revenuecat-store-state

Warn

Audited by Snyk on Aug 26, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill explicitly provides tools to read and write product pricing and related store-state in App Store Connect and Google Play Console. It names specific write operations (create-product-prices, set-product-store-state, equalize-subscription-prices, submit-products-to-store) and warns that writes "go straight to production stores and can change what live customers see and pay." These are targeted APIs for updating prices/availability (financial configuration) rather than generic automation, so this grants direct financial execution authority over product pricing.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 26, 2026, 08:41 PM
Issues
1
Security Audit — snyk — revenuecat-store-state