Agent skill

Cometchat Flutter V6 Production

by cometchat in cometchat/cometchat-skills

Take a CometChat Flutter integration to production — server-minted auth tokens instead of the Auth Key, secret handling in a Flutter bundle, logout/session hygiene, release build config, and the…

MITAuto-check passedMobile

Install Cometchat Flutter V6 Production

skills CLI
$ npx skills add cometchat/cometchat-skills --skill cometchat-flutter-v6-production -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cometchat/cometchat-skills cometchat-flutter-v6-production --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cometchat/cometchat-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cometchat-flutter-v6-production .claude/skills/cometchat-flutter-v6-production && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cometchat-flutter-v6-production
GitHub stars
131
Token cost
~1.4k tokens
SKILL.md length
700 words
Files
1
Skills in repo
97
Repo updated
First seen
Licence
MIT

At a glance

Take a CometChat Flutter integration to production — server-minted auth tokens instead of the Auth Key, secret handling in a Flutter bundle, logout/session hygiene, release build config, and the…

  • Works in 4 steps: Your server mints a per-user auth token… → Your app authenticates the user your… → The app signs in with the token → …
  • Tasks that involve Cross-platform mobile apps
  • SKILL.md covers Companion skills (read first), Use this skill when, Prerequisites & install and The one thing that actually…, plus 5 more sections
  • Calls flutter

What it does

Cometchat Flutter V6 Production is an agent skill from cometchat/cometchat-skills. Take a CometChat Flutter integration to production — server-minted auth tokens instead of the Auth Key, secret handling in a Flutter bundle, logout/session hygiene, release build config, and the pre-ship checklist. Triggers: 'production auth cometchat', 'auth token flutter', 'is the auth key safe', 'ship cometchat to production', 'release build cometchat'.

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: Flutter =3.38.9; cometchatchatuikit ^6 (6.1.x, verified 6.1.0); cometchatsdk ^5.0.6

It sits in Mobile, covering Cross-platform mobile apps and App store release. It works with CometChat and Flutter. The repository describes itself as: Add CometChat chat & messaging and voice & video calls to any React, Next.js, React Native, Angular, Android, iOS, or Flutter project through your AI coding agent. Works with… The licence is MIT.

When your agent uses it

  • Tasks that involve Cross-platform mobile apps
  • Tasks that involve App store release

Example prompts

  • “production auth cometchat”
  • “auth token flutter”
  • “is the auth key safe”
  • “/cometchat-flutter-v6-production”

Requirements

  • Compatibility (from SKILL.md): Flutter >=3.38.9; cometchat_chat_uikit ^6 (6.1.x, verified 6.1.0); cometchat_sdk ^5.0.6

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Your server mints a per-user auth token by calling CometChat's REST API with the REST API Key (which stays on the server, never in the app).
  2. Your app authenticates the user your normal way, then asks YOUR backend for that token.
  3. The app signs in with the token
  4. Remove credentials.authKey from the shipped settings file. Confirm by unzipping the release artifact and grepping for the key — do not…

What it can do on your machine

Read from SKILL.md and the folder at commit 911b108. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • flutter

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Flutter >=3.38.9; cometchat_chat_uikit ^6 (6.1.x, verified 6.1.0); cometchat_sdk ^5.0.6

    From compatibility in the SKILL.md frontmatter.

Context cost

Cometchat Flutter V6 Production loads about 1.4k tokens when it runs. Until then it costs about 98 tokens; SKILL.md has 700 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~98
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cometchat/cometchat-skills at commit 911b108, republished under its MIT licence (© cometchat). 700 words, ~1,413 tokens.

