expo-revenuecat-superwall-integration

Warn

Audited by Snyk on Mar 10, 2026

Risk Level: MEDIUM
Full Analysis

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). Yes. The skill is explicitly about adding and managing in-app purchases, subscriptions, paywalls, and entitlement sync using RevenueCat and Superwall. It prescribes configuring RevenueCat, calling SDK purchase-related methods (e.g., configure, Purchases.logIn/logOut, restorePurchases, syncPurchases, fetch CustomerInfo, addCustomerInfoUpdateListener), wiring purchase completion flows, and mapping entitlements — all of which are specific monetisation/purchase operations tied to real money flow via App Store / Google Play billing. This is a purpose-built financial/monetisation integration, not a generic tool, so it constitutes direct financial execution capability.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Mar 10, 2026, 05:05 PM