Agent skill

Cometchat Angular V5 Production

by cometchat in cometchat/cometchat-skills

Ship a CometChat Angular integration safely — server-minted auth tokens instead of the Auth Key, environment file replacement, key hygiene, build config and a pre-launch checklist.

MITAuto-check passedBackend & APIs

Install Cometchat Angular V5 Production

skills CLI
$ npx skills add cometchat/cometchat-skills --skill cometchat-angular-v5-production -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cometchat/cometchat-skills cometchat-angular-v5-production --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cometchat/cometchat-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cometchat-angular-v5-production .claude/skills/cometchat-angular-v5-production && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cometchat-angular-v5-production
GitHub stars
130
Token cost
~1.6k tokens
SKILL.md length
703 words
Files
1
Skills in repo
97
Repo updated
First seen
Licence
MIT

At a glance

Ship a CometChat Angular integration safely — server-minted auth tokens instead of the Auth Key, environment file replacement, key hygiene, build config and a pre-launch checklist.

  • Works in 4 steps: Your app authenticates the user (your… → Your server calls CometChat's REST API… → The server returns the token to the… → …
  • Tasks that involve Product launch strategy
  • SKILL.md covers Companion skills (read first), Use this skill when, The one thing that matters and The production login flow, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cometchat Angular V5 Production is an agent skill from cometchat/cometchat-skills. Ship a CometChat Angular integration safely — server-minted auth tokens instead of the Auth Key, environment file replacement, key hygiene, build config and a pre-launch checklist. Triggers: 'is this production ready', 'auth token instead of auth key angular', 'secure my cometchat setup', 'production build config', 'going live checklist'.

Its SKILL.md is about 1.6k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: @cometchat/chat-uikit-angular ^5 (5.1.0–5.2.0 verified); Angular 17-21

It sits in Backend & APIs, covering Product launch strategy. It works with CometChat and Angular. The repository describes itself as: Add CometChat chat & messaging and voice & video calls to any React, Next.js, React Native, Angular, Android, iOS, or Flutter project through your AI coding agent. Works with… The licence is MIT.

When your agent uses it

  • Tasks that involve Product launch strategy

Example prompts

  • “is this production ready”
  • “auth token instead of auth key angular”
  • “secure my cometchat setup”
  • “/cometchat-angular-v5-production”

Requirements

  • A credential in YOUR_AUTH_KEY
  • Compatibility (from SKILL.md): @cometchat/chat-uikit-angular ^5 (5.1.0–5.2.0 verified); Angular 17-21

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Your app authenticates the user (your own auth — CometChat is not an identity provider).
  2. Your server calls CometChat's REST API with the REST API Key to mint an auth token for that user's UID.
  3. The server returns the token to the browser over an authenticated request.
  4. The app calls loginWithAuthToken(token).

What it can do on your machine

Read from SKILL.md and the folder at commit 911b108. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are typescript and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    @cometchat/chat-uikit-angular ^5 (5.1.0–5.2.0 verified); Angular 17-21

    From compatibility in the SKILL.md frontmatter.

Context cost

Cometchat Angular V5 Production loads about 1.6k tokens when it runs. Until then it costs about 93 tokens; SKILL.md has 703 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~93
When it runs · the whole SKILL.md, loaded when a task matches
~1.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cometchat/cometchat-skills at commit 911b108, republished under its MIT licence (© cometchat). 703 words, ~1,638 tokens.

Download SKILL.mdSave it as .claude/skills/cometchat-angular-v5-production/SKILL.md (or your agent's skills folder).
name
cometchat-angular-v5-production
description
Ship a CometChat Angular integration safely — server-minted auth tokens instead of the Auth Key, environment file replacement, key hygiene, build config and a pre-launch checklist. Triggers: 'is this production ready', 'auth token instead of auth key angular', 'secure my cometchat setup', 'production build config', 'going live checklist'.
compatibility
@cometchat/chat-uikit-angular ^5 (5.1.0–5.2.0 verified); Angular 17-21
license
MIT
metadata.author
CometChat
metadata.version
1.0.0
metadata.tags
cometchat angular production v5 security auth-token hardening deployment

Ground truth: @cometchat/chat-uikit-angular@5 (5.1.0–5.2.0 verified). The auth-token API is FETCHED from {DOCS_BASE}/ui-kit/angular/methods.md and /integration.md (base + paths in cometchat-angular-v5-core/references/docs-map.md). The Angular UI Kit docs have no dedicated production-hardening page — the checklist below is the pack's own guidance, derived from the credential rules in RULES.md §4 and what the kit ships; it is labelled as such rather than presented as documented. Treat that as a tracked DOCS GAP.

