Agent skill

Cometchat Audit

by cometchat in cometchat/cometchat-skills

Review an EXISTING CometChat integration and report what's wrong or risky — security (no client Auth Key, server tokens), correctness (init→login→render order, no raw localization keys, no dead…

MITAuto-check: notesFrontend & Design

Install Cometchat Audit

skills CLI
$ npx skills add cometchat/cometchat-skills --skill cometchat-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cometchat/cometchat-skills cometchat-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cometchat/cometchat-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cometchat-audit .claude/skills/cometchat-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cometchat-audit
GitHub stars
129
Token cost
~1.4k tokens
SKILL.md length
599 words
Files
1
Skills in repo
97
Repo updated
First seen
Licence
MIT

At a glance

Review an EXISTING CometChat integration and report what's wrong or risky — security (no client Auth Key, server tokens), correctness (init→login→render order, no raw localization keys, no dead…

  • Works in 3 steps: Detect — npx @cometchat/skills detect… → Read the integration — the… → Score each check below, gather evidence…
  • Tasks that involve Internationalization
  • SKILL.md covers Use this skill when, How to run the audit, The checklist and The report format, plus 2 more sections
  • Calls npx

What it does

Cometchat Audit is an agent skill from cometchat/cometchat-skills. Review an EXISTING CometChat integration and report what's wrong or risky — security (no client Auth Key, server tokens), correctness (init→login→render order, no raw localization keys, no dead affordances), version drift (versionconflict), production-readiness, accessibility & localization gaps — ranked, with fixes routed to the right skill. Read-only: it reports, it doesn't rewrite unless you ask. Triggers: 'audit my cometchat integration', 'review my chat setup', 'is my cometchat secure / production ready'…

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Any CometChat integration (React v7 · Angular v5 · React Native v5 · iOS v5 · Android v6 · Flutter v6 · headless SDK). Read-only review; fixes route to the…

It sits in Frontend & Design, covering Internationalization and Code quality. It works with CometChat. The repository describes itself as: Add CometChat chat & messaging and voice & video calls to any React, Next.js, React Native, Angular, Android, iOS, or Flutter project through your AI coding agent. Works with… The licence is MIT.

When your agent uses it

  • Tasks that involve Internationalization
  • Tasks that involve Code quality

Example prompts

  • “t rewrite unless you ask. Triggers:”
  • “review my chat setup”
  • “is my cometchat secure / production ready”
  • “/cometchat-audit”

Requirements

  • Node.js
  • Compatibility (from SKILL.md): Any CometChat integration (React v7 · Angular v5 · React Native v5 · iOS v5 · Android v6 · Flutter v6 · headless SDK). Read-only review; fixes route to the family skills.

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Detect — npx @cometchat/skills detect --json: framework, installed UI Kit, version_conflict, existing_cometchat. Resolve from peers.yaml`…
  2. Read the integration — the init/login/lifecycle file, where the surface renders, the env/secret files, the server token endpoint (if any)…
  3. Score each check below, gather evidence (file:line), and write a ranked report — most severe first — with, per finding, the fix and the…

What it can do on your machine

Read from SKILL.md and the folder at commit 911b108. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Any CometChat integration (React v7 · Angular v5 · React Native v5 · iOS v5 · Android v6 · Flutter v6 · headless SDK). Read-only review; fixes route to the family skills.

    From compatibility in the SKILL.md frontmatter.

Context cost

Cometchat Audit loads about 1.4k tokens when it runs. Until then it costs about 151 tokens; SKILL.md has 599 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~151
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:58
    tion** — a dev-only Auth Key in a local `.env` is not the same as one shipped in production; judge by what actually reac

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cometchat/cometchat-skills at commit 911b108, republished under its MIT licence (© cometchat). 599 words, ~1,389 tokens.

