drop-in-ui
Pass
Audited by Gen Agent Trust Hub on Apr 21, 2026
Risk Level: SAFE
Full Analysis
- [EXTERNAL_DOWNLOADS]: Fetches the HitPay.js SDK from the official vendor domain (hit-pay.com) to provide payment functionality. This is a standard integration pattern for payment providers.
- [COMMAND_EXECUTION]: Includes server-side code snippets that perform network operations to HitPay's payment request API. These operations are limited to the vendor's official API endpoints.
- [SAFE]: No malicious patterns, obfuscation, or unauthorized data access were detected. The skill correctly instructs developers to keep sensitive API keys on the server and verify payments via webhooks.
Audit Metadata