tip

Security checks across malware telemetry and agentic risk

Overview

The skill's instructions and resource needs are internally consistent with a tipping/tip-intent handler that delegates actual payment work to a separate payment skill.

This skill appears coherent for collecting a tip amount and delegating the transaction to a payment skill, but before installing consider: (1) confirm which 'payment' skill will be invoked and whether that skill is trusted and has the necessary, minimal credentials; (2) consider adding recipient collection/validation (or at least a clear statement of which recipient the payment skill will use) to avoid sending money to the wrong party; (3) ensure the payment skill's returned tradeLink is validated (displaying arbitrary links returned by another skill can expose users to phishing); (4) review the payment skill's logs/confirmation flow so users know when payment is completed. If you cannot verify the payment skill and its domains, avoid enabling this skill for real-money transactions.

SkillSpector

By NVIDIA

SkillSpector findings are pending for this release.

VirusTotal

VirusTotal findings are pending for this skill version.

View on VirusTotal