Companion skills (read first)

  • cometchat-angular-v5-core — references/setup-credentials.md covers the dev credential flow this replaces.
  • cometchat-security — the enterprise auth model this client-side hardening plugs into: wiring your IdP / SSO into the token flow (your IdP → your server → mint the CometChat auth token; CometChat is not an IdP), token expiry/refresh + re-login, RBAC roles + group (SBAC) scopes, and Auth Key vs auth token vs REST API Key. Load it for a security review or any SSO question.

Use this skill when

Moving off the development setup: going live, a security review, or "is this safe to ship".

The one thing that matters

Never ship the Auth Key in the browser bundle.

The Auth Key can mint a session for any user in your app. Anything in environment.ts is compiled into JavaScript your users download, so an Auth Key there is public. Anyone can read it, log in as any UID, and read every conversation.

DevelopmentProduction
LoginCometChatUIKit.login(uid)CometChatUIKit.loginWithAuthToken(token)
Auth Keyin environment.tsabsent from the bundle
Token sourcen/ayour backend, per authenticated user
REST API Keynever client-sideserver only

The production login flow

  1. Your app authenticates the user (your own auth — CometChat is not an identity provider).
  2. Your server calls CometChat's REST API with the REST API Key to mint an auth token for that user's UID.
  3. The server returns the token to the browser over an authenticated request.
  4. The app calls loginWithAuthToken(token).
ts
import { inject } from '@angular/core';
import { HttpClient } from '@angular/common/http';
import { firstValueFrom } from 'rxjs';
import { CometChatUIKit } from '@cometchat/chat-uikit-angular';

const http = inject(HttpClient);

async function loginForCurrentUser() {
  // your endpoint, protected by your own session
  const { authToken } = await firstValueFrom(
    http.get<{ authToken: string }>('/api/cometchat-token', { withCredentials: true }),
  );
  return CometChatUIKit.loginWithAuthToken(authToken);
}

The endpoint must derive the UID from the server-side session, never from a request parameter. Accepting ?uid= lets any caller impersonate anyone.

Environment files

ts
// src/environments/environment.prod.ts
export const environment = {
  production: true,
  cometchat: { appId: 'APP_ID', region: 'REGION', authKey: '' },   // empty on purpose
};

App ID and Region are not secrets — they identify the app. The Auth Key is the secret, and it is empty here. Confirm fileReplacements is wired in the production configuration, then grep the built bundle for the key to be certain:

bash
ng build --configuration production && grep -r "YOUR_AUTH_KEY" dist/ || echo "clean"

Run that in CI. A misconfigured fileReplacements fails silently and ships the dev file.

Show full SKILL.md (322 more words)Show less

Also before launch

  • Users are created server-side, as part of your signup — not from the browser.
  • Log out properly: await CometChatUIKit.logout(), then clear derived state and unregister push tokens (cometchat-angular-v5-push).
  • HTTPS everywhere — required for calls (getUserMedia) and push.
  • Pin the kit to an exact or ~ range so a minor cannot change component behaviour under you.
  • Set a log level: CometChatUIKit.setLogLevel(...) — quieter in production.
  • Handle errors visibly: every list EXCEPT <cometchat-call-logs> has an (error) output — verified vs 5.1.0, its only outputs are itemClick and callButtonClicked; it takes an onError INPUT callback instead, so (error) there binds a DOM listener that never fires. Conversations / Users / Groups / GroupMembers / MessageList all do have (error); wrap the surface in <cometchat-error-boundary>.
  • Teardown — ngOnDestroy on every subscription and listener; leaks are worse in a long-lived SPA.
  • Region must match the dashboard app, in every configuration you build.