Download SKILL.mdSave it as .claude/skills/cometchat-audit/SKILL.md (or your agent's skills folder).
name
cometchat-audit
description
Review an EXISTING CometChat integration and report what's wrong or risky — security (no client Auth Key, server tokens), correctness (init→login→render order, no raw localization keys, no dead affordances), version drift (version_conflict), production-readiness, accessibility & localization gaps — ranked, with fixes routed to the right skill. Read-only: it reports, it doesn't rewrite unless you ask. Triggers: 'audit my cometchat integration', 'review my chat setup', 'is my cometchat secure / production ready', 'check my cometchat code', 'health check', 'what's wrong with my chat'.
compatibility
Any CometChat integration (React v7 · Angular v5 · React Native v5 · iOS v5 · Android v6 · Flutter v6 · headless SDK). Read-only review; fixes route to the family skills.
license
MIT
metadata.author
CometChat
metadata.version
1.0.0
metadata.tags
cometchat audit review health-check security production-readiness diagnostics

Ground truth: the authority for "correct" is RULES.md + the resolved family's skills (cometchat-<family>-core/-production/-troubleshooting) and the offline probe npx @cometchat/skills detect --json. Verify every symbol/prop you flag against the family catalog + docs (via -core/references/docs-map.md); never flag from memory. This is a read-only review — produce the report first; only change code if the user says so (then hand each fix to the owning skill).

Use this skill when

Someone wants an existing CometChat integration checked — before a launch, a security review, an upgrade, or a "why is this flaky / is this safe" question. It is the proactive complement to the per-family troubleshooting skills (cometchat-<family>-troubleshooting, which react to a specific symptom).

How to run the audit

  1. Detect — npx @cometchat/skills detect --json: framework, installed UI Kit, version_conflict, existing_cometchat. Resolve <family> from peers.yaml. If nothing is detected, say so and stop (nothing to audit).
  2. Read the integration — the init/login/lifecycle file, where the surface renders, the env/secret files, the server token endpoint (if any), and any custom message/theme/feature code. Do NOT read node_modules/.d.ts.
  3. Score each check below, gather evidence (file:line), and write a ranked report — most severe first — with, per finding, the fix and the skill that owns it. Then offer to apply fixes; don't auto-edit.

The checklist

Security (highest severity)

  • Auth Key present in client code / bundle / binary? → critical; must move to server-minted tokens (cometchat-security, cometchat-<family>-production).
  • Token endpoint deriving the UID from a client parameter (?uid=)? → impersonation.
  • REST API Key anywhere client-side or in the repo? → critical.
  • Sessions revocable on offboarding (flush tokens)? RBAC roles configured, or everyone on default? (cometchat-security.)

Correctness

  • init() → login() → render order honored; no component rendered before login resolves; no init during SSR; StrictMode/double-invoke guarded.
  • initFromSettings used (ai-agent attribution), not the classic builder init.
  • Surface has real dimensions (not a collapsed 0-height box); host CSS not leaking into .cometchat.
  • No raw localization keys rendered (group_info etc.).
  • No dead affordances — every default-on control wired or hidden.
  • Listeners removed on unmount/dispose (no duplicate messages/leaks).

Version & drift

  • version_conflict from detect (UI Kit major ≠ the family's target)? → route to cometchat-<family>-migration.
  • Kit/SDK versions pinned (not a floating major)? iOS: the exact kit+SDK+Calls pins.

Production-readiness

  • HTTPS everywhere; logout teardown (session + push tokens); dashboard extensions/AI enabled on the PRODUCTION app; error handling in place (React families: an error boundary such as CometChatErrorBoundary; iOS/Android/Flutter: SDK error listeners / kit error-state views). (cometchat-<family>-production.)

Accessibility & localization (enterprise procurement)

  • Focus rings / contrast not stripped by global CSS; chat container labelled; reduced-motion honored (cometchat-a11y).
  • Locale set before render; no raw keys; RTL handled if targeted (cometchat-i18n).

