cometchat-react-core

Pass

Audited by Gen Agent Trust Hub on Apr 3, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill references the installation of official CometChat library packages from the public NPM registry.
  • Evidence: Recommendations to install @cometchat/chat-uikit-react and @cometchat/calls-sdk-javascript.
  • [DATA_EXFILTRATION]: The skill instructs the agent to discover project configuration by reading local .env files and searching source code for previous initialization parameters.
  • Evidence: The INFER_BEFORE_ASK section specifically directs the agent to check environment files (.env, .env.local, .env.development) for APP_ID, REGION, and AUTH_KEY to automate the integration process. This behavior is associated with the primary purpose of the skill and includes clear warnings about secure credential handling.
Audit Metadata
Risk Level
SAFE
Analyzed
Apr 3, 2026, 10:12 AM