CtrlK
BlogDocsLog inGet started
Tessl Logo

rc-security

Use this skill when hardening a RevenueCat integration on Android. Covers Trusted Entitlements response verification (INFORMATIONAL vs ENFORCED), why the server is always the authority, API key hygiene (public SDK key vs secret REST key), anonymous user identity, and purchase token protections RevenueCat provides automatically.

66

Quality

81%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide

SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

75%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured, actionable hardening runbook with executable code, clear phased sequencing, and a verification checklist. The main gaps are a missing webhook-flag code example, no literal grep command, and no explicit fix-retry loop.

Suggestions

Add a concrete code snippet for the webhook-driven local has_entitlement flag alternative described in Decision B and 3.4.

Provide a literal grep command (e.g. `grep -rE 'sk_...|secret' app/src/`) for the secret-key release check.

Add an explicit feedback loop in Phase 4 (if a checklist item fails, fix and re-verify before considering the hardening complete).

DimensionReasoningScore

Conciseness

Mostly lean with dense tables and tight code, but the Plan/Execute/Verify/Common-mistakes sections restate the same points (e.g. anonymous-id handling, secret-key placement), which is trimmable reinforcement.

4 / 5

Actionability

Copy-paste-ready Kotlin and Python examples cover the common cases, but the webhook-driven flag alternative has no code example and the secret-key grep is described as an instruction rather than a literal command.

4 / 5

Workflow Clarity

Clear Phase 0 to Phase 4 sequence with a Verify checklist and a telemetry-gated upgrade from INFORMATIONAL to ENFORCED, but there is no explicit fix-and-retry feedback loop when verification or grep checks fail.

4 / 5

Progressive Disclosure

Single self-contained file with well-organized phase sections and one clearly signaled one-level external reference; no bundle files exist, so structure is appropriate, though the chapter reference could be more prominently surfaced.

4 / 5

Total

16

/

20

Passed

Description

87%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, specific description with an explicit Use-when trigger and comprehensive coverage of the chapter's security concerns. It could be sharpened by leading with verb-led actions and adding a few common synonyms.

Suggestions

Reframe the 'Covers...' list as verb-led actions (e.g. 'Verify Trusted Entitlements responses, enforce API key hygiene, identify real users') to lift specificity.

Add natural synonyms such as 'in-app purchase security' or 'subscription entitlement verification' to broaden trigger-term coverage.

DimensionReasoningScore

Specificity

Lists several concrete, domain-specific capabilities (Trusted Entitlements verification with INFORMATIONAL/ENFORCED, API key hygiene, anonymous user identity, purchase token protections), but frames them as 'Covers...' topics rather than verb-led actions and one item is an automatic protection rather than a skill action, leaving minor gaps.

4 / 5

Completeness

Explicitly answers both what the skill does (hardening plus the enumerated concerns) and when to use it ('Use this skill when hardening a RevenueCat integration on Android') with concrete trigger phrases.

5 / 5

Trigger Term Quality

Natural trigger phrasing ('Use this skill when hardening a RevenueCat integration on Android') plus strong domain keywords (RevenueCat, Android, Trusted Entitlements, API key, ENFORCED/INFORMATIONAL), but a few common synonyms like 'in-app purchase security' or 'subscription security' are absent.

4 / 5

Distinctiveness Conflict Risk

Targets a very specific niche (RevenueCat Android security hardening) with distinct triggers, so overlap with other skills is minimal.

5 / 5

Total

18

/

20

Passed

Validation

87%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 14 / 16 Passed

Validation for skill structure

CriteriaDescriptionResult

metadata_version

'metadata.version' is missing

Warning

metadata_field

'metadata' should map string keys to string values

Warning

Total

14

/

16

Passed

Repository
RevenueCat/ai-toolkit
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.