Agent skill

Cometchat Compliance

by cometchat in cometchat/cometchat-skills

Data governance & compliance for CometChat — pick the data-residency region, satisfy GDPR/CCPA (right-to-erasure and data export), plan message retention & purge, and produce audit / eDiscovery…

MITAuto-check passedLegal & Compliance

Install Cometchat Compliance

skills CLI
$ npx skills add cometchat/cometchat-skills --skill cometchat-compliance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cometchat/cometchat-skills cometchat-compliance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cometchat/cometchat-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cometchat-compliance .claude/skills/cometchat-compliance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cometchat-compliance
GitHub stars
130
Token cost
~1.7k tokens
SKILL.md length
756 words
Files
1
Skills in repo
97
Repo updated
First seen
Licence
MIT

At a glance

Data governance & compliance for CometChat — pick the data-residency region, satisfy GDPR/CCPA (right-to-erasure and data export), plan message retention & purge, and produce audit / eDiscovery…

  • Works in 6 steps: Data residency — choose the region up… → Right to erasure (GDPR Art. 17 / CCPA… → Right of access / portability (data… → …
  • Tasks that involve Privacy and GDPR
  • SKILL.md covers Use this skill when, 1. Data residency — choose the…, 2. Right to erasure (GDPR Art.… and 3. Right of access /…, plus 5 more sections
  • Reaches cometchat.com; needs REST_API_KEY

What it does

Cometchat Compliance is an agent skill from cometchat/cometchat-skills. Data governance & compliance for CometChat — pick the data-residency region, satisfy GDPR/CCPA (right-to-erasure and data export), plan message retention & purge, and produce audit / eDiscovery records. Cross-family: all server/REST/dashboard-side. Triggers: 'is cometchat GDPR compliant', 'delete a user and their data', 'right to be forgotten', 'export a user's data', 'data residency EU', 'which region', 'message retention policy', 'audit log', 'eDiscovery', 'HIPAA/SOC2 chat', 'compliance review'.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: CometChat REST API v3 (users · messages · conversations) + dashboard (regions, moderation records). Server-side over HTTPS.

It sits in Legal & Compliance, covering Privacy and GDPR, SOC 2 and security compliance and Healthcare and finance regulation. It works with CometChat. The repository describes itself as: Add CometChat chat & messaging and voice & video calls to any React, Next.js, React Native, Angular, Android, iOS, or Flutter project through your AI coding agent. Works with… The licence is MIT.

When your agent uses it

  • Tasks that involve Privacy and GDPR
  • Tasks that involve SOC 2 and security compliance
  • Tasks that involve Healthcare and finance regulation

Example prompts

  • “is cometchat GDPR compliant”
  • “delete a user and their data”
  • “right to be forgotten”
  • “/cometchat-compliance”

Requirements

  • A credential in REST_API_KEY
  • Compatibility (from SKILL.md): CometChat REST API v3 (users · messages · conversations) + dashboard (regions, moderation records). Server-side over HTTPS.

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Data residency — choose the region up front
  2. Right to erasure (GDPR Art. 17 / CCPA delete)
  3. Right of access / portability (data export)
  4. Retention & purge
  5. Audit & eDiscovery
  6. Certifications & agreements (business, not code)

What it can do on your machine

Read from SKILL.md and the folder at commit 911b108. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are http).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • cometchat.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • REST_API_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    CometChat REST API v3 (users · messages · conversations) + dashboard (regions, moderation records). Server-side over HTTPS.

    From compatibility in the SKILL.md frontmatter.

Context cost

Cometchat Compliance loads about 1.7k tokens when it runs. Until then it costs about 131 tokens; SKILL.md has 756 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~131
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cometchat/cometchat-skills at commit 911b108, republished under its MIT licence (© cometchat). 756 words, ~1,693 tokens.

