Agent skill

Cometchat Android V6 Production

by cometchat in cometchat/cometchat-skills

Ship a CometChat Android v6 app safely — server-minted auth tokens instead of the dev Auth Key, keeping credentials out of the APK, release-build and R8/ProGuard checks, user provisioning…

MITAuto-check passedMobile

Install Cometchat Android V6 Production

skills CLI
$ npx skills add cometchat/cometchat-skills --skill cometchat-android-v6-production -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cometchat/cometchat-skills cometchat-android-v6-production --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cometchat/cometchat-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cometchat-android-v6-production .claude/skills/cometchat-android-v6-production && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cometchat-android-v6-production
GitHub stars
129
Token cost
~1.7k tokens
SKILL.md length
751 words
Files
1
Skills in repo
97
Repo updated
First seen
Licence
MIT

At a glance

Ship a CometChat Android v6 app safely — server-minted auth tokens instead of the dev Auth Key, keeping credentials out of the APK, release-build and R8/ProGuard checks, user provisioning…

  • Works in 7 steps: Auth: server-minted tokens, never the… → Strip credentials from the release… → Provision users server-side.… → …
  • Tasks that involve App store release
  • SKILL.md covers Companion skills (read first), Use this skill when, Production golden path and Known failure modes → fix, plus 2 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cometchat Android V6 Production is an agent skill from cometchat/cometchat-skills. Ship a CometChat Android v6 app safely — server-minted auth tokens instead of the dev Auth Key, keeping credentials out of the APK, release-build and R8/ProGuard checks, user provisioning server-side, rate limits, and the Play Store publishing prerequisites. Triggers: 'is my cometchat android app production ready', 'auth token instead of auth key android', 'release build cometchat android', 'proguard cometchat', 'publish chat app play store'.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Android minSdk =28; compileSdk =36; Kotlin =2.1; AGP =8.9.1; JVM target 11; com.cometchat:chatuikit-kotlin-android ^6 OR…

It sits in Mobile, covering App store release, Rate limiting and Android development. It works with Android and CometChat. The repository describes itself as: Add CometChat chat & messaging and voice & video calls to any React, Next.js, React Native, Angular, Android, iOS, or Flutter project through your AI coding agent. Works with… The licence is MIT.

When your agent uses it

  • Tasks that involve App store release
  • Tasks that involve Rate limiting
  • Tasks that involve Android development

Example prompts

  • “is my cometchat android app production ready”
  • “auth token instead of auth key android”
  • “release build cometchat android”
  • “/cometchat-android-v6-production”

Requirements

  • Compatibility (from SKILL.md): Android minSdk >=28; compileSdk >=36; Kotlin >=2.1; AGP >=8.9.1; JVM target 11; com.cometchat:chatuikit-kotlin-android ^6 OR com.cometchat:chatuikit-compose-android ^6 (6.0.x, verified 6.0.5); com.cometchat:chat-sdk-android ^5

Workflow steps

7 steps, taken from the first numbered list in SKILL.md.

  1. Auth: server-minted tokens, never the Auth Key. The dev flow (login(uid, …) backed by credentials.authKey in the settings file) is…
  2. Strip credentials from the release artifact. Omit credentials.authKey from app/src/main/assets/cometchat-settings.json in release builds…
  3. Provision users server-side. CometChatUIKit.createUser(...) is for prototypes; production creates users through your backend + the…
  4. Log out cleanly. Unregister the push token BEFORE CometChatUIKit.logout(...) (cometchat-android-v6-push), and clear any cached uid/token…
  5. Release build sanity. Build the release variant (not just debug) and run the app: minified/shrunk builds are where reflection-based…
  6. Rate limits & scale. The Chat SDK has documented limits (message rates, request sizes, listener/connection behavior) — fetch…
  7. Play Store prerequisites. Fetch /sdk/android/v5/publishing-app-on-playstore.md — it covers what the SDK needs for a store submission. Also…

What it can do on your machine

Read from SKILL.md and the folder at commit 911b108. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are kotlin).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Android minSdk >=28; compileSdk >=36; Kotlin >=2.1; AGP >=8.9.1; JVM target 11; com.cometchat:chatuikit-kotlin-android ^6 OR com.cometchat:chatuikit-compose-android ^6 (6.0.x, verified 6.0.5); com.cometchat:chat-sdk-android ^5

    From compatibility in the SKILL.md frontmatter.

Context cost

Cometchat Android V6 Production loads about 1.7k tokens when it runs. Until then it costs about 120 tokens; SKILL.md has 751 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~120
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cometchat/cometchat-skills at commit 911b108, republished under its MIT licence (© cometchat). 751 words, ~1,706 tokens.