Compliance (if in scope)

  • App in the right data-residency region; a data-deletion path exists (cometchat-compliance); moderation enabled if the product needs T&S (cometchat-moderation).
Show full SKILL.md (161 more words)Show less

The report format

Lead with a one-line verdict (ship / fix-first / not-ready) and counts by severity. Then a table: Severity · Finding · Evidence (file:line) · Fix · Owning skill. List what PASSED too, so the reader knows it was checked. End with the top 3 things to fix first. Do not inflate severity, and do not flag a "problem" you didn't verify against docs/catalog.

Common pitfalls (of the auditor)

  1. Flagging from memory — verify each symbol/prop against the catalog + docs before calling it wrong.
  2. Auto-editing — this is read-only; report, then ask.
  3. Reading node_modules/.d.ts — audit the user's code + docs, not kit internals.
  4. Severity inflation — a dev-only Auth Key in a local .env is not the same as one shipped in production; judge by what actually reaches users.

Verify it works

The report names the framework + family, lists ranked findings each with file:line + a fix + an owning skill, states what passed, and gives a clear verdict — and nothing was edited unless the user approved.

© cometchat, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cometchat-audit of cometchat/cometchat-skills.

Open the folder on GitHubat commit 911b108

Compare with similar skills

Cometchat Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cometchat Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cometchat Audit this skillcometchat/cometchat-skills129—~1.4kAutomated safety check: NotesMIT
Reviewquran/quran.com-frontend-next1.9k—~1.1kAutomated safety check: PassNone
React Doctormakeplane/plane60k12 repos~657Automated safety check: PassAGPL-3.0
Impeccablebestofjs/bestofjs3.1k27 repos~2.6kAutomated safety check: PassMIT
Chatbox i18n Translatorchatboxai/chatbox42k—~508Automated safety check: PassGPL-3.0
Internationalization Workflow with i18niOfficeAI/AionUi33k1 repos~1.9kAutomated safety check: PassApache-2.0

Similar skills

  • Review

    quran/quran.com-frontend-next

    Reviews PR(s) using comprehensive review guidelines including security, correctness, clean code, TypeScript, React patterns, i18n/RTL, performance, and accessibility.

    1.9k GitHub stars~1.1k tokensUpdated 5 mo ago
    DevelopmentAuto-check passed
  • React Doctor

    makeplane/plane

    Scans React code for lint, accessibility, bundle size and architecture issues, reports a health score and checks that changes do not lower it.

    60k GitHub starsUsed in 12 repos~657 tokens
    Frontend & DesignAuto-check passed
  • Impeccable

    bestofjs/bestofjs

    A skill your agent uses when the user wants to design, redesign, shape, critique, audit, polish, clarify, distill, harden, optimize, adapt, animate, colorize, extract, or otherwise improve a…

    3.1k GitHub starsUsed in 27 repos~2.6k tokens
    Frontend & DesignAuto-check passed
  • Chatbox i18n Translator

    chatboxai/chatbox

    Translates new or changed i18n keys from a Chatbox Pro diff, staged changes or a commit range, writing the locale JSON files directly with a built-in glossary.

    42k GitHub stars~508 tokensUpdated 13 days ago
    Frontend & DesignAuto-check passed
  • Standards for keeping all user-facing text translatable: read the i18n config first, use namespaced keys, reuse shared strings and follow the key naming rules.

    33k GitHub starsUsed in 1 repo~1.9k tokens
    Frontend & DesignAuto-check passed
  • Review pending AIRI translations on Crowdin in a batch, then sync them into the repository.

    50k GitHub stars~1.5k tokensUpdated today
    Frontend & DesignAuto-check passed

More from cometchat/cometchat-skills

All 97 skills in this repo
  • CometChat Android Calls SDK v5

    cometchat/cometchat-skills

    Adds voice and video calling to an Android app in Kotlin with the headless CometChat Calls SDK v5, covering meeting-style rooms, 1:1 ringing calls, call logs and recording.

    129 GitHub stars~5.2k tokensUpdated 2 days ago
    Auto-check passed
  • CometChat Android v5 Headless SDK

    cometchat/cometchat-skills

    Builds chat on Android with your own UI against the headless CometChat Chat SDK v5, covering install, Jetifier conflicts, credentials and init-before-login ordering.

