▾
ab-test-generator
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
conversion-tracker
│ │ │ ├─
▾
agents
│ │ │ │ └─
openai.yaml
YAML
│ │ │ ├─
▾
references
│ │ │ │ └─
tracking-templates.md
Markdown
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
internal-linking-optimizer
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
performance-report
│ │ │ ├─
▾
agents
│ │ │ │ └─
openai.yaml
YAML
│ │ │ ├─
▾
references
│ │ │ │ └─
benchmarks.md
Markdown
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ └─
▾
seo-audit
│ │ ├─
LICENSE.txt
Text
│ │ └─
SKILL.md
Markdown
│ ├─
▾
automation
│ │ ├─
▾
content-repurposer
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
email-automation-builder
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
multi-program-manager
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
paid-ad-copy-writer
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ └─
▾
proprietary-data-generator
│ │ └─
SKILL.md
Markdown
│ ├─
▾
blog
│ │ ├─
▾
affiliate-blog-builder
│ │ │ ├─
▾
agents
│ │ │ │ └─
openai.yaml
YAML
│ │ │ ├─
▾
references
│ │ │ │ ├─
blog-templates.md
Markdown
│ │ │ │ ├─
seo-checklist.md
Markdown
│ │ │ │ └─
wordpress-deploy.md
Markdown
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
comparison-post-writer
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
content-decay-detector
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
content-moat-calculator
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
how-to-tutorial-writer
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
keyword-cluster-architect
│ │ │ └─
SKILL.md
Markdown
│ │ └─
▾
listicle-generator
│ │ ├─
LICENSE.txt
Text
│ │ └─
SKILL.md
Markdown
│ ├─
▾
content
│ │ ├─
▾
content-pillar-atomizer
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
reddit-post-writer
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
tiktok-script-writer
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
twitter-thread-writer
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ └─
▾
viral-post-writer
│ │ ├─
▾
agents
│ │ │ └─
openai.yaml
YAML
│ │ ├─
▾
references
│ │ │ ├─
platform-specs.md
Markdown
│ │ │ └─
viral-frameworks.md
Markdown
│ │ ├─
LICENSE.txt
Text
│ │ └─
SKILL.md
Markdown
│ ├─
▾
distribution
│ │ ├─
▾
bio-link-deployer
│ │ │ ├─
▾
agents
│ │ │ │ └─
openai.yaml
YAML
│ │ │ ├─
▾
references
│ │ │ │ └─
domain-setup.md
Markdown
│ │ │ ├─
▾
templates
│ │ │ │ └─
bio-link.html
HTML
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
email-drip-sequence
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
github-pages-deployer
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ └─
▾
social-media-scheduler
│ │ ├─
LICENSE.txt
Text
│ │ └─
SKILL.md
Markdown
│ ├─
▾
landing
│ │ ├─
▾
bonus-stack-builder
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
grand-slam-offer
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
guarantee-generator
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
landing-page-creator
│ │ │ ├─
▾
agents
│ │ │ │ └─
openai.yaml
YAML
│ │ │ ├─
▾
references
│ │ │ │ └─
conversion-principles.md
Markdown
│ │ │ ├─
▾
templates
│ │ │ │ ├─
comparison.html
HTML
│ │ │ │ └─
single-product.html
HTML
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
product-showcase-page
│ │ │ ├─
▾
references
│ │ │ │ └─
conversion-principles.md
Markdown
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
squeeze-page-builder
│ │ │ ├─
▾
references
│ │ │ │ └─
conversion-principles.md
Markdown
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
value-ladder-architect
│ │ │ └─
SKILL.md
Markdown
│ │ └─
▾
webinar-registration-page
│ │ ├─
▾
references
│ │ │ └─
conversion-principles.md
Markdown
│ │ ├─
LICENSE.txt
Text
│ │ └─
SKILL.md
Markdown
│ ├─
▾
meta
│ │ ├─
▾
category-designer
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
compliance-checker
│ │ │ ├─
▾
agents
│ │ │ │ └─
openai.yaml
YAML
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
funnel-planner
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ ├─
▾
self-improver
│ │ │ ├─
LICENSE.txt
Text
│ │ │ └─
SKILL.md
Markdown
│ │ └─
▾
skill-finder
│ │ ├─
▾
agents
│ │ │ └─
openai.yaml
YAML
│ │ ├─
LICENSE.txt
Text
│ │ └─
SKILL.md
Markdown
│ └─
▾
research
│ ├─
▾
affiliate-program-search
│ │ ├─
▾
agents
│ │ │ └─
openai.yaml
YAML
│ │ ├─
▾
references
│ │ │ ├─
list-affitor-api.md
Markdown
│ │ │ ├─
platform-rules.md
Markdown
│ │ │ └─
scoring-criteria.md
Markdown
│ │ ├─
LICENSE.txt
Text
│ │ └─
SKILL.md
Markdown
│ ├─
▾
commission-calculator
│ │ ├─
LICENSE.txt
Text
│ │ └─
SKILL.md
Markdown
│ ├─
▾
competitor-spy
│ │ ├─
LICENSE.txt
Text
│ │ └─
SKILL.md
Markdown
│ ├─
▾
monopoly-niche-finder
│ │ └─
SKILL.md
Markdown
│ ├─
▾
niche-opportunity-finder
│ │ ├─
LICENSE.txt
Text
│ │ └─
SKILL.md
Markdown
│ └─
▾
purple-cow-audit
│ └─
SKILL.md
Markdown
├─
▾
spec
│ └─
README.md
Markdown
├─
▾
template
│ └─
SKILL.md
Markdown
├─
▾
tools
│ └─
▾
src
│ ├─
api.ts
TypeScript
│ ├─
cache.ts
TypeScript
│ ├─
cli.ts
TypeScript
│ ├─
format.ts
TypeScript
│ └─
server.ts
TypeScript
├─
API.md
Markdown
├─
CLAUDE.md
Markdown
├─
CONTRIBUTING.md
Markdown
├─
package.json
JSON
├─
QUICKSTART.md
Markdown
├─
README.md
Markdown
├─
registry.json
JSON
└─
SKILL.md
Markdown
Dependencies 1 items
| Package | Version | Source | Known Vulns | Notes |
|---|---|---|---|---|
bun | * | runtime | No | Bun runtime required but not pinned as dependency |
Security Positives
✓ No base64, eval(), or obfuscated code patterns found
✓ No credential exfiltration detected - AFFITOR_API_KEY only used locally for API auth
✓ No access to sensitive paths (~/.ssh, ~/.aws, .env files)
✓ No external C2 communications or suspicious network activity
✓ Network requests limited to expected endpoints (127.0.0.1, list.affitor.com)
✓ All dependencies declared, MIT licensed, no malicious packages
✓ Skills generate content for user copy-paste, not automatic file writes
✓ Distribution script requires explicit user interaction before execution