cometchat-features

Pass

Audited by Gen Agent Trust Hub on May 7, 2026

Risk Level: SAFE
Full Analysis
  • [EXTERNAL_DOWNLOADS]: The skill facilitates the installation of the '@cometchat/calls-sdk-javascript' package from the public npm registry. This is a verified vendor-owned package required for the calling features functionality.
  • [COMMAND_EXECUTION]: The skill utilizes the 'npx @cometchat/skills-cli' tool to perform deterministic project updates, feature applications, and state verification. These operations are restricted to the vendor's official integration workflow.
  • [DATA_EXFILTRATION]: The skill searches local project files and configuration ('.cometchat/state.json') to identify active UI components. This allows the agent to provide contextually relevant documentation and prop advice. This local inspection is a core function of the skill and does not involve transmitting sensitive data to external domains.
Audit Metadata
Risk Level
SAFE
Analyzed
May 7, 2026, 06:19 AM