Back to skill

Security audit

RevenueCat

Security checks for vulnerabilities and agentic risk

Overview

The skill is mostly transparent, but it mixes a read-oriented RevenueCat assistant with documentation for sensitive admin actions like refunds, cancellations, deletes, and webhook changes.

Review before installing. Use a least-privilege or read-only RevenueCat API key where possible, and avoid giving this skill credentials that can refund purchases, cancel subscriptions, delete resources, or modify integrations unless you explicitly want those admin capabilities and have a separate confirmation process.

Vulnerability Patterns
  • Skill Instruction HijackingAlters the agent's session goals or safety constraints when the skill loads
  • Agent Memory PoisoningWrites attacker-controlled rules into memory that affect later sessions
  • Remote Payload Retrieval and ExecutionFetches external code whose behavior can change after review
  • Embedded Malicious CodeShips malicious scripts inside the skill and executes them locally
  • Unauthorized Access and Privilege EscalationObtains permissions beyond the task's legitimate needs
Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep
  • Tool MisuseTool Parameter Abuse, Chaining Abuse, Unsafe Defaults
  • MCP Least PrivilegeUnderdeclared Capability, Wildcard Permission, Missing Permission Declaration
  • MCP Tool PoisoningHidden Instructions, Unicode Deception, Parameter Description Injection
Findings (78)

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is described as query/search-oriented for metrics, customer data, and documentation, but this reference exposes extensive state-changing and administrative operations such as create, delete, transfer, entitlement grants, balance modification, and block-list management. In an agent setting, this creates dangerous capability overreach: a user asking to 'look up' customer information could, through prompt confusion or tool misuse, trigger destructive or privilege-sensitive actions not implied by the skill’s stated purpose.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

A raw delete endpoint exposed through agent-readable documentation is susceptible to tool misuse or prompt-driven parameter abuse because a single attacker-influenced customer_id can trigger irreversible destructive action. The surrounding skill context increases the risk because the skill is framed as a customer-data/query tool, not an admin-deletion tool, so operators may underestimate the danger.

Content

Scanner excerpt · references/customers.md (reported line 43)May include surrounding context.

md
- attributes: object — List of the attributes of the customer. This is an expandable property, only available in the "Get a customer" endpoint.
- **Status:** public

### DELETE /projects/{project_id}/customers/{customer_id}

Delete a customer

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
84% confidence
Finding

The block-list removal endpoint can be abused by supplying attacker-chosen customer identifiers to alter access-control state. Because this is an administrative action exposed in general customer references, an agent may execute it without sufficient scrutiny, enabling unauthorized service restoration or policy bypass.

Content

Scanner excerpt · references/customers.md (reported line 307)May include surrounding context.

md
### DELETE /projects/{project_id}/customers/blocked_customers/{customer_id}

Remove a customer from the block list

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
90% confidence
Finding

A publicly documented parameterized DELETE endpoint can be abused if an agent is induced to supply attacker-chosen project_id or entitlement_id values. Because entitlements control access to subscription features, deleting one can have broad operational impact, and the read/search-oriented skill context makes such mutation capability especially unexpected and dangerous.

Content

Scanner excerpt · references/entitlements.md (reported line 38)May include surrounding context.

md
- products: object, nullable — List of products attached to the entitlement
- **Status:** public

### DELETE /projects/{project_id}/entitlements/{entitlement_id}

Delete an entitlement

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is described as supporting RevenueCat metrics, customer data, and documentation search, but this file exposes webhook integration administration endpoints including create, update, and delete operations. That expands the capability from read-oriented analytics/docs access into privileged configuration management, which can let an agent alter outbound data flows or disrupt integrations beyond the user's expected scope.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
95% confidence
Finding

Webhook administration is a sensitive control-plane capability because it allows adding, modifying, or removing destinations that receive RevenueCat event data. In the context of a skill marketed for analytics and docs, this unjustified capability increases the chance that users or downstream agents will invoke dangerous actions without understanding they are performing administrative changes.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
84% confidence
Finding

A public DELETE endpoint exposed through an agent tool can be abused through prompt-driven parameter substitution, causing the agent to remove an arbitrary webhook integration if it has credentials. In this skill context, the danger is elevated because the capability is both destructive and out of scope for an analytics/docs assistant, making accidental or manipulated invocation more plausible.

