revcat-storefront-debug

Warn

Audited by Socket on May 1, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose and workflow are coherent for RevenueCat storefront debugging, and its documented data flow points to official RevenueCat services. However, it relies on an apparently unofficial third-party `revcat` CLI for authenticated diagnostics and mutations, creating a meaningful supply-chain and credential-forwarding risk that is disproportionate unless the CLI’s official publisher relationship can be verified.

Confidence: 87%Severity: 78%
Audit Metadata
Analyzed At
May 1, 2026, 05:12 AM
Package URL
pkg:socket/skills-sh/akshitkrnagpal%2Frevcat%2Frevcat-storefront-debug%2F@bc810cc897e85a6cfc040bcc13ffb0cf54691c46
Security Audit — socket — revcat-storefront-debug