Download SKILL.mdSave it as .claude/skills/cometchat-flutter-v6-production/SKILL.md (or your agent's skills folder).
name
cometchat-flutter-v6-production
description
Take a CometChat Flutter integration to production — server-minted auth tokens instead of the Auth Key, secret handling in a Flutter bundle, logout/session hygiene, release build config, and the pre-ship checklist. Triggers: 'production auth cometchat', 'auth token flutter', 'is the auth key safe', 'ship cometchat to production', 'release build cometchat'.
compatibility
Flutter >=3.38.9; cometchat_chat_uikit ^6 (6.1.x, verified 6.1.0); cometchat_sdk ^5.0.6
license
MIT
metadata.author
CometChat
metadata.version
1.0.0
metadata.tags
cometchat flutter production auth-token security release v6

Ground truth: loginWithAuthToken and logout are catalog-verified against 6.1.0. Token MINTING is a server-side REST call — its exact endpoint is FETCHED from the REST API docs, never guessed. The dev-vs-prod credential rule is RULES.md §4.

Companion skills (read first)

  • cometchat-flutter-v6-core — install, credentials, init→login→render, lifecycle.md. This skill ASSUMES it.
  • cometchat-flutter-v6-patterns — where config comes from in your build pipeline.
  • cometchat-security — the enterprise auth model this client-side hardening plugs into: wiring your IdP / SSO into the token flow (your IdP → your server → mint the CometChat auth token; CometChat is not an IdP), token expiry/refresh + re-login, RBAC roles + group (SBAC) scopes, and Auth Key vs auth token vs REST API Key. Load it for a security review or any SSO question.

Use this skill when

Hardening before release: "is the Auth Key safe to ship", "set up production auth", "what do I check before shipping".

Prerequisites & install

Core done. No new package.

The one thing that actually matters: the Auth Key must not ship

An Auth Key can log in as ANY user of your app. Everything core writes for development puts it in cometchat-settings.json, which is bundled into the APK/IPA — and a bundle is not a secret. Anyone can extract it.

Development (what core wired): credentials.authKey in the settings asset → CometChatUIKit.login(uid). Fine for building; never for release.

Production (what you must move to):

  1. Your server mints a per-user auth token by calling CometChat's REST API with the REST API Key (which stays on the server, never in the app).
  2. Your app authenticates the user your normal way, then asks YOUR backend for that token.
  3. The app signs in with the token:
dart
import 'package:cometchat_chat_uikit/cometchat_chat_uikit.dart';

Future<void> signIn(String authTokenFromYourServer) async {
  await CometChatUIKit.loginWithAuthToken(
    authTokenFromYourServer,
    onSuccess: (User user) {},
    onError: (CometChatException e) {},
  );
}
  1. Remove credentials.authKey from the shipped settings file. Confirm by unzipping the release artifact and grepping for the key — do not take it on trust.

Fetch the exact token-minting endpoint from the REST API docs (../cometchat-flutter-v6-core/references/docs-map.md → SDK/REST). Never invent a URL or payload.

Session hygiene

  • Log out properly — CometChatUIKit.logout() on your app's sign-out, and unregister the push token FIRST (-push), or the next user of the device receives the previous user's notifications.
  • One user per session. login no-ops if that UID is already signed in, but switching users requires an explicit logout first.
  • Token expiry — a server-minted token can expire; handle the login error by refetching from your backend rather than falling back to the Auth Key.
Show full SKILL.md (312 more words)Show less

Release build config

  • Android — minSdk 26 (the docs' 24 is too low — the kit's cometchat_calls_sdk dependency pins 26); INTERNET permission; calling adds camera/mic. If you use R8/ProGuard, verify the kit still works in a release build, not just debug.
  • iOS — deployment target per the docs; usage-description strings for camera/mic/photos, or the OS kills the app on first use.
  • Settings asset — a registered asset, so NOT gitignored (a fresh clone / CI flutter build fails with "No file or variants found for asset"): commit a placeholder (no real Auth Key) and have CI overwrite it at build time with the prod-flavoured file (no Auth Key).
  • Flavors — dev and prod should point at different CometChat apps; do not test against production data.

Pre-ship checklist

  1. No Auth Key in the release artifact (verified by inspection, not assumption).
  2. loginWithAuthToken is the only login path in prod code.
  3. Logout clears the session and unregisters push.
  4. Permission strings present on both platforms.
  5. Release build (obfuscated) actually runs — chat renders, messages send.
  6. Tested against the prod CometChat app, on real devices.
  7. Errors surface to the user rather than being swallowed in an empty onError.

