cometchat-react-react-router

Warn

Audited by Socket on Apr 15, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS: The skill’s purpose is coherent for CometChat integration, and most data flows stay within CometChat-owned domains. The main issue is trust: it relies on repeated execution of an unpinned remote CLI via `npx @latest`, plus transitive skill installation/use and some external content fetching. This is not confirmed malware, but it carries meaningful supply-chain and agent-action risk.

Confidence: 82%Severity: 72%
Audit Metadata
Analyzed At
Apr 15, 2026, 05:59 PM
Package URL
pkg:socket/skills-sh/cometchat%2Fcometchat-skills%2Fcometchat-react-react-router%2F@bf78afab8fc954f01456baa103694c780ea5a4d4