cometchat-features

Warn

Audited by Socket on Apr 28, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The feature-enablement purpose mostly matches the described actions, and the calls SDK install appears same-org and normal. However, the skill’s main workflow depends on an unverified `@cometchat/skills-cli` that reads keychain tokens, calls backend APIs, and edits project files; combined with MCP installation instructions, that creates a disproportionate trust and credential-forwarding risk.

Confidence: 83%Severity: 82%
Audit Metadata
Analyzed At
Apr 28, 2026, 02:52 AM
Package URL
pkg:socket/skills-sh/cometchat%2Fcometchat-skills%2Fcometchat-features%2F@dadf11642662801c6bd5ea0670981534792c6b8a