Content

Scanner excerpt · references/integrations.md (reported line 46)May include surrounding context.

md
- created_at: integer(int64) (required) — The timestamp in ms since epoch when the webhook integration was created (e.g., 1658399423658)
- **Status:** public

### DELETE /projects/{project_id}/integrations/webhooks/{webhook_integration_id}

Delete a webhook integration

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The documented DELETE /projects/{project_id}/offerings/{offering_id} endpoint can remove an offering and its attached packages, making it a high-risk state-changing action if an agent can supply or infer identifiers from user input. This creates a strong tool-parameter-abuse path where prompt injection, misunderstanding, or malicious prompting could trigger irreversible administrative changes.

Content

Scanner excerpt · references/offerings.md (reported line 41)May include surrounding context.

md
- packages: object, nullable
- **Status:** public

### DELETE /projects/{project_id}/offerings/{offering_id}

Delete an offering and its attached packages

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
94% confidence
Finding

The documented DELETE /projects/{project_id}/packages/{package_id} endpoint enables direct deletion of subscription package configuration based on parameters an agent may obtain from conversation context. In this skill context, that is especially dangerous because the declared purpose suggests analytics and docs usage, so users may not anticipate that the agent has destructive configuration powers.

Content

Scanner excerpt · references/offerings.md (reported line 129)May include surrounding context.

md
- products: object, nullable
- **Status:** public

### DELETE /projects/{project_id}/packages/{package_id}

Delete a package

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

The DELETE endpoint accepts attacker- or model-influenced path parameters for project_id and paywall_id, enabling tool parameter abuse if an agent is induced to target the wrong resource. Because this operation is destructive and the skill context is broader than paywall administration, misuse could delete production paywalls and disrupt monetization flows.

Content

Scanner excerpt · references/paywalls.md (reported line 38)May include surrounding context.

md
- url: string (required) — The URL where this list can be accessed. (e.g., "/v2/projects/proj1ab2c3d4/paywalls")
- **Status:** public

### DELETE /projects/{project_id}/paywalls/{paywall_id}

Delete a paywall

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

A delete-product endpoint is documented even though the skill description frames the integration as analytics/customer/docs oriented. Hidden destructive capability is dangerous because an agent may be granted this skill expecting read/search behavior while it can actually remove configuration objects permanently.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
95% confidence
Finding

A public, parameterized delete endpoint is a classic tool-parameter abuse risk because any agent-controlled or user-supplied product_id can target arbitrary products within the project. In this skill context, the danger is elevated because the overall description implies safer read/query behavior, reducing operator suspicion while exposing destructive control.

Content

Scanner excerpt · references/products.md (reported line 51)May include surrounding context.

md
- display_name: string, nullable (required) — The display name of the product (e.g., "Premium Monthly 2023")
- **Status:** public

### DELETE /projects/{project_id}/products/{product_id}

Delete a product

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The documented create_in_store operation can push products to an external store, which goes far beyond analytics or docs lookup. This creates real-world side effects outside the expected skill scope and could publish billing artifacts or alter storefront state if triggered mistakenly or abusively.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
96% confidence
Finding

The documented DELETE /projects/{project_id}/apps/{app_id} endpoint is a direct tool-parameter abuse risk because an attacker or malformed prompt could supply arbitrary project_id and app_id values to delete resources. The danger is amplified by the skill's mismatch between declared read/search purpose and actual destructive capability, making unsafe invocation less expected and easier to overlook.

Content

Scanner excerpt · references/projects.md (reported line 83)May include surrounding context.

md
- paddle: object — Paddle Billing type details
- **Status:** public

### DELETE /projects/{project_id}/apps/{app_id}

Delete an app

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The skill is described as supporting analytics, customer data, and documentation search, but this reference includes write-capable subscription mutation endpoints such as cancellation and refund. That mismatch expands the skill from read-oriented analysis into financially and operationally destructive actions, increasing the risk of confused-deputy abuse or accidental invocation.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

Cancellation and refund capabilities allow direct modification of customer subscriptions and financial state, which is not justified by the stated read-oriented purpose of the skill. In an agent setting, exposing these actions without strong contextual controls can lead to unauthorized refunds, service disruption, and abuse through prompt manipulation or operator error.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The refund endpoint lacks warnings about irreversible or financially sensitive consequences, making it more likely to be invoked accidentally or via manipulated prompts. Because refunds directly affect revenue and customer financial records, omission of confirmation requirements materially raises abuse and mistake risk.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The transaction-level refund endpoint enables targeted financial actions against individual App Store or Play Store subscription transactions. This is especially risky because fine-grained refund capability can be abused for fraudulent reimbursements or silent revenue loss while appearing operationally legitimate.

