Back to skill

Security audit

Drip Billing

Security checks for vulnerabilities and agentic risk

Overview

The skill is a coherent Drip billing integration, but it should be reviewed because it gives agents billing/customer authority and documents unpinned npm/npx package execution with an API key.

Install only after deciding you are comfortable giving an agent access to Drip billing and customer operations. Use a pk_test_ or least-privileged pk_live_ key, avoid sk_ keys unless you truly need admin operations, pin package versions instead of using unversioned npm/npx commands, and require human approval for billing or customer-changing actions where your client supports it.

Vulnerability Patterns
  • Insecure DependenciesIntroduces malicious components through unsafe dependency sources
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
Findings (2)

T08 · Insecure Dependencies

Warning
Location
SKILL.md:88
Finding

Unpinned Drip SDK Dependency Installation

Content
View full analysis

Vulnerability Details

File Location: SKILL.md:88-91
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

bash
## Installation

npm install @drip-sdk/node

Technical Analysis

The installation command does not pin @drip-sdk/node to a specific reviewed version and does not require a lockfile or package-integrity verification. Consequently, npm may install whichever version is currently selected by the registry and applicable npm configuration.

This creates a supply-chain risk because the code ultimately executed by users can change after the Skill has been audited. A compromised maintainer account, registry package, or unsafe future release could cause arbitrary package lifecycle or runtime code to execute with the permissions of the user running npm. Although the document recommends checking the package's npm page, manual inspection of a listing does not provide reproducible dependency resolution or cryptographic integrity enforcement.

Attack Path

  1. An attacker compromises the package publication process, maintainer credentials, or a future package release.
  2. The attacker publishes a malicious version under @drip-sdk/node.
  3. A user follows the documented unversioned npm install command.
  4. npm resolves and installs the attacker-controlled version.
  5. Malicious lifecycle or runtime code executes in the installation or application context.
  6. The malicious code can access data and resources available to that process, potentially including DRIP_API_KEY when the integrated application subsequently runs.

Impact Assessment

Successful exploitation could permit arbitrary code execution under the account installing or running the dependency. The accessible scope may include application files, environment variables, network access, and credentials available to that process. It does not inherently grant administrator privileges; impact is bounded ...[truncated 201 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the SDK to an exact reviewed version, for example npm install --save-exact @drip-sdk/node@<reviewed-version>.
  • Commit a package lockfile and use npm ci in automated or production installations to enforce reproducible resolution.
  • Verify package provenance, publisher identity, signatures where available, and lockfile integrity before deployment.
  • Review lifecycle scripts and dependency changes when updating the pinned version.
  • Use automated dependency scanning and require explicit security review before version upgrades.
  • Run the application with minimal operating-system permissions and expose only the required environment variables.
  • Continue using a least-privileged pk_ key and rotate it if dependency compromise is suspected.

T08 · Insecure Dependencies

Warning
Location
references/API.md:22
Finding

Unpinned MCP Package Download and Execution Through npx

Content
View full analysis

Vulnerability Details

File Location: references/API.md:22-31
Vulnerability Type: T08: Insecure Dependencies
Risk Level: Medium

Vulnerable Code

json
{
  "mcpServers": {
    "drip": {
      "command": "npx",
      "args": ["@drip/mcp-server"],
      "env": { "DRIP_API_KEY": "pk_live_..." }
    }
  }
}

Technical Analysis

This MCP configuration invokes npx with an unversioned package name. If the package is not already available locally, npx may resolve, download, and execute registry-hosted code at launch time. The executed payload can therefore change after the Skill has been reviewed.

The launched process is explicitly supplied DRIP_API_KEY. A malicious package release could read and exfiltrate that key in addition to accessing other resources permitted to the process. The MCP server also exposes billing and usage operations to the agent, making package authenticity and least-privilege isolation particularly important.

This is a dependency and runtime supply-chain weakness rather than evidence that the named package is currently malicious.

Attack Path

  1. An attacker compromises the @drip/mcp-server publication channel, maintainer account, or a future release.
  2. The attacker publishes malicious code under the expected package name.
  3. An MCP-compatible client starts the documented server configuration.
  4. npx resolves the mutable package reference and downloads the compromised release when necessary.
  5. The package executes as the MCP server with the user's local process permissions.
  6. It reads the supplied DRIP_API_KEY and may exfiltrate it or misuse the Drip operations available to that key.
  7. It may also inspect or modify other files and resources accessible to the invoking process.

Impact Assessment

Successful exploitation could result in arbitrary local code execution within the MCP process's privilege boundary and disclosure of the sup ...[truncated 499 chars]

Remediation
View remediation

Remediation Suggestions

  • Pin the MCP server to an exact reviewed version rather than using an unversioned package reference.
  • Install the pinned package through a committed lockfile using npm ci, then invoke its fixed local binary instead of permitting npx to resolve and download code dynamically.
  • If npx must be retained, specify an exact package version and configure it to avoid interactive or unexpected package installation; however, a preinstalled local binary is preferable.
  • Verify package provenance and integrity before installation and review all version updates.
  • Run the MCP server in a sandbox or container with a read-only filesystem where practical, restricted network access, and no unnecessary host-directory mounts.
  • Supply only a least-privileged pk_ key and expose no unrelated environment variables to the process.
  • Restrict autonomous billing tools with client-side approval or policy controls where supported.
  • Rotate the API key immediately if package or runtime compromise is suspected.
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.