cometchat-audit
SkillSecurityLets your agent review an existing CometChat chat integration and report security, correctness, and readiness issues.
Available today. Use it from your connected AI after setup.
No other account needed.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the cometchat-audit skill
About this skill
Review an EXISTING CometChat integration and report what's wrong or risky, security (no client Auth Key, server tokens), correctness (init→login→render order, no raw localization keys, no dead affordances), version drift (version_conflict), production-readiness, accessibility & localization gaps,
What this skill tells your AI
The instructions your AI receives, as published by cometchat/cometchat-skills in skills/cometchat-audit/SKILL.md and read by ahel’s review.
Ground truth: the authority for "correct" is
RULES.md+ the resolved family's skills (cometchat-<family>-core/-production/-troubleshooting) and the offline probenpx @cometchat/skills detect --json. Verify every symbol/prop you flag against the family catalog + docs (via-core/references/docs-map.md); never flag from memory. This is a read-only review — produce the report first; only change code if the user says so (then hand each fix to the owning skill).
Use this skill when
Someone wants an existing CometChat integration checked — before a launch, a security review, an upgrade, or a "why is this flaky / is this safe" question. It is the proactive complement to the per-family troubleshooting skills (cometchat-<family>-troubleshooting, which react to a specific symptom).
How to run the audit
- Detect —
npx @cometchat/skills detect --json: framework, installed UI Kit,version_conflict,existing_cometchat. Resolve<family>frompeers.yaml. If nothing is detected, say so and stop (nothing to audit). - Read the integration — the init/login/lifecycle file, where the surface renders, the env/secret files, the server token endpoint (if any), and any custom message/theme/feature code. Do NOT read
node_modules/.d.ts. - Score each check below, gather evidence (
file:line), and write a ranked report — most severe first — with, per finding, the fix and the skill that owns it. Then offer to apply fixes; don't auto-edit.
The checklist
Security (highest severity)
- Auth Key present in client code / bundle / binary? → critical; must move to server-minted tokens (
cometchat-security,cometchat-<family>-production). - Token endpoint deriving the UID from a client parameter (
?uid=)? → impersonation. - REST API Key anywhere client-side or in the repo? → critical.
- Sessions revocable on offboarding (flush tokens)? RBAC roles configured, or everyone on
default? (cometchat-security.)
Correctness
init() → login() → renderorder honored; no component rendered before login resolves; no init during SSR; StrictMode/double-invoke guarded.initFromSettingsused (ai-agent attribution), not the classic builder init.- Surface has real dimensions (not a collapsed 0-height box); host CSS not leaking into
.cometchat. - No raw localization keys rendered (
group_infoetc.). - No dead affordances — every default-on control wired or hidden.
- Listeners removed on unmount/dispose (no duplicate messages/leaks).
Version & drift
version_conflictfrom detect (UI Kit major ≠ the family's target)? → route tocometchat-<family>-migration.- Kit/SDK versions pinned (not a floating major)? iOS: the exact kit+SDK+Calls pins.
Production-readiness
- HTTPS everywhere; logout teardown (session + push tokens); dashboard extensions/AI enabled on the PRODUCTION app; error handling in place (React families: an error boundary such as
CometChatErrorBoundary; iOS/Android/Flutter: SDK error listeners / kit error-state views). (cometchat-<family>-production.)
Accessibility & localization (enterprise procurement)
- Focus rings / contrast not stripped by global CSS; chat container labelled; reduced-motion honored (
cometchat-a11y). - Locale set before render; no raw keys; RTL handled if targeted (
cometchat-i18n).
Compliance (if in scope)
- App in the right data-residency region; a data-deletion path exists (
cometchat-compliance); moderation enabled if the product needs T&S (cometchat-moderation).
The report format
Lead with a one-line verdict (ship / fix-first / not-ready) and counts by severity. Then a table: Severity · Finding · Evidence (file:line) · Fix · Owning skill. List what PASSED too, so the reader knows it was checked. End with the top 3 things to fix first. Do not inflate severity, and do not flag a "problem" you didn't verify against docs/catalog.
Common pitfalls (of the auditor)
- Flagging from memory — verify each symbol/prop against the catalog + docs before calling it wrong.
- Auto-editing — this is read-only; report, then ask.
- Reading
node_modules/.d.ts— audit the user's code + docs, not kit internals. - Severity inflation — a dev-only Auth Key in a local
.envis not the same as one shipped in production; judge by what actually reaches users.
Verify it works
The report names the framework + family, lists ranked findings each with file:line + a fix + an owning skill, states what passed, and gives a clear verdict — and nothing was edited unless the user approved.
Signals
- GitHub stars
- 120
- Forks
- 2
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
cometchat-audit- Source
- github.com/cometchat/cometchat-skills