Download SKILL.mdSave it as .claude/skills/cometchat-android-v6-production/SKILL.md (or your agent's skills folder).
name
cometchat-android-v6-production
description
Ship a CometChat Android v6 app safely — server-minted auth tokens instead of the dev Auth Key, keeping credentials out of the APK, release-build and R8/ProGuard checks, user provisioning server-side, rate limits, and the Play Store publishing prerequisites. Triggers: 'is my cometchat android app production ready', 'auth token instead of auth key android', 'release build cometchat android', 'proguard cometchat', 'publish chat app play store'.
compatibility
Android minSdk >=28; compileSdk >=36; Kotlin >=2.1; AGP >=8.9.1; JVM target 11; com.cometchat:chatuikit-kotlin-android ^6 OR com.cometchat:chatuikit-compose-android ^6 (6.0.x, verified 6.0.5); com.cometchat:chat-sdk-android ^5
license
MIT
metadata.author
CometChat
metadata.version
1.0.0
metadata.tags
cometchat android production release auth-token security v6 proguard

Ground truth: the installed kit source (CometChatUIKit.loginWithAuthToken) + contracts.android-v6.json (prod-auth-token-guidance) + the live SDK pages /sdk/android/v5/rate-limits and /sdk/android/v5/publishing-app-on-playstore. Fetch specifics from docs; never assert a limit or a ProGuard rule from memory.

Companion skills (read first)

  • cometchat-android-v6-core — install, credentials, initFromSettings → login, lifecycle. Assumed here, never repeated.
  • cometchat-android-v6-builder-settings — the settings file + auth method reference · cometchat-android-v6-testing — pre-release verification · cometchat-android-v6-push (unregister on logout).
  • cometchat-security — the enterprise auth model this client-side hardening plugs into: wiring your IdP / SSO into the token flow (your IdP → your server → mint the CometChat auth token; CometChat is not an IdP), token expiry/refresh + re-login, RBAC roles + group (SBAC) scopes, and Auth Key vs auth token vs REST API Key. Load it for a security review or any SSO question.

Use this skill when

"are we production ready?", "switch from the Auth Key to auth tokens", "prepare the release build", "does CometChat need ProGuard rules?", "what are the rate limits?", "anything to do before Play Store submission?".

Production golden path

  1. Auth: server-minted tokens, never the Auth Key. The dev flow (login(uid, …) backed by credentials.authKey in the settings file) is development only — the Auth Key can create/authenticate any user, so shipping it in an APK is a full compromise (APKs are trivially decompiled). Production: your backend creates the user and mints a per-user auth token via the CometChat REST API, your app fetches it over your own authenticated channel, then:
    kotlin
    CometChatUIKit.loginWithAuthToken(authToken, object : CometChat.CallbackListener<User>() {
        override fun onSuccess(user: User) { /* unlock the chat UI */ }
        override fun onError(e: CometChatException) { /* surface + retry path */ }
    })
    Guard it the same way (getLoggedInUser() != null → skip). Token fetch failure must be a real error state, not a blank screen.
  2. Strip credentials from the release artifact. Omit credentials.authKey from app/src/main/assets/cometchat-settings.json in release builds (or ship a release-flavored assets file); keep the file gitignored. appId/region are not secrets, the Auth Key is. Verify by unzipping the APK/AAB and grepping the merged assets — do this before every release.
  3. Provision users server-side. CometChatUIKit.createUser(...) is for prototypes; production creates users through your backend + the CometChat REST API, in the same request that issues the auth token.
  4. Log out cleanly. Unregister the push token BEFORE CometChatUIKit.logout(...) (cometchat-android-v6-push), and clear any cached uid/token in your own storage — otherwise the next user on a shared device inherits notifications.
  5. Release build sanity. Build the release variant (not just debug) and run the app: minified/shrunk builds are where reflection-based failures appear. The kit ships its own consumer rules, so there is normally nothing to add — but verify by running the release build, and if a ClassNotFoundException/serialization failure appears, capture it and check the current kit docs before hand-writing -keep rules. Don't paste ProGuard rules from memory.
  6. Rate limits & scale. The Chat SDK has documented limits (message rates, request sizes, listener/connection behavior) — fetch /sdk/android/v5/rate-limits.md before building anything that sends in bulk or fans out; paginate with request builders rather than unbounded fetches.
  7. Play Store prerequisites. Fetch /sdk/android/v5/publishing-app-on-playstore.md — it covers what the SDK needs for a store submission. Also budget for: runtime permission rationale (CAMERA/RECORD_AUDIO for calls, POST_NOTIFICATIONS for push), a privacy-policy entry covering chat data, and Data-safety form answers reflecting what CometChat transmits.
Show full SKILL.md (253 more words)Show less

