cometchat-ios-features

Warn

Audited by Socket on May 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The skill’s stated purpose matches most of its content, and the CometChat SDK/dependency references are broadly consistent with official product features. However, it asks the agent to run an unverified `cometchat` CLI and pass an OpenAI API key into it, which is disproportionate trust for a documentation-style skill and creates a credential-forwarding risk. Main issue is install/provenance uncertainty, not confirmed malicious behavior.

Confidence: 84%Severity: 82%
Audit Metadata
Analyzed At
May 14, 2026, 05:42 PM
Package URL
pkg:socket/skills-sh/cometchat%2Fcometchat-skills%2Fcometchat-ios-features%2F@3d2e3374e341d67810b4cde74649e1330e7a97b0