Skip to content
Report library
Purpose / Other

Referrals Skill Security Audit

What the author says it does (original text)

When the user wants to create, optimize, or analyze a referral program, affiliate program, or word-of-mouth strategy. Also use when the user mentions 'referral,' 'affiliate,' 'ambassador,' 'word of mouth,' 'viral loop,' 'refer a friend,' 'partner program,' 'referral incentive,' 'how to get referrals,' 'customers referring customers,' or 'affiliate payout.' Use this whenever someone wants existing

Independent security check

Security risks found

Files checked
5
Risks found
3
Could it run dangerous commands?Looks for programs run straight after downloading, remote control of your computer, and hidden commands.No risks found
Could it expose your files or keys?Looks for uploads of files containing passwords or keys, and keys written directly in the code.Risks found: 1
Medium risk

Fraud controls recommend device fingerprinting and IP monitoring, which collect linkable personal data

Source references: 1
What we found

The technical measures explicitly recommend device fingerprinting and IP-address monitoring without accompanying requirements for notice, consent, purpose limits, retention, access control, or deletion.

Why this matters

If implemented, they may continuously identify and correlate referred users’ devices and network locations, creating privacy, compliance, and breach exposure. False positives may also deny legitimate rewards.

The file presents device fingerprinting and IP-address monitoring as operational fraud controls. If enabled, they process data that can identify or link users and devices. The shown material does not address notice, legal basis, retention, access, or deletion. Users can ask the author to document these controls and restrict collection until they are confirmed.

references/affiliate-programs.md:149In the instructionsOpen original file
### Prevention Measures**Technical:**- Email verification required- Device fingerprinting- IP address monitoring- Delayed reward payout (after activation)- Minimum activity threshold
Could it delete files or keep running?Looks for broad file deletion, disk overwrites, and programs set to start automatically.No risks found
Could it bypass safety checks?Looks for skipped website security checks, excessive file access, or actions that skip your approval.No risks found
Could it mislead the AI or hide text?Checks the skill instructions for requests to ignore you, influence the report, or hide text in invisible characters.No risks found
Could it change links or payment recipients without asking?Looks for forced referral or payment changes combined with instructions to hide the change.Risks found: 2
Medium risk

The “maximum referral reward” formula can allocate nearly all remaining gross profit to incentives

Source references: 2
What we found

The formula subtracts only target CAC from LTV times gross margin. It omits servicing and program costs, fraud and refunds, taxes, and required profit, yet labels the result a maximum reward; its example therefore produces a $640 cap.

Why this matters

Using it directly for pricing or budgeting could overfund rewards, lengthen payback, or make acquired customers unprofitable.

The formula calls the entire remainder after subtracting target CAC from LTV times gross margin the maximum reward, producing $640 in its example. It does not deduct tools, administration, refunds, fraud, taxes, or desired profit, while the same file later recognizes tool and management costs. Used directly for budgeting, it could overstate an affordable reward. Users should request a full-cost model and sensitivity testing.

references/program-examples.md:78In the instructionsOpen original file
## Incentive Sizing Framework**Calculate your maximum incentive:**```Max Referral Reward = (Customer LTV × Gross Margin) - Target CAC```**Example:**- LTV: $1,200- Gross margin: 70%- Target CAC: $200- Max reward: ($1,200 × 0.70) - $200 = $640
Show 1 other places
references/program-examples.md:132In the instructionsOpen original file
### Calculating Referral Program ROI```Referral Program ROI = (Revenue from referred customers - Program costs) / Program costsProgram costs = Rewards paid + Tool costs + Management time```
Medium risk

Precise “typical” growth and customer-value claims lack sources and applicability limits

Source references: 3
What we found

The Skill supplies exact ranges for referred-customer LTV, churn, further referrals, and participation without identifying a source, industry, sample, date, or measurement method.

Why this matters

A user could treat these figures as dependable benchmarks when forecasting revenue, approving incentive budgets, or judging performance, leading to decisions that do not fit their business.

The Skill labels precise ranges as “Typical Findings” and referral-rate ranges as “Good,” “Great,” and “Exceptional,” but the visible material gives no source, industry, sample, period, or measurement definition. Using them for targets or investment decisions may apply unsuitable benchmarks. Users should request sources and validate them against their own cohort data.

