跳转到正文
报告库
用途分类 / 其他用途

Referrals Skill 安全审计

作者说它能做什么(原文)

When the user wants to create, optimize, or analyze a referral program, affiliate program, or word-of-mouth strategy. Also use when the user mentions 'referral,' 'affiliate,' 'ambassador,' 'word of mouth,' 'viral loop,' 'refer a friend,' 'partner program,' 'referral incentive,' 'how to get referrals,' 'customers referring customers,' or 'affiliate payout.' Use this whenever someone wants existing

第三方安全检查结论

发现安全风险

已检查文件
5
发现的风险
3
会不会运行危险命令?检查是否下载程序后直接运行、让他人远程控制电脑,或藏起要运行的命令。未发现风险
会不会泄露文件和密钥?检查是否发送含密码或密钥的文件,以及代码里是否直接写了密钥。发现 1 项风险
中风险

反欺诈建议包含设备指纹和 IP 监控,会收集可关联个人的数据

原文依据:1 处
发现了什么

技术措施明确建议设备指纹和 IP 地址监控,但没有同时说明告知、同意、用途限制、保存期限、访问控制或删除方式。

为什么需要注意

实施后可能持续识别和关联被推荐用户的设备及网络位置,增加隐私、合规和数据泄露风险;误判也可能阻止合法奖励。

该文件把设备指纹和 IP 地址监控列为实际反欺诈措施;启用时会处理可用于识别或关联用户及设备的数据。所示内容没有配套说明告知、法律依据、保存期限、访问权限或删除机制。用户可要求作者说明这些控制,并在确认前限制相关采集。

references/affiliate-programs.md:149来自说明文档打开原文件
### Prevention Measures**Technical:**- Email verification required- Device fingerprinting- IP address monitoring- Delayed reward payout (after activation)- Minimum activity threshold
会不会删除文件或一直在后台运行?检查是否大范围删除文件、改写磁盘,或设置自动启动。未发现风险
会不会绕过安全保护?检查是否跳过网站安全验证、开放过多文件权限,或取消操作前的确认。未发现风险
会不会误导 AI 或隐藏内容?检查工作说明是否要求 AI 忽略你的指令、干扰检查结果,或夹带看不见的文字。未发现风险
会不会偷偷改推广链接或收款方?检查是否强制替换推广链接或收款对象,同时要求隐瞒更改。发现 2 项风险
中风险

“最高推荐奖励”公式可能把几乎全部剩余毛利当作可支出预算

原文依据:2 处
发现了什么

公式只从 LTV 乘毛利率中扣除目标 CAC,未计入服务成本、奖励管理费用、欺诈和退款、税费或期望利润,却将结果称为“最高奖励”。示例因此得出 640 美元上限。

为什么需要注意

如果直接用于定价或预算,推荐计划可能过度奖励、延长回本期,甚至让新增客户无利可图。

该公式确实把“LTV×毛利率”扣除目标 CAC 后的全部余额称为最高奖励,示例得到 640 美元。它没有在公式中扣除工具、管理、退款、欺诈、税费或目标利润;而同一文件稍后承认项目成本还包括工具和管理时间。若直接据此定预算,可能高估可承受奖励。用户应要求完整成本模型和敏感性测试。

references/program-examples.md:78来自说明文档打开原文件
## Incentive Sizing Framework**Calculate your maximum incentive:**```Max Referral Reward = (Customer LTV × Gross Margin) - Target CAC```**Example:**- LTV: $1,200- Gross margin: 70%- Target CAC: $200- Max reward: ($1,200 × 0.70) - $200 = $640
查看另外 1 个位置
references/program-examples.md:132来自说明文档打开原文件
### Calculating Referral Program ROI```Referral Program ROI = (Revenue from referred customers - Program costs) / Program costsProgram costs = Rewards paid + Tool costs + Management time```
中风险

精确的增长和客户价值“典型值”没有提供来源或适用范围

原文依据:3 处
发现了什么

Skill 给出推荐客户 LTV、流失率、再推荐率以及参与率的精确区间,却没有注明数据来源、行业、样本、时间或统计口径。

为什么需要注意

用户可能把这些数字当作可靠基准来预测收入、批准奖励预算或误判项目表现,导致不适合自身业务的商业决策。

Skill 将若干精确区间直接标为“典型发现”,并把推荐参与率标为“Good/Great/Exceptional”,但可见材料没有给出来源、行业、样本、时期或指标口径。用户若用这些数字设目标或作投资判断,可能得到不适合自身业务的基准;应要求出处并以自身队列数据验证。

SKILL.md:174来自说明文档打开原文件
### Typical Findings- Referred customers have 16-25% higher LTV- Referred customers have 18-37% lower churn- Referred customers refer others at 2-3x rate
查看另外 2 个位置
references/program-examples.md:120来自说明文档打开原文件
Benchmarks:- Good: 10-25% of customers refer- Great: 25-50%- Exceptional: 50%+
references/program-examples.md:115来自说明文档打开原文件
**Referral rate:**```Referral Rate = (Customers who refer) / (Total customers)```Benchmarks:- Good: 10-25% of customers refer- Great: 25-50%- Exceptional: 50%+