Download SKILL.mdSave it as .claude/skills/cometchat-compliance/SKILL.md (or your agent's skills folder).
name
cometchat-compliance
description
Data governance & compliance for CometChat — pick the data-residency region, satisfy GDPR/CCPA (right-to-erasure and data export), plan message retention & purge, and produce audit / eDiscovery records. Cross-family: all server/REST/dashboard-side. Triggers: 'is cometchat GDPR compliant', 'delete a user and their data', 'right to be forgotten', 'export a user's data', 'data residency EU', 'which region', 'message retention policy', 'audit log', 'eDiscovery', 'HIPAA/SOC2 chat', 'compliance review'.
compatibility
CometChat REST API v3 (users · messages · conversations) + dashboard (regions, moderation records). Server-side over HTTPS.
license
MIT
metadata.author
CometChat
metadata.version
1.0.0
metadata.tags
cometchat compliance gdpr ccpa hipaa data-residency retention audit ediscovery erasure region

Ground truth: REST shapes are FETCHED from the live docs — {DOCS_BASE}/rest-api/users/delete (erasure), /rest-api/messages, /rest-api/conversations (access/export), /articles/properties-and-constraints (regions, retention behaviour), /moderation/reviewed-messages (audit). DOCS_BASE = https://www.cometchat.com/docs; append .md. Where a control is a dashboard setting or a sales/plan item (a managed retention policy, a signed BAA, certifications), this skill says so plainly rather than inventing an API. Certification status (SOC 2, ISO 27001, HIPAA) is a business fact — confirm current scope at {DOCS_BASE}/the trust page, don't assert it from here.

Use this skill when

A privacy/security/compliance review, a data-subject request (delete/export), choosing where data lives, or planning retention and audit. All actions here are server-side; there is no client code to write.

1. Data residency — choose the region up front

CometChat hosts each app in one region: us, eu, or in ({DOCS_BASE}/rest-api/chat-apis → Data Center Hosting — re-fetch before quoting to a customer; regions can be added). The region is fixed to the app and is part of every API/SDK endpoint (https://{APP_ID}.api-{REGION}.cometchat.io/v3, and the SDK init region). To keep EU data in the EU (GDPR) or meet a residency clause, create the app in that region — you cannot silently move an app's region afterward; migrating regions means a new app + a data migration (cometchat-migrate-from-* machinery / CometChat support). For full data sovereignty (your own infrastructure), see cometchat-self-host.

2. Right to erasure (GDPR Art. 17 / CCPA delete)

Call the REST Delete User endpoint (DELETE https://{APP_ID}.api-{REGION}.cometchat.io/v3/users/{uid}; see the docs at {DOCS_BASE}/rest-api/users) with the REST API Key:

  • Default (no body) → deactivates the user (recoverable; keeps data).
  • { "permanent": true } → permanently deletes the user with all their messages, conversations and associated data. Irreversible.
http
DELETE https://{APP_ID}.api-{REGION}.cometchat.io/v3/users/{uid}
apikey: {REST_API_KEY}
content-type: application/json

{ "permanent": true }

Wire this to your account-deletion flow so a "delete my account" request erases the user in CometChat too. Also flush their auth tokens (cometchat-security) so no session lingers.

3. Right of access / portability (data export)

To answer a data-subject access request, export the user's data server-side via REST and hand it over in a portable format:

  • their messages — the Messages REST collection ({DOCS_BASE}/rest-api/messages, filtered by the user);
  • their conversations — {DOCS_BASE}/rest-api/conversations;
  • their profile — the Users API. Run it with the REST API Key from a server job; never expose these to the client. Fetch the exact filter params from the docs before writing the exporter.

4. Retention & purge

CometChat keeps messages until they are deleted. Behaviour to know (/articles/properties-and-constraints): soft-deleted messages are retained; messages permanently deleted via the API are not. To enforce a retention window:

  • run a scheduled server job that deletes messages/conversations older than your policy via the REST APIs (delete-message / delete-conversation / user permanent-delete);
  • a managed/automatic retention policy (auto-purge at N days) is a dashboard/plan capability — confirm availability and configure it with CometChat rather than assuming an API. Do not invent a retention endpoint.
  • on-prem gives you full control of storage lifecycle and backups (cometchat-self-host).
Show full SKILL.md (298 more words)Show less

5. Audit & eDiscovery

  • Moderation audit trail: the dashboard's Moderation → Reviewed Messages records moderator activity and decisions for compliance ({DOCS_BASE}/moderation/reviewed-messages); pair with cometchat-moderation.
  • eDiscovery / legal hold: export the relevant conversations and messages via the REST collections above (by user, group, or time range) — that is the supported way to produce chat records; there is no separate "eDiscovery API." For a legal hold, export before any retention purge runs.
  • Webhooks ({DOCS_BASE}/rest-api/management-apis/webhooks/overview) can stream message/user events to your own immutable audit store in real time if you need a tamper-evident log outside CometChat.

