revenuecat-sdk-compatibility

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFECOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: The skill instructs the agent to use standard CLI tools or a code execution environment to analyze and filter data retrieved from RevenueCat tools. \n
  • Evidence: "Use jq for quick filtering or a code execution tool for version comparisons, grouping, and subscriber-share calculations when the output is too large to analyze reliably by inspection." \n- [PROMPT_INJECTION]: The skill processes data from external tool outputs and documentation links, which represents an attack surface for indirect prompt injection. \n
  • Ingestion points: Data fetched from list-sdk-feature-gates and list-sdk-versions tools in SKILL.md. \n
  • Boundary markers: None present. \n
  • Capability inventory: The skill has the capability to execute commands (jq) and run code for data analysis. \n
  • Sanitization: No explicit validation or sanitization of tool-provided data is defined.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 10:47 PM
Security Audit — agent-trust-hub — revenuecat-sdk-compatibility