axiom-implement-iap
Pass
Audited by Gen Agent Trust Hub on Apr 26, 2026
Risk Level: SAFE
Full Analysis
- [SAFE]: The skill provides legitimate technical guidance and code snippets for implementing in-app purchases using official Apple StoreKit 2 APIs.
- [SAFE]: No evidence of prompt injection or instructions to bypass security filters were found; the usage of 'CRITICAL' refers to essential development steps for local testing.
- [SAFE]: There are no network operations, external downloads, or remote code execution patterns. All code is intended to be implemented locally by the developer within an Xcode project.
- [SAFE]: No hardcoded credentials or access to sensitive local environment files (e.g., .ssh, .aws) were detected.
- [SAFE]: The skill follows established security best practices for payment processing, such as mandatory transaction verification and explicit completion of transaction cycles using 'transaction.finish()'.
Audit Metadata