Pre-launch checklist

  • Auth Key absent from the production bundle (grep-verified in CI)
  • loginWithAuthToken in production; UID from the server session
  • REST API Key server-side only
  • fileReplacements verified by building, not by reading config — note the production build FAILS on the default 1 MB budget until you raise it (cometchat-angular-v5-core Install); the grep below never runs otherwise
  • HTTPS, valid certificate
  • Logout clears session, state and push tokens
  • Kit version pinned
  • Error boundary + error outputs handled
  • Dashboard extensions/AI enabled for the production app, not just dev
  • Tested against the production app's credentials

Common pitfalls

  1. Auth Key in the production bundle — the critical one.
  2. Token endpoint trusting a client-supplied UID — impersonation.
  3. fileReplacements assumed rather than verified — dev config ships.
  4. Dashboard configured on the dev app only — features silently missing in production.
  5. No logout teardown — the next user inherits the session or the push token.

Verify it works

Production build contains no Auth Key · login works via token · a tampered UID is rejected by the server · logout fully clears · calls and push work over HTTPS · features enabled on the production app.

© cometchat, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cometchat-angular-v5-production of cometchat/cometchat-skills.

Open the folder on GitHubat commit 911b108

Compare with similar skills

Cometchat Angular V5 Production next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cometchat Angular V5 Production compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cometchat Angular V5 Production this skillcometchat/cometchat-skills130—~1.6kAutomated safety check: PassMIT
SaaS Mvp Launchersickn33/agentic-awesome-skills47k2 repos~1.9kAutomated safety check: NotesMIT
Submit To Agentlaunchdavepoon/buildwithclaude3.6k1 repos~1.3kAutomated safety check: PassMIT
Dr Jskilljdubois/dr-jskill342—~4.6kAutomated safety check: NotesApache-2.0
Sanity Best Practicessanity-io/agent-toolkit188—~1.3kAutomated safety check: PassMIT
Progensivaprasadreddy/sivalabs-agent-skills188—~2.7kAutomated safety check: NotesMIT

Similar skills

  • SaaS Mvp Launcher

    sickn33/agentic-awesome-skills

    A skill your agent uses when planning or building a SaaS MVP from scratch.

    47k GitHub starsUsed in 2 repos~1.9k tokens
    Backend & APIsAuto-check: notes
  • Submit To Agentlaunch

    davepoon/buildwithclaude

    Submit an AI agent to agentlaunch (a Product Hunt-style directory for AI agents) and read the directory via a public, no-auth REST API.

    3.6k GitHub starsUsed in 1 repo~1.3k tokens
    Backend & APIsAuto-check passed
  • Dr Jskill

    jdubois/dr-jskill

    Creates Java + Spring Boot projects: Web applications, full-stack apps with Vue.js or Angular or React or vanilla JS, PostgreSQL, REST APIs, and Docker.

    342 GitHub stars~4.6k tokensUpdated 8 days ago
    Backend & APIsAuto-check: notes
  • Sanity Best Practices

    sanity-io/agent-toolkit

    Official

    Sanity development best practices for schema design, GROQ queries, TypeGen, Visual Editing, images, Portable Text, Studio structure, localization, migrations, Sanity Functions, webhooks, Blueprints…

    188 GitHub stars~1.3k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Progen

    sivaprasadreddy/sivalabs-agent-skills

    A skill your agent uses when the user wants to create/generate/scaffold a new Spring Boot project (Maven or Gradle, REST API / Web App / Spring Boot + Angular full stack).

    188 GitHub stars~2.7k tokensUpdated 3 days ago
    Backend & APIsAuto-check: notes
  • Lunora Realtime

    anolilab/lunora

    Wires Lunora's live data into a client app. An agent skill from anolilab/lunora.

    283 GitHub stars~2.7k tokensUpdated today
    MobileAuto-check passed

More from cometchat/cometchat-skills

All 97 skills in this repo
  • CometChat Android Calls SDK v5

    cometchat/cometchat-skills

    Adds voice and video calling to an Android app in Kotlin with the headless CometChat Calls SDK v5, covering meeting-style rooms, 1:1 ringing calls, call logs and recording.

    130 GitHub stars~5.2k tokensUpdated 2 days ago
    Auto-check passed
  • CometChat Android v5 Headless SDK

    cometchat/cometchat-skills

    Builds chat on Android with your own UI against the headless CometChat Chat SDK v5, covering install, Jetifier conflicts, credentials and init-before-login ordering.