Known failure modes → fix

SymptomCauseFix
Auth works in debug, fails in releaserelease settings file has no authKey but code still uses login(uid)switch the release path to loginWithAuthToken
Auth Key found in the APKcredentials.authKey shippedremove for release; rotate the key in the Dashboard
Crash only in releaseshrinking/obfuscationreproduce on the release variant, read the real stack trace, then consult docs before adding keep rules
Notifications reach the wrong usertoken not unregistered on logoutunregister before logout
Sends throttled / requests rejectedrate limitsbatch + paginate; fetch the limits page
Blank chat after reinstalltoken fetch failed and wasn't surfacedrender an error state + retry

Common pitfalls

Treating the dev Auth Key path as shippable · a settings file committed to git · never building the release variant before submission · creating users from the client in production · hand-written ProGuard rules copied from an old version · unbounded message/user fetches · no error state for token-fetch failure · leaving enableCalling/debug logging on when the product doesn't use calls.

Verify it works

Compile (./gradlew :app:assembleDebug # in YOUR app (npm run verify:fences:android-v6 is a pack-repo gate)). Then, on a release build installed on a device: login uses loginWithAuthToken and succeeds; unzipping the artifact shows no Auth Key; chat, calls (if used) and push all work post-minification; logout unregisters push and a second user's session is clean; an intentionally broken token fetch shows a readable error, not a blank screen. Anything you could not verify (store review, backend token endpoint) — say so explicitly rather than claiming it.

© cometchat, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cometchat-android-v6-production of cometchat/cometchat-skills.

Open the folder on GitHubat commit 911b108

Compare with similar skills

Cometchat Android V6 Production next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cometchat Android V6 Production compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cometchat Android V6 Production this skillcometchat/cometchat-skills129—~1.7kAutomated safety check: PassMIT
Mobile App Builderrevfactory/harness-1001.3k—~1.8kAutomated safety check: PassApache-2.0
Android Readme Screenshot Studiopermissionlesstech/bitchat-android7.7k—~3kAutomated safety check: PassGPL-3.0
Generating Baseline ProfilesrosuH/EasyWatermark1.9k1 repos~5kAutomated safety check: PassApache-2.0
Ipaship Auditatharvnaik1/ipaship-audit108—~1.5kAutomated safety check: NotesMIT
uni-app Native App Packagingfeige996/unibest2.3k—~651Automated safety check: PassMIT

Similar skills

  • Mobile App Builder

    revfactory/harness-100

    Full mobile app development pipeline. An agent skill from revfactory/harness-100.

    1.3k GitHub stars~1.8k tokensUpdated 6 mo ago
    MobileAuto-check passed
  • Android Readme Screenshot Studio

    permissionlesstech/bitchat-android

    Create or refresh polished, high-resolution screenshots of the Bitchat Android app for README and repository showcase use.

    7.7k GitHub stars~3k tokensUpdated yesterday
    MobileAuto-check passed
  • Generating Baseline Profiles

    rosuH/EasyWatermark

    A skill your agent uses to generate and measure Jetpack Compose Baseline Profiles end-to-end with the AGP 8.2+ Baseline Profile Generator module and the Macrobenchmark harness.

    1.9k GitHub starsUsed in 1 repo~5k tokens
    MobileAuto-check passed
  • Ipaship Audit

    atharvnaik1/ipaship-audit

    A skill your agent uses when auditing iOS/Android app submissions for compliance with Apple App Store Review Guidelines or Google Play Developer Policies.

    108 GitHub stars~1.5k tokensUpdated 4 mo ago
    MobileAuto-check: notes
  • A comprehensive skill for uni-app native app offline packaging. Use this skill to package uni-app as native Android/iOS apps, configure native app settings…

    2.3k GitHub stars~651 tokensUpdated 22 days ago
    MobileAuto-check passed
  • Deploy Android

    timusus/Shuttle2

    Deploy the Android app to the Play Store via GitHub Actions.

    229 GitHub stars~1.2k tokensUpdated today
    MobileAuto-check passed

More from cometchat/cometchat-skills

All 97 skills in this repo
  • CometChat Android Calls SDK v5

    cometchat/cometchat-skills

    Adds voice and video calling to an Android app in Kotlin with the headless CometChat Calls SDK v5, covering meeting-style rooms, 1:1 ringing calls, call logs and recording.

