revcat-getting-started
Warn
Audited by Socket on May 2, 2026
1 alert found:
SecuritySecuritySKILL.md
MEDIUMSecurityMEDIUM
SKILL.md
SUSPICIOUS: the skill is internally coherent as a getting-started guide for a RevenueCat CLI, but it steers users to an unofficial personal-account tool and forwards RevenueCat credentials/tokens into that tool, including repo-local credential copies. This is not confirmed malware, but the install trust and credential-handling model are risky enough to treat as suspicious rather than benign.
Confidence: 87%Severity: 79%
Audit Metadata