chatkit-botbuilder
Warn
Audited by Socket on Aug 24, 2026
1 alert found:
SecuritySecurityskill-report.json
MEDIUMSecurityMEDIUM
skill-report.json
No clear evidence of intentional malware/sabotage behavior is present in the provided fragment; it is mostly documentation/snippet guidance. However, there is a high-severity, actionable security misguidance: recommending an OpenAI API key via a Next.js NEXT_PUBLIC variable (which would be bundled to the browser and effectively leaked). Additional medium risks include browser storage of bearer/JWT tokens and potential authorization boundary weaknesses if user_id enforcement/wrapper injection is implemented inconsistently.
Confidence: 72%Severity: 78%
Audit Metadata