Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/RevenueCat/ai-toolkitWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/revenuecat/ai-toolkit/revenuecat-play-billing)<a href="https://agentmods.dev/plugins/revenuecat/ai-toolkit/revenuecat-play-billing"><img src="https://agentmods.dev/badge/plugins/revenuecat/ai-toolkit/revenuecat-play-billing/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/plugins/revenuecat/ai-toolkit/revenuecat-play-billing"><img src="https://agentmods.dev/badge/plugins/revenuecat/ai-toolkit/revenuecat-play-billing.svg" alt="Reviewed on agentmods" width="80" height="20"></a>Grade A, and why
revenuecat-play-billing scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "revenuecat-play-billing",
"description": "Deep Google Play subscription lifecycle skills for the RevenueCat Android SDK — purchases, plan and price changes, payment recovery, webhooks, security. From the RevenueCat Android SDK handbook.",
"version": "1.0.0",
"license": "Apache-2.0",
"keywords": ["revenuecat", "android", "google-play", "play-billing", "subscriptions", "iap"],
"author": {
"name": "RevenueCat",
"url": "https://www.revenuecat.com",
"email": "[email protected]"
},
"homepage": "https://www.revenuecat.com/guides/revenuecat-android-sdk",
"repository": "https://github.com/RevenueCat/ai-toolkit"
}
What it installs
The manifest is a name and a version. 20 skills travel with it, and installing the plugin installs all of them — 1,097 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill rc-revenuecat-api-quick-reference A 53 tokens
- Skill rc-subscriptions A 51 tokens
- Skill rc-testing A 69 tokens
- Skill rc-webhooks A 57 tokens
- Skill rc-backend A 63 tokens
- Skill rc-cancellations-pauses-winback A 62 tokens
- Skill rc-catalog-management A 61 tokens
- Skill rc-configuring-the-sdk A 54 tokens
- Skill rc-error-handling A 48 tokens
- Skill rc-plan-changes A 48 tokens
- Skill rc-purchase-flow A 51 tokens
- Skill rc-revenuecat-vs-raw-billing A 52 tokens
- Skill rc-security A 64 tokens
- Skill rc-setup A 50 tokens
- Skill rc-subscription-states A 57 tokens
- Skill rc-understanding-revenuecat A 65 tokens
- Skill rc-alternative-billing A 50 tokens
- Skill rc-one-time-products A 43 tokens
- Skill rc-payment-recovery A 53 tokens
- Skill rc-price-changes A 46 tokens
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 10d ago First seen · 15 lines scan A 167ef4de3909
revenuecat-play-billing is a plugin published in the GitHub repository RevenueCat/ai-toolkit (65 stars, last pushed 8d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
goodbarber
GoodBarber no-code app builder: 44 skills plus the GoodBarber MCP server to manage your mobile app's shop, content, community and membership by chat.
goodbarber
Manage a GoodBarber no-code app by conversation: shop, content, push notifications, customers and analytics, through the GoodBarber MCP server (OAuth 2.1, 150 tools).
purchasely
Purchasely SDK integration assistant — guides implementation, reviews code, and debugs issues across iOS, Android, React Native, Flutter, and Cordova.
adapty-skills
Skills that hand your app's subscription surface to your agent: integrate the Adapty SDK on any mobile platform (iOS, Android, Flutter, React Native, Unity, KMP, Capacitor), run Apple Search Ads, audit a Flow Builder flow before you publish, edit a flow's config, and turn a paywall screenshot or an onboarding flow…
ios-app-framework-skills
App experience frameworks: widgets, Live Activities, App Intents, StoreKit, push notifications, maps, media, video, PDF, CarPlay, ads.
ios
MobiAI for iOS — simulator, build, testing, and architecture skills.