    129 GitHub stars~5.2k tokensUpdated 2 days ago
    Auto-check passed
  • CometChat Android v5 Headless SDK

    cometchat/cometchat-skills

    Builds chat on Android with your own UI against the headless CometChat Chat SDK v5, covering install, Jetifier conflicts, credentials and init-before-login ordering.

    129 GitHub stars~4k tokensUpdated 2 days ago
    Auto-check passed
  • CometChat Angular Component Picker

    cometchat/cometchat-skills

    Picks and customizes CometChat's Angular UI Kit components by their verified component list, exact input and output event names, and the surfaces that have no kit component at all.

    129 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed
  • CometChat Angular Features

    cometchat/cometchat-skills

    Enables or builds CometChat features such as polls, reactions, smart replies and pinned messages in an Angular app, first classifying how much client code each one needs.

    129 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed
  • CometChat Angular Chat Placement

    cometchat/cometchat-skills

    Decides where CometChat chat UI goes in an Angular app: a dedicated route, a dashboard panel, a support widget or the full multi-pane app, with thread and search panels.

    129 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed
  • Cometchat iOS V5 SDK

    cometchat/cometchat-skills

    Add voice & video calling to any iOS app FROM SCRATCH with the headless CometChat Calls SDK v5 (CometChatCallsSDK, via Swift Package Manager) — no UI Kit.

    129 GitHub stars~5.2k tokensUpdated 2 days ago
    Auto-check passed

Questions about Cometchat Android V6 Production

What does Cometchat Android V6 Production do?

Ship a CometChat Android v6 app safely — server-minted auth tokens instead of the dev Auth Key, keeping credentials out of the APK, release-build and R8/ProGuard checks, user provisioning…. Cometchat Android V6 Production is an agent skill from cometchat/cometchat-skills. Ship a CometChat Android v6 app safely — server-minted auth tokens instead of the dev Auth Key, keeping credentials out of the APK, release-build and R8/ProGuard checks, user provisioning server-side, rate limits, and the Play Store publishing prerequisites.

When should I use Cometchat Android V6 Production?

Cometchat Android V6 Production fits situations like: tasks that involve App store release; tasks that involve Rate limiting; tasks that involve Android development.

How do I install Cometchat Android V6 Production in Claude Code?

Run `npx skills add cometchat/cometchat-skills --skill cometchat-android-v6-production -a claude-code`. Or copy the skill folder (skills/cometchat-android-v6-production in cometchat/cometchat-skills) into .claude/skills/cometchat-android-v6-production in your project. Claude Code loads it when a task matches its description.

How do I install Cometchat Android V6 Production in Codex?

Run `npx skills add cometchat/cometchat-skills --skill cometchat-android-v6-production -a codex`. Or copy the skill folder (skills/cometchat-android-v6-production in cometchat/cometchat-skills) into .agents/skills/cometchat-android-v6-production in your project. Codex loads it when a task matches its description.

Can I use Cometchat Android V6 Production in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cometchat/cometchat-skills --skill cometchat-android-v6-production -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cometchat-android-v6-production, .gemini/skills/cometchat-android-v6-production, .github/skills/cometchat-android-v6-production and .opencode/skills/cometchat-android-v6-production in your project.

What does Cometchat Android V6 Production need to run?

SKILL.md names no scripts, command-line tools or credentials: Cometchat Android V6 Production is instructions for the agent only. Compatibility (from SKILL.md): Android minSdk >=28; compileSdk >=36; Kotlin >=2.1; AGP >=8.9.1; JVM target 11; com.cometchat:chatuikit-kotlin-android ^6 OR com.cometchat:chatuikit-compose-android ^6 (6.0.x, verified 6.0.5); com.cometchat:chat-sdk-android ^5.

Does Cometchat Android V6 Production access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cometchat Android V6 Production safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cometchat Android V6 Production use?

Cometchat Android V6 Production is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cometchat Android V6 Production use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cometchat Android V6 Production?

Skills that share tags, products or a category with Cometchat Android V6 Production: Mobile App Builder (revfactory/harness-100, 1.3k stars), Android Readme Screenshot Studio (permissionlesstech/bitchat-android, 7.7k stars), Generating Baseline Profiles (rosuH/EasyWatermark, 1.9k stars) and Ipaship Audit (atharvnaik1/ipaship-audit, 108 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cometchat Android V6 Production?

cometchat (a GitHub organization) maintains it in cometchat/cometchat-skills, which has 129 GitHub stars. The repository holds 97 skills in this directory. The repository was last updated on October 5, 2026.

Source: cometchat/cometchat-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.