kotlin-multiplatform-in-app-purchases

Warn

Audited by Snyk on Jul 13, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill is explicitly about implementing in-app purchases and subscriptions and includes concrete platform payment APIs and functions: Play Billing client usage and launchBillingFlow, StoreKit 2 product.purchase(), restore/purchase methods on the BillingRepository interface, and server-side validation endpoints (Google Play Developer API and App Store Server API). These are specific payment/transaction APIs (not generic browser or HTTP callers) and therefore grant direct financial execution authority for in-app payments.

Issues (1)

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
MEDIUM
Analyzed
Jul 13, 2026, 03:15 AM
Issues
1
Security Audit — snyk — kotlin-multiplatform-in-app-purchases