SKILL.md:174In the instructionsOpen original file
### Typical Findings- Referred customers have 16-25% higher LTV- Referred customers have 18-37% lower churn- Referred customers refer others at 2-3x rate
Show 2 other places
references/program-examples.md:120In the instructionsOpen original file
Benchmarks:- Good: 10-25% of customers refer- Great: 25-50%- Exceptional: 50%+
references/program-examples.md:115In the instructionsOpen original file
**Referral rate:**```Referral Rate = (Customers who refer) / (Total customers)```Benchmarks:- Good: 10-25% of customers refer- Great: 25-50%- Exceptional: 50%+

Inside this skill

8 instruction sections

The Skill first reads local product-marketing context, then asks about program type, LTV, CAC, current state, and budget to advise on referral or affiliate programs. Its read scope includes three conventional marketing-context filenames that may contain non-public business information.

View source
SKILL.md:14In the instructionsOpen original file
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
SKILL.md:17In the instructionsOpen original file
Gather this context (ask if not provided):### 1. Program Type- Customer referral program, affiliate program, or both?- B2B or B2C?- What's the average customer LTV?- What's your current CAC from other channels?
SKILL.md:35In the instructionsOpen original file
### 4. Resources- Tools/platforms you use or consider?- Budget for referral incentives?

It provides marketing-design guidance and operational checklists covering sharing, rewards, attribution, website and in-app promotion, and reminder emails. The visible material is advice or templates; the supplied files do not show implementation code that automatically sends messages, changes a site, or invokes a payment platform.

View source
SKILL.md:182In the instructionsOpen original file
## Launch Checklist### Before Launch- [ ] Define program goals and success metrics- [ ] Design incentive structure- [ ] Build or configure referral tool- [ ] Create referral landing page- [ ] Set up tracking and attribution- [ ] Define fraud prevention rules- [ ] Create terms and conditions- [ ] Test complete referral flow### Launch- [ ] Announce to existing customers- [ ] Add in-app referral prompts- [ ] Update website with program details- [ ] Brief support team### Post-Launch (First 30 Days)- [ ] Review conversion funnel- [ ] Identify top referrers- [ ] Gather feedback- [ ] Fix friction points- [ ] Send reminder emails to non-referrers
SKILL.md:211In the instructionsOpen original file
### Referral Program Launch```Subject: You can now earn [reward] for sharing [Product]We just launched our referral program!Share [Product] with friends and earn [reward] for each signup.They get [their reward] too.[Unique referral link]1. Share your link2. Friend signs up3. You both get [reward]```

The Skill also recommends placing product branding in customer-facing output through attribution badges, embedded links, and harder-to-remove watermarks, turning free users’ output into product advertising.

View source
references/viral-mechanisms.md:36In the instructionsOpen original file
### 1. "Powered By" BadgesA small attributed badge on user-facing output ("Powered by [Product]"). Every page/form/widget a customer ships becomes an ad. Often free-tier only (paid tier removes it).
references/viral-mechanisms.md:49In the instructionsOpen original file
### 4. Embed OptionsLet users embed their content elsewhere; the embed carries your brand and a link back.- **Notion, Figma, Loom** — embedded docs, designs, and videos spread the product to every viewer on every host site.### 5. Watermarks / Mandatory BadgesLike "Powered By" but harder to remove — baked into the output itself.- **OpusClips** watermark on generated clips.- **"Made in Webflow"** badge on free-plan sites.Free tier carries the mark; paid tier removes it. The free users become the distribution.
Start here · InstructionsSKILL.md
referrals
Lines connect the instruction file to its sections, not an observed execution order. Select a section to read the source. 4 more sections are available in the original file.

File reference map

References: 4
Files making referencesReferenced content
Lines show actual file references, not execution order. Select a node to highlight its connections and inspect the files and source locations. Dashed lines include files that still need locating.
Files and check records5 files

Coverage and gaps

Content covered in each file

These are the source ranges included in this check, not a guarantee that every issue has been resolved.

  • SKILL.mdFull text included
  • references/affiliate-programs.mdFull text included
  • references/program-examples.mdFull text included
  • references/viral-mechanisms.mdFull text included
  • evals/evals.jsonFull text included

This report is for the version above. We read the available code and instructions without running the skill or checking extra packages it installs. This is not a promise of safety: a different version or setup may behave differently.

  • SKILL.mdInstructions
  • evals/evals.jsonSupporting file
  • references/affiliate-programs.mdSupporting file
  • references/program-examples.mdSupporting file
  • references/viral-mechanisms.mdSupporting file
Lines read
797
File checksum (to compare versions)
e390683d5c4878aa1bed71bd843899fca1d9d167c841dec5be98d5c8d1121ee2