Clear documentation, MIT licensing, typed declarations, and reproducible publishing improve adoption and trust. The repository is actively maintained with broad organizational participation, though its workflows grant write access broadly and do not explicitly identify this package.
88%
Total Score
100
100
94
83
100
The repository name does not match the package name and its README does not mention @chat-adapter/x, so the package-to-repository relationship is less transparent even though the organization-backed monorepo context can explain the name mismatch.
Both workflows were analyzed successfully, use no unpinned actions, and contain no reported findings or untrusted checkouts. One release workflow has top-level write permissions, a mild hygiene concern because the scope is broader than necessary, but no untrusted sink is present to amplify it.
| Title | Versions | Severity |
|---|---|---|
AIKIDO-2026-300100 Pre-CVE Found by Aikido Intel before public disclosure or CVE publication. @chat-adapter/x is vulnerable to Authentication Bypass in versions 4.33.0 - 4.36.0. | 4.33.0 - 4.36.0 | High |
| Dependency | Last Release | Score |
|---|---|---|
chat Version 4.41.1 | — | — |
@chat-adapter/shared Version 4.41.1 | — | — |
Connect your repositories to instantly see whether vulnerable or malicious packages exist in your codebase.
Free. No credit card required.

I consent to receiving marketing communications based on Aikido’s Privacy Policy.
SOC 2Compliant
ISO 27001Compliant
ISO 42001Compliant© All Intel data is openly available and commercially licensed.