Common pitfalls (BAKED)

  • Shipping the Auth Key — the single most serious mistake here.
  • Assuming --dart-define is a secret — it is compiled into the binary, same exposure.
  • Only testing debug builds — obfuscation/minification problems appear only in release.
  • No logout path → the session persists across users on a shared device.
  • Swallowing onError → a production auth failure looks like a blank screen.
  • Minting tokens in the app — that needs the REST key, which must never be in the client.

Verify it works

The release artifact contains no Auth Key; sign-in goes through your backend; sign-out clears the session and push; a release build on a real device sends and receives; an expired token produces a clean re-auth rather than a blank screen.

© cometchat, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cometchat-flutter-v6-production of cometchat/cometchat-skills.

Open the folder on GitHubat commit 911b108

Compare with similar skills

Cometchat Flutter V6 Production next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cometchat Flutter V6 Production compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cometchat Flutter V6 Production this skillcometchat/cometchat-skills131—~1.4kAutomated safety check: PassMIT
Marionette Flutter Drive Appleancodepl/marionette_mcp482—~11kAutomated safety check: PassApache-2.0
Mobile App Builderrevfactory/harness-1001.3k—~1.8kAutomated safety check: PassApache-2.0
OdevioOdevio/Odevio-CLI423—~7.6kAutomated safety check: PassMIT
Flutter Appccplugins/awesome-claude-code-plugins970—~1.1kAutomated safety check: NotesApache-2.0
Mobile Developeraiskillstore/marketplace4307 repos~2.3kAutomated safety check: PassNone

Similar skills

  • Marionette Flutter Drive App

    leancodepl/marionette_mcp

    Set up and drive a running Flutter app (debug or profile) with Marionette — an AI agent's hands and eyes for the app.

    482 GitHub stars~11k tokensUpdated 3 days ago
    MobileAuto-check passed
  • Mobile App Builder

    revfactory/harness-100

    Full mobile app development pipeline. An agent skill from revfactory/harness-100.

    1.3k GitHub stars~1.8k tokensUpdated 6 mo ago
    MobileAuto-check passed
  • Odevio

    Odevio/Odevio-CLI

    Take a Flutter project to an iPhone or the App Store with Odevio - build, sign and publish iOS apps from Windows, Linux or macOS with no Mac and no Xcode.

    423 GitHub stars~7.6k tokensUpdated 14 days ago
    MobileAuto-check passed
  • Flutter App

    ccplugins/awesome-claude-code-plugins

    Bootstrap a new Flutter mobile app with clean architecture, Riverpod, FVM-pinned SDK, current packages, and no deprecated APIs.

    970 GitHub stars~1.1k tokensUpdated 1 mo ago
    MobileAuto-check: notes
  • Mobile Developer

    aiskillstore/marketplace

    Develop React Native, Flutter, or native mobile apps with modern architecture patterns.

    430 GitHub starsUsed in 7 repos~2.3k tokens
    MobileAuto-check passed
  • Measures and optimizes the size of Flutter application bundles for deployment.

    130 GitHub stars~1.4k tokensUpdated 11 days ago
    MobileAuto-check passed

More from cometchat/cometchat-skills

All 97 skills in this repo
  • CometChat Android Calls SDK v5

    cometchat/cometchat-skills

    Adds voice and video calling to an Android app in Kotlin with the headless CometChat Calls SDK v5, covering meeting-style rooms, 1:1 ringing calls, call logs and recording.

    131 GitHub stars~5.2k tokensUpdated 3 days ago
    Auto-check passed
  • CometChat Android v5 Headless SDK

    cometchat/cometchat-skills

    Builds chat on Android with your own UI against the headless CometChat Chat SDK v5, covering install, Jetifier conflicts, credentials and init-before-login ordering.