    130 GitHub stars~4k tokensUpdated 2 days ago
    Auto-check passed
  • CometChat Angular Component Picker

    cometchat/cometchat-skills

    Picks and customizes CometChat's Angular UI Kit components by their verified component list, exact input and output event names, and the surfaces that have no kit component at all.

    130 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed
  • CometChat Angular Features

    cometchat/cometchat-skills

    Enables or builds CometChat features such as polls, reactions, smart replies and pinned messages in an Angular app, first classifying how much client code each one needs.

    130 GitHub stars~2.6k tokensUpdated 2 days ago
    Auto-check passed
  • CometChat Angular Chat Placement

    cometchat/cometchat-skills

    Decides where CometChat chat UI goes in an Angular app: a dedicated route, a dashboard panel, a support widget or the full multi-pane app, with thread and search panels.

    130 GitHub stars~2.2k tokensUpdated 2 days ago
    Auto-check passed
  • Cometchat iOS V5 SDK

    cometchat/cometchat-skills

    Add voice & video calling to any iOS app FROM SCRATCH with the headless CometChat Calls SDK v5 (CometChatCallsSDK, via Swift Package Manager) — no UI Kit.

    130 GitHub stars~5.2k tokensUpdated 2 days ago
    Auto-check passed

Questions about Cometchat Angular V5 Production

What does Cometchat Angular V5 Production do?

Ship a CometChat Angular integration safely — server-minted auth tokens instead of the Auth Key, environment file replacement, key hygiene, build config and a pre-launch checklist. Cometchat Angular V5 Production is an agent skill from cometchat/cometchat-skills. Ship a CometChat Angular integration safely — server-minted auth tokens instead of the Auth Key, environment file replacement, key hygiene, build config and a pre-launch checklist.

When should I use Cometchat Angular V5 Production?

Cometchat Angular V5 Production fits situations like: tasks that involve Product launch strategy.

How do I install Cometchat Angular V5 Production in Claude Code?

Run `npx skills add cometchat/cometchat-skills --skill cometchat-angular-v5-production -a claude-code`. Or copy the skill folder (skills/cometchat-angular-v5-production in cometchat/cometchat-skills) into .claude/skills/cometchat-angular-v5-production in your project. Claude Code loads it when a task matches its description.

How do I install Cometchat Angular V5 Production in Codex?

Run `npx skills add cometchat/cometchat-skills --skill cometchat-angular-v5-production -a codex`. Or copy the skill folder (skills/cometchat-angular-v5-production in cometchat/cometchat-skills) into .agents/skills/cometchat-angular-v5-production in your project. Codex loads it when a task matches its description.

Can I use Cometchat Angular V5 Production in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cometchat/cometchat-skills --skill cometchat-angular-v5-production -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cometchat-angular-v5-production, .gemini/skills/cometchat-angular-v5-production, .github/skills/cometchat-angular-v5-production and .opencode/skills/cometchat-angular-v5-production in your project.

What does Cometchat Angular V5 Production need to run?

SKILL.md names no scripts, command-line tools or credentials: Cometchat Angular V5 Production is instructions for the agent only. Our summary lists: A credential in YOUR_AUTH_KEY. Compatibility (from SKILL.md): @cometchat/chat-uikit-angular ^5 (5.1.0–5.2.0 verified); Angular 17-21.

Does Cometchat Angular V5 Production access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cometchat Angular V5 Production safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cometchat Angular V5 Production use?

Cometchat Angular V5 Production is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cometchat Angular V5 Production use?

About 1.6k tokens (SKILL.md is roughly 6.6k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cometchat Angular V5 Production?

Skills that share tags, products or a category with Cometchat Angular V5 Production: SaaS Mvp Launcher (sickn33/agentic-awesome-skills, 47k stars), Submit To Agentlaunch (davepoon/buildwithclaude, 3.6k stars), Dr Jskill (jdubois/dr-jskill, 342 stars) and Sanity Best Practices (sanity-io/agent-toolkit, 188 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cometchat Angular V5 Production?

cometchat (a GitHub organization) maintains it in cometchat/cometchat-skills, which has 130 GitHub stars. The repository holds 97 skills in this directory. The repository was last updated on October 5, 2026.

Source: cometchat/cometchat-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.