6. Certifications & agreements (business, not code)

SOC 2, ISO 27001, HIPAA (with a BAA), GDPR/CCPA posture, and pen-test reports are handled through CometChat's trust/compliance process, not the API. Point the reviewer to the current trust page and get agreements in writing; encryption in transit (TLS) is standard, and at-rest/e2e options + key management vary by plan/deployment — confirm the specifics for the customer's plan.

Common pitfalls

  1. Region chosen by accident — the default is us; an EU customer needs the app created in eu from day one.
  2. "Delete" that only deactivates — omitting permanent: true leaves the data; erasure requests need the flag.
  3. Deleting the user but leaving live sessions — also flush auth tokens (cometchat-security).
  4. Assuming an automatic retention policy exists — implement purge via REST/on-prem, or confirm the managed setting; don't invent it.
  5. Asserting a certification from memory — verify current SOC 2 / HIPAA / ISO scope with CometChat.

Verify it works

A test user permanently deleted returns success and their messages/conversations are gone · an access-request export produces the user's profile + messages + conversations · the app's region matches the customer's residency requirement · a retention job (or the confirmed managed policy) removes data past the window · moderation decisions appear in Reviewed Messages · webhooks (if used) land audit events in your store.

© cometchat, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cometchat-compliance of cometchat/cometchat-skills.

Open the folder on GitHubat commit 911b108

Compare with similar skills

Cometchat Compliance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cometchat Compliance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cometchat Compliance this skillcometchat/cometchat-skills130—~1.7kAutomated safety check: PassMIT
Policy OpaAgentSecOps/SecOpsAgentKit2201 repos~3.5kAutomated safety check: PassCustom licence
Implementing Complianceancoleman/ai-design-components526—~4kAutomated safety check: PassMIT
Security Compliance Compliance Checkaiskillstore/marketplace4308 repos~600Automated safety check: PassNone
Compliance Testingproffesor-for-testing/agentic-qe494—~1.8kAutomated safety check: PassMIT
Cursor Compliance Auditjeremylongshore/tons-of-skills-marketplace2.8k—~2.3kAutomated safety check: NotesMIT

Similar skills

  • Policy Opa

    AgentSecOps/SecOpsAgentKit

    Policy-as-code enforcement and compliance validation using Open Policy Agent (OPA).

    220 GitHub starsUsed in 1 repo~3.5k tokens
    Legal & ComplianceAuto-check passed
  • Implementing Compliance

    ancoleman/ai-design-components

    Implement and maintain compliance with SOC 2, HIPAA, PCI-DSS, and GDPR using unified control mapping, policy-as-code enforcement, and automated evidence collection.

    526 GitHub stars~4k tokensUpdated 10 mo ago
    Legal & ComplianceAuto-check passed
  • Security Compliance Compliance Check

    aiskillstore/marketplace

    You are a compliance expert specializing in regulatory requirements for software systems including GDPR, HIPAA, SOC2, PCI-DSS, and other industry standards.

    430 GitHub starsUsed in 8 repos~600 tokens
    Legal & ComplianceAuto-check passed
  • Compliance Testing

    proffesor-for-testing/agentic-qe

    Regulatory compliance testing for GDPR, CCPA, HIPAA, SOC2, PCI-DSS and industry-specific regulations.

    494 GitHub stars~1.8k tokensUpdated 4 days ago
    Legal & ComplianceAuto-check passed
  • Cursor Compliance Audit

    jeremylongshore/tons-of-skills-marketplace

    Compliance and security auditing for Cursor IDE usage: SOC 2, GDPR, HIPAA assessment, evidence collection, and remediation.

    2.8k GitHub stars~2.3k tokensUpdated today
    Legal & ComplianceAuto-check: notes
  • Unified compliance verification across ISO 27001, NIST CSF, CIS Controls, NIS2, EU CRA, GDPR, SOC 2, PCI DSS, and HIPAA for cybersecurity consulting

    239 GitHub stars~994 tokensUpdated yesterday
    Legal & ComplianceAuto-check passed

More from cometchat/cometchat-skills

All 97 skills in this repo
  • CometChat Android Calls SDK v5

    cometchat/cometchat-skills

    Adds voice and video calling to an Android app in Kotlin with the headless CometChat Calls SDK v5, covering meeting-style rooms, 1:1 ringing calls, call logs and recording.

