Drip Billing

Security checks across malware telemetry and agentic risk

Overview

This skill is a disclosed Drip billing and usage-tracking integration, with no evidence of hidden code, destructive behavior, or unexpected data access.

Install only if you intend to let your agent write usage and billing telemetry to Drip. Prefer pk_test_ or pk_live_ keys, avoid sk_ keys unless admin operations are required, keep DRIP_BASE_URL pointed at a trusted endpoint, and never place raw prompts, secrets, PII, source code, or full request bodies in metadata.

SkillSpector

By NVIDIA
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

VirusTotal

66/66 vendors flagged this skill as clean.

View on VirusTotal