Skill 逻辑拆解

8 个说明模块

该 Skill 的主要行为是先读取本地产品营销背景,再询问项目类型、LTV、CAC、现状和预算,用这些信息提出推荐或联盟计划。读取范围包括三个约定名称的营销上下文文件,可能涉及非公开商业数据。

查看原文
SKILL.md:14来自说明文档打开原文件
**Check for product marketing context first:**If `.agents/product-marketing.md` exists (or `.claude/product-marketing.md`, or the legacy `product-marketing-context.md` filename, in older setups), read it before asking questions. Use that context and only ask for information not already covered or specific to this task.
SKILL.md:17来自说明文档打开原文件
Gather this context (ask if not provided):### 1. Program Type- Customer referral program, affiliate program, or both?- B2B or B2C?- What's the average customer LTV?- What's your current CAC from other channels?
SKILL.md:35来自说明文档打开原文件
### 4. Resources- Tools/platforms you use or consider?- Budget for referral incentives?

它提供的是营销设计建议和操作清单,包括分享机制、奖励、跟踪归因、网站及应用内推广和提醒邮件。所示内容是建议或模板;提供的文件中没有展示自动发送邮件、修改网站或调用支付平台的实现代码。

查看原文
SKILL.md:182来自说明文档打开原文件
## Launch Checklist### Before Launch- [ ] Define program goals and success metrics- [ ] Design incentive structure- [ ] Build or configure referral tool- [ ] Create referral landing page- [ ] Set up tracking and attribution- [ ] Define fraud prevention rules- [ ] Create terms and conditions- [ ] Test complete referral flow### Launch- [ ] Announce to existing customers- [ ] Add in-app referral prompts- [ ] Update website with program details- [ ] Brief support team### Post-Launch (First 30 Days)- [ ] Review conversion funnel- [ ] Identify top referrers- [ ] Gather feedback- [ ] Fix friction points- [ ] Send reminder emails to non-referrers
SKILL.md:211来自说明文档打开原文件
### Referral Program Launch```Subject: You can now earn [reward] for sharing [Product]We just launched our referral program!Share [Product] with friends and earn [reward] for each signup.They get [their reward] too.[Unique referral link]1. Share your link2. Friend signs up3. You both get [reward]```

该 Skill 也建议把产品品牌放入客户面向外部的内容,例如署名徽章、嵌入链接和难以移除的水印;免费用户的输出由此成为产品广告。

查看原文
references/viral-mechanisms.md:36来自说明文档打开原文件
### 1. "Powered By" BadgesA small attributed badge on user-facing output ("Powered by [Product]"). Every page/form/widget a customer ships becomes an ad. Often free-tier only (paid tier removes it).
references/viral-mechanisms.md:49来自说明文档打开原文件
### 4. Embed OptionsLet users embed their content elsewhere; the embed carries your brand and a link back.- **Notion, Figma, Loom** — embedded docs, designs, and videos spread the product to every viewer on every host site.### 5. Watermarks / Mandatory BadgesLike "Powered By" but harder to remove — baked into the output itself.- **OpusClips** watermark on generated clips.- **"Made in Webflow"** badge on free-plan sites.Free tier carries the mark; paid tier removes it. The free users become the distribution.
从这里开始 · 工作说明SKILL.md
referrals
连线表示工作说明包含的模块,不是实际运行顺序。点击模块可查看原文。 另有 4 个章节,可在原文件中查看。

文件引用关系图

4 处引用
哪些文件发起引用引用了什么
连线表示真实的文件引用,不是运行顺序。点击节点可高亮相关连线,并查看具体文件和原文位置。虚线表示还有文件需要定位。
文件与检查记录5 个文件

检查范围与遗漏

逐文件查看涉及的内容

下方列出本次涉及的原文范围;纳入检查不代表已查清所有问题。

  • SKILL.md已纳入全文
  • references/affiliate-programs.md已纳入全文
  • references/program-examples.md已纳入全文
  • references/viral-mechanisms.md已纳入全文
  • evals/evals.json已纳入全文

这份报告只针对上方版本。我们看了拿到的代码和说明文件,没有实际运行 Skill,也没有检查它另外安装的软件包。因此,这不是“保证安全”的承诺;换了版本或使用环境,结果也可能不同。

  • SKILL.md工作说明
  • evals/evals.json配套文件
  • references/affiliate-programs.md配套文件
  • references/program-examples.md配套文件
  • references/viral-mechanisms.md配套文件
读取了多少行
797
文件校验值(用于核对版本)
e390683d5c4878aa1bed71bd843899fca1d9d167c841dec5be98d5c8d1121ee2