    129 GitHub stars~4k tokensUpdated 2 days ago
    Auto-check passed
  • CometChat Angular Component Picker

    cometchat/cometchat-skills

    Picks and customizes CometChat's Angular UI Kit components by their verified component list, exact input and output event names, and the surfaces that have no kit component at all.

    129 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed
  • CometChat Angular Features

    cometchat/cometchat-skills

    Enables or builds CometChat features such as polls, reactions, smart replies and pinned messages in an Angular app, first classifying how much client code each one needs.

    129 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed
  • CometChat Angular Chat Placement

    cometchat/cometchat-skills

    Decides where CometChat chat UI goes in an Angular app: a dedicated route, a dashboard panel, a support widget or the full multi-pane app, with thread and search panels.

    129 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed
  • Cometchat iOS V5 SDK

    cometchat/cometchat-skills

    Add voice & video calling to any iOS app FROM SCRATCH with the headless CometChat Calls SDK v5 (CometChatCallsSDK, via Swift Package Manager) — no UI Kit.

    129 GitHub stars~5.2k tokensUpdated 2 days ago
    Auto-check passed

Works with

Questions about Cometchat Audit

What does Cometchat Audit do?

Review an EXISTING CometChat integration and report what's wrong or risky — security (no client Auth Key, server tokens), correctness (init→login→render order, no raw localization keys, no dead…. Cometchat Audit is an agent skill from cometchat/cometchat-skills. Review an EXISTING CometChat integration and report what's wrong or risky — security (no client Auth Key, server tokens), correctness (init→login→render order, no raw localization keys, no dead affordances), version drift (versionconflict), production-readiness, accessibility & localization gaps — ranked, with fixes routed to the right skill.

When should I use Cometchat Audit?

Cometchat Audit fits situations like: tasks that involve Internationalization; tasks that involve Code quality.

How do I install Cometchat Audit in Claude Code?

Run `npx skills add cometchat/cometchat-skills --skill cometchat-audit -a claude-code`. Or copy the skill folder (skills/cometchat-audit in cometchat/cometchat-skills) into .claude/skills/cometchat-audit in your project. Claude Code loads it when a task matches its description.

How do I install Cometchat Audit in Codex?

Run `npx skills add cometchat/cometchat-skills --skill cometchat-audit -a codex`. Or copy the skill folder (skills/cometchat-audit in cometchat/cometchat-skills) into .agents/skills/cometchat-audit in your project. Codex loads it when a task matches its description.

Can I use Cometchat Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cometchat/cometchat-skills --skill cometchat-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cometchat-audit, .gemini/skills/cometchat-audit, .github/skills/cometchat-audit and .opencode/skills/cometchat-audit in your project.

What does Cometchat Audit need to run?

Going by SKILL.md and its folder, Cometchat Audit needs the command-line tools its instructions call (npx). Our summary lists: Node.js. Compatibility (from SKILL.md): Any CometChat integration (React v7 · Angular v5 · React Native v5 · iOS v5 · Android v6 · Flutter v6 · headless SDK). Read-only review; fixes route to the family skills..

Does Cometchat Audit access the network?

SKILL.md contains no URLs. Its commands use npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Cometchat Audit safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Cometchat Audit use?

Cometchat Audit is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cometchat Audit use?

About 1.4k tokens (SKILL.md is roughly 5.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cometchat Audit?

Skills that share tags, products or a category with Cometchat Audit: Review (quran/quran.com-frontend-next, 1.9k stars), React Doctor (makeplane/plane, 60k stars), Impeccable (bestofjs/bestofjs, 3.1k stars) and Chatbox i18n Translator (chatboxai/chatbox, 42k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cometchat Audit?

cometchat (a GitHub organization) maintains it in cometchat/cometchat-skills, which has 129 GitHub stars. The repository holds 97 skills in this directory. The repository was last updated on October 5, 2026.

Source: cometchat/cometchat-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.