Content

No source excerpt is available for this finding.

Missing User Warnings

High
Category
Not specified by scanner
Confidence
97% confidence
Finding

The transaction refund action is a sensitive financial operation, yet the reference provides no warning about its irreversible or abuse-prone nature. This makes agent misuse more plausible, especially in environments where documentation is used to derive callable capabilities or action plans.

Content

No source excerpt is available for this finding.

Description-Behavior Mismatch

High
Category
Not specified by scanner
Confidence
98% confidence
Finding

The skill is described as supporting RevenueCat metrics, customer data, and documentation search, but this file documents administrative virtual-currency CRUD endpoints, including create, update, and delete operations. That mismatch expands the agent's effective authority beyond user-expected analytics/docs use cases and could enable unauthorized or accidental project configuration changes if these endpoints are exposed through the skill.

Content

No source excerpt is available for this finding.

Context-Inappropriate Capability

High
Category
Not specified by scanner
Confidence
96% confidence
Finding

This section includes creation and deletion of project virtual currencies, which are configuration-changing operations not justified by the skill's stated analytics/customer/docs purpose. In an agent setting, undocumented write authority is dangerous because a user may invoke what appears to be a reporting skill while the underlying tool can mutate billing/game-economy configuration.

Content

No source excerpt is available for this finding.

Tool Parameter Abuse

High
Category
Tool Misuse
Confidence
91% confidence
Finding

The DELETE endpoint takes attacker- or user-controlled path parameters for project and virtual currency code and performs a destructive action. In the context of an agent skill with mismatched declared scope, this creates a tool-parameter abuse risk where prompt injection, misunderstanding, or manipulated inputs could cause deletion of arbitrary virtual currency resources the backing credentials can access.

Content

Scanner excerpt · references/virtual-currencies.md (reported line 40)May include surrounding context.

md
- product_grants: array, nullable — The grants that define how products grant this virtual currency
- **Status:** public

### DELETE /projects/{project_id}/virtual_currencies/{virtual_currency_code}

Delete a virtual currency

Undeclared Tool Scope

Medium
Category
MCP Least Privilege
Confidence
96% confidence
Finding

The skill invokes a shell script (scripts/rc-api.sh) and requires curl, but it does not declare any explicit tool restrictions such as permissions or allowed-tools. In an agent environment, undeclared shell capability broadens what the skill may execute and weakens enforcement boundaries, increasing the chance of command execution beyond the intended API wrapper.

Content

No source excerpt is available for this finding.

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 40)May include surrounding context.

md
Start with `{baseDir}/references/api-v2.md` for auth, pagination, and common patterns. Then load the domain file you need:

| Domain             | File                               | Covers                                                                                                   |
| ------------------ | ---------------------------------- | -------------------------------------------------------------------------------------------------------- |
| Customers          | `references/customers.md`          | CRUD, attributes, aliases, entitlements, subscriptions, purchases, invoices, virtual currencies, actions |
| Subscriptions      | `references/subscriptions.md`      | List, get, transactions, cancel, refund, management URL                                                  |

Whitespace Padding

Medium
Category
Prompt Injection
Confidence
70% confidence
Finding

Large whitespace padding was detected (a block of blank lines or a long run of spaces). This can push injected instructions below or to the right of the visible area so a human reviewer never sees them while the agent still reads them. Manual review of the hidden content is recommended.

Content

Scanner excerpt · SKILL.md (reported line 50)May include surrounding context.

md
| Purchases          | `references/purchases.md`          | List, get, refund, entitlements                                                                          |
| Projects           | `references/projects.md`           | Projects, apps, API keys, StoreKit config                                                                |
| Metrics            | `references/metrics.md`            | Overview metrics, charts, chart options                                                                  |
| Paywalls           | `references/paywalls.md`           | Paywall creation                                                                                         |
| Integrations       | `references/integrations.md`       | Integrations CRUD                                                                                        |
| Virtual Currencies | `references/virtual-currencies.md` | Virtual currencies CRUD                                                                                  |
| Error Handling     | `references/error-handling.md`     | Error handling                                                                                           |

Static analysis

No suspicious patterns detected.