pp-revenuecat
Warn
Audited by Snyk on Jul 19, 2026
Risk Level: MEDIUM
Full Analysis
MEDIUM W012: Unverifiable external dependency detected (runtime URL that controls agent).
- Potentially malicious external URL detected (high risk: 0.80). The skill's setup instructions require installing and running remote Go modules (go install github.com/mvanhorn/printing-press-library/library/payments/revenuecat/cmd/revenuecat-pp-cli@latest and go install github.com/mvanhorn/printing-press-library/library/payments/revenuecat/cmd/revenuecat-pp-mcp@latest), which fetch and build/execute remote code and are required prerequisites for the skill to run.
MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).
- Direct money access detected (high risk: 1.00). The skill explicitly exposes a refund operation that can execute refunds: "refund-cascade" with "--apply issues the refund" (command + example). This is a specific payment-related action (sending a refund/transaction) — i.e., direct financial execution authority.
Issues (2)
W012
MEDIUMUnverifiable external dependency detected (runtime URL that controls agent).
W009
MEDIUMDirect money access capability detected (payment gateways, crypto, banking).
Audit Metadata