expo-revenuecat-superwall-integration
Audited by Socket on Mar 10, 2026
1 alert found:
Obfuscated FileThe skill description is largely coherent with its stated purpose: it defines a structured, architecture-aware workflow for integrating RevenueCat and Superwall into Expo-based React Native apps, including preflight checks, identity handling, and migration paths. It relies on standard Expo package management and well-known libraries, and it emphasizes safe defaults (production-ready setup, one-time RevenueCat configuration, proper placement). There are no explicit unverifiable binaries or suspicious data-exfiltration patterns present. The data flows described (entitlements syncing, identity synchronization, and analytics) are consistent with the intended monetization integration. Some areas are underspecified (detailed endpoint mappings, exact entitlement schemas, and concrete credentials handling in code), but these are typical for a high-level integration guide and do not undermine the overall coherence. Overall risk is low-to-moderate (securityRisk around 0.25–0.40; malware near 0.05), with a cautious note to ensure proper key management and environment handling during implementation.