revenuecat-troubleshoot
Pass
Audited by Gen Agent Trust Hub on May 8, 2026
Risk Level: SAFEPROMPT_INJECTION
Full Analysis
- [SAFE]: The skill is authored by RevenueCat and provides authoritative guidance for diagnosing common integration issues across multiple platforms (iOS, Android, Flutter, React Native, and KMP). It utilizes authorized tools for project inspection and follows standard developer workflows.\n- [PROMPT_INJECTION]: An indirect prompt injection surface is present as the skill involves processing untrusted external data in the form of debug logs. Ingestion points: Instructions to have users send full debug logs for analysis in
SKILL.mdand platform files. Boundary markers: Absent; no specific instructions provided to isolate log data from instructions. Capability inventory: The skill has access to MCP tools with write capabilities, such asattach-products-to-entitlementandattach-products-to-package. Sanitization: Absent; log content is not pre-processed or validated. Mitigation: The skill explicitly requires human-in-the-loop confirmation before any corrective actions are performed via MCP, which significantly reduces the risk of automated exploitation.
Audit Metadata