{"enrichment":{"faq":[{"a":"Axiom Audit IAP systematically scans Swift codebases to uncover in-app purchase vulnerabilities\u2014from unfinished transactions and missing verification checks to incomplete subscription state handling. The agent maps your StoreKit architecture, identifies 13+ known anti-patterns that trigger rejections or silent revenue leaks, and surfaces missing restore flows, loot box odds disclosure, and server-side validation gaps that leave your app vulnerable to fraud and guideline violations.","q":"What does axiom-audit-iap detect in in-app purchase audit swift codebases?"},{"a":"Axiom Audit IAP audits StoreKit transaction handling by examining your transaction listeners, finish() call patterns, and verification logic. It detects unfinished transactions that cause revenue loss, missing server-side validation of receipts, and incomplete entitlement granting flows. The tool flags whether you're properly handling transaction state across StoreKit 1 and StoreKit 2 implementations and identifies gaps in error handling that leave purchases in limbo.","q":"How does axiom-audit-iap audit StoreKit transaction handling for verification and completion issues?"},{"a":"Axiom Audit IAP detects 13+ anti-patterns including missing promoted purchases handlers, incomplete subscription disclosure and terms display, loot box odds non-compliance, family sharing entitlement gaps, and restore purchases flow failures. It identifies subscription grace period tracking issues, refund handling for revoked entitlements, and missing app account token server validation\u2014all common rejection triggers and revenue-loss vectors.","q":"What IAP anti-patterns does axiom-audit-iap detect to prevent app store rejection?"},{"a":"Yes. Axiom Audit IAP maps your entire IAP architecture to identify subscription state coverage gaps. It evaluates whether your centralized manager pattern handles all subscription lifecycle states, grace periods, and billing retry logic. The tool assesses completeness of state tracking across active, expired, and revoked subscriptions, and flags architectural patterns that leave entitlements inconsistent or unverifiable.","q":"Does axiom-audit-iap assess subscription state coverage and IAP architecture completeness?"},{"a":"Axiom Audit IAP examines your server-side receipt validation, app account token handling, and entitlement granting logic. It identifies missing or weak verification checks that expose your backend to fraud, incomplete validation of transaction JWTs in StoreKit 2, and gaps in revoking entitlements when refunds or subscriptions lapse. The tool flags security weaknesses that leave your revenue and user data at risk.","q":"How does axiom-audit-iap evaluate server-side validation and entitlement security?"},{"a":"Axiom Audit IAP is released under the MIT license, allowing free use, modification, and distribution with minimal restrictions.","q":"What license does axiom-audit-iap use?"}],"shadow_tags":["revenue-protection","app-store-compliance","transaction-lifecycle","subscription-state","payment-security","purchase-verification","entitlement-granting","storekit-patterns","fraud-prevention","user-entitlements"],"summary_rewrite":"Axiom Audit IAP systematically scans Swift codebases to uncover in-app purchase vulnerabilities\u2014from unfinished transactions and missing verification checks to incomplete subscription state handling. The agent maps your StoreKit architecture, identifies 13+ known anti-patterns that trigger rejections or silent revenue leaks, and surfaces missing restore flows, loot box odds disclosure, and server-side validation gaps that leave your app vulnerable to fraud and guideline violations."},"files":[{"bytes":19412,"path":"axiom-codex/skills/axiom-audit-iap/SKILL.md","sha256":"8eb022fe1b4321fb1fc9ad357574f3a864199310fd76eddd6adb428385ba1daf","url":"https://skillfed.io/files/CharlesWiltgen/Axiom/axiom-audit-iap/675a39c4/SKILL.md"}],"id":"CharlesWiltgen/Axiom/axiom-audit-iap","links":{"html":"https://skillfed.io/CharlesWiltgen/Axiom/axiom-audit-iap","md":"https://skillfed.io/CharlesWiltgen/Axiom/axiom-audit-iap.md","repo":"https://github.com/CharlesWiltgen/Axiom"},"meta":{"agents_supported":[],"first_seen":"2026-07-28","forks":81,"language":"Go","last_updated":"2026-07-27","license":"MIT","name":"axiom-audit-iap","publisher":"CharlesWiltgen","stars":1095},"relations":{"similar":[{"id":"CharlesWiltgen/Axiom/axiom-implement-iap"},{"id":"dpearson2699/swift-ios-skills/storekit"},{"id":"johnrogers/claude-swift-engineering/storekit"},{"id":"rshankras/claude-code-apple-skills/promoted-iap"},{"id":"rshankras/claude-code-apple-skills/bundles-and-licensing"},{"id":"rshankras/claude-code-apple-skills/subscription-lifecycle"},{"id":"tristanmanchester/agent-skills/expo-revenuecat-superwall-integration"},{"id":"rshankras/claude-code-apple-skills/paywall-generator"},{"id":"pluginagentmarketplace/custom-plugin-game-developer/monetization-systems"},{"id":"rshankras/claude-code-apple-skills/external-purchases"}]},"slug":{"owner":"CharlesWiltgen","repo":"Axiom","skill":"axiom-audit-iap"},"version":"675a39c4"}
