drop-in-ui

Pass

Audited by Gen Agent Trust Hub on Apr 21, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: Fetches the HitPay.js SDK from the official vendor domain (hit-pay.com) to provide payment functionality. This is a standard integration pattern for payment providers.
  • [COMMAND_EXECUTION]: Includes server-side code snippets that perform network operations to HitPay's payment request API. These operations are limited to the vendor's official API endpoints.
  • [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were detected. The skill correctly instructs developers to keep sensitive API keys on the server and verify payments via webhooks.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 21, 2026, 06:50 PM