kotlin-multiplatform-in-app-purchases

Pass

Audited by Gen Agent Trust Hub on Jul 13, 2026

Risk Level: SAFE
Full Analysis
  • [SAFE]: The skill utilizes official platform libraries for billing, specifically com.android.billingclient:billing-ktx version 7.1.1 for Android and Apple's native StoreKit 2 for iOS.
  • [SAFE]: Implements a robust domain model using a sealed interface (PurchaseState) to manage entitlement states without exposing platform-specific logic to the shared business layer.
  • [SAFE]: Explicitly recommends server-side receipt validation for subscriptions via official Google Play Developer and App Store Server APIs, which is the industry standard for preventing client-side purchase tampering.
  • [SAFE]: Adheres to Apple App Store guideline 3.1.1 by ensuring that the 'restore purchases' functionality is triggered by explicit user action rather than automatically on app launch.
  • [SAFE]: No unauthorized network operations, hardcoded credentials, or command execution patterns were found. The skill includes guidance on acknowledging purchases to prevent automatic refunds, following Google Play's standard requirements.
Audit Metadata
Risk Level
SAFE
Analyzed
Jul 13, 2026, 03:15 AM
Security Audit — agent-trust-hub — kotlin-multiplatform-in-app-purchases