    130 GitHub stars~5.2k tokensUpdated 3 days ago
    Auto-check passed
  • CometChat Android v5 Headless SDK

    cometchat/cometchat-skills

    Builds chat on Android with your own UI against the headless CometChat Chat SDK v5, covering install, Jetifier conflicts, credentials and init-before-login ordering.

    130 GitHub stars~4k tokensUpdated 3 days ago
    Auto-check passed
  • CometChat Angular Component Picker

    cometchat/cometchat-skills

    Picks and customizes CometChat's Angular UI Kit components by their verified component list, exact input and output event names, and the surfaces that have no kit component at all.

    130 GitHub stars~2.6k tokensUpdated 3 days ago
    Auto-check passed
  • CometChat Angular Features

    cometchat/cometchat-skills

    Enables or builds CometChat features such as polls, reactions, smart replies and pinned messages in an Angular app, first classifying how much client code each one needs.

    130 GitHub stars~2.6k tokensUpdated 3 days ago
    Auto-check passed
  • CometChat Angular Chat Placement

    cometchat/cometchat-skills

    Decides where CometChat chat UI goes in an Angular app: a dedicated route, a dashboard panel, a support widget or the full multi-pane app, with thread and search panels.

    130 GitHub stars~2.2k tokensUpdated 3 days ago
    Auto-check passed
  • Cometchat iOS V5 SDK

    cometchat/cometchat-skills

    Add voice & video calling to any iOS app FROM SCRATCH with the headless CometChat Calls SDK v5 (CometChatCallsSDK, via Swift Package Manager) — no UI Kit.

    130 GitHub stars~5.2k tokensUpdated 3 days ago
    Auto-check passed

Works with

Questions about Cometchat Compliance

What does Cometchat Compliance do?

Data governance & compliance for CometChat — pick the data-residency region, satisfy GDPR/CCPA (right-to-erasure and data export), plan message retention & purge, and produce audit / eDiscovery…. Cometchat Compliance is an agent skill from cometchat/cometchat-skills. Data governance & compliance for CometChat — pick the data-residency region, satisfy GDPR/CCPA (right-to-erasure and data export), plan message retention & purge, and produce audit / eDiscovery records.

When should I use Cometchat Compliance?

Cometchat Compliance fits situations like: tasks that involve Privacy and GDPR; tasks that involve SOC 2 and security compliance; tasks that involve Healthcare and finance regulation.

How do I install Cometchat Compliance in Claude Code?

Run `npx skills add cometchat/cometchat-skills --skill cometchat-compliance -a claude-code`. Or copy the skill folder (skills/cometchat-compliance in cometchat/cometchat-skills) into .claude/skills/cometchat-compliance in your project. Claude Code loads it when a task matches its description.

How do I install Cometchat Compliance in Codex?

Run `npx skills add cometchat/cometchat-skills --skill cometchat-compliance -a codex`. Or copy the skill folder (skills/cometchat-compliance in cometchat/cometchat-skills) into .agents/skills/cometchat-compliance in your project. Codex loads it when a task matches its description.

Can I use Cometchat Compliance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cometchat/cometchat-skills --skill cometchat-compliance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cometchat-compliance, .gemini/skills/cometchat-compliance, .github/skills/cometchat-compliance and .opencode/skills/cometchat-compliance in your project.

What does Cometchat Compliance need to run?

Going by SKILL.md and its folder, Cometchat Compliance needs credentials named REST_API_KEY. Our summary lists: A credential in REST_API_KEY. Compatibility (from SKILL.md): CometChat REST API v3 (users · messages · conversations) + dashboard (regions, moderation records). Server-side over HTTPS..

Does Cometchat Compliance access the network?

SKILL.md names 1 domain. In commands or code: cometchat.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Cometchat Compliance safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cometchat Compliance use?

Cometchat Compliance is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cometchat Compliance use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cometchat Compliance?

Skills that share tags, products or a category with Cometchat Compliance: Policy Opa (AgentSecOps/SecOpsAgentKit, 220 stars), Implementing Compliance (ancoleman/ai-design-components, 526 stars), Security Compliance Compliance Check (aiskillstore/marketplace, 430 stars) and Compliance Testing (proffesor-for-testing/agentic-qe, 494 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cometchat Compliance?

cometchat (a GitHub organization) maintains it in cometchat/cometchat-skills, which has 130 GitHub stars. The repository holds 97 skills in this directory. The repository was last updated on October 5, 2026.

Source: cometchat/cometchat-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.