    131 GitHub stars~4k tokensUpdated 3 days ago
    Auto-check passed
  • CometChat Angular Component Picker

    cometchat/cometchat-skills

    Picks and customizes CometChat's Angular UI Kit components by their verified component list, exact input and output event names, and the surfaces that have no kit component at all.

    131 GitHub stars~2.6k tokensUpdated 3 days ago
    Auto-check passed
  • CometChat Angular Features

    cometchat/cometchat-skills

    Enables or builds CometChat features such as polls, reactions, smart replies and pinned messages in an Angular app, first classifying how much client code each one needs.

    131 GitHub stars~2.6k tokensUpdated 3 days ago
    Auto-check passed
  • CometChat Angular Chat Placement

    cometchat/cometchat-skills

    Decides where CometChat chat UI goes in an Angular app: a dedicated route, a dashboard panel, a support widget or the full multi-pane app, with thread and search panels.

    131 GitHub stars~2.2k tokensUpdated 3 days ago
    Auto-check passed
  • Cometchat iOS V5 SDK

    cometchat/cometchat-skills

    Add voice & video calling to any iOS app FROM SCRATCH with the headless CometChat Calls SDK v5 (CometChatCallsSDK, via Swift Package Manager) — no UI Kit.

    131 GitHub stars~5.2k tokensUpdated 3 days ago
    Auto-check passed

Categories

Questions about Cometchat Flutter V6 Production

What does Cometchat Flutter V6 Production do?

Take a CometChat Flutter integration to production — server-minted auth tokens instead of the Auth Key, secret handling in a Flutter bundle, logout/session hygiene, release build config, and the…. Cometchat Flutter V6 Production is an agent skill from cometchat/cometchat-skills. Take a CometChat Flutter integration to production — server-minted auth tokens instead of the Auth Key, secret handling in a Flutter bundle, logout/session hygiene, release build config, and the pre-ship checklist.

When should I use Cometchat Flutter V6 Production?

Cometchat Flutter V6 Production fits situations like: tasks that involve Cross-platform mobile apps; tasks that involve App store release.

How do I install Cometchat Flutter V6 Production in Claude Code?

Run `npx skills add cometchat/cometchat-skills --skill cometchat-flutter-v6-production -a claude-code`. Or copy the skill folder (skills/cometchat-flutter-v6-production in cometchat/cometchat-skills) into .claude/skills/cometchat-flutter-v6-production in your project. Claude Code loads it when a task matches its description.

How do I install Cometchat Flutter V6 Production in Codex?

Run `npx skills add cometchat/cometchat-skills --skill cometchat-flutter-v6-production -a codex`. Or copy the skill folder (skills/cometchat-flutter-v6-production in cometchat/cometchat-skills) into .agents/skills/cometchat-flutter-v6-production in your project. Codex loads it when a task matches its description.

Can I use Cometchat Flutter V6 Production in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cometchat/cometchat-skills --skill cometchat-flutter-v6-production -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cometchat-flutter-v6-production, .gemini/skills/cometchat-flutter-v6-production, .github/skills/cometchat-flutter-v6-production and .opencode/skills/cometchat-flutter-v6-production in your project.

What does Cometchat Flutter V6 Production need to run?

Going by SKILL.md and its folder, Cometchat Flutter V6 Production needs the command-line tools its instructions call (flutter). Compatibility (from SKILL.md): Flutter >=3.38.9; cometchat_chat_uikit ^6 (6.1.x, verified 6.1.0); cometchat_sdk ^5.0.6.

Does Cometchat Flutter V6 Production access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cometchat Flutter V6 Production safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cometchat Flutter V6 Production use?

Cometchat Flutter V6 Production is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cometchat Flutter V6 Production use?

About 1.4k tokens (SKILL.md is roughly 5.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cometchat Flutter V6 Production?

Skills that share tags, products or a category with Cometchat Flutter V6 Production: Marionette Flutter Drive App (leancodepl/marionette_mcp, 482 stars), Mobile App Builder (revfactory/harness-100, 1.3k stars), Odevio (Odevio/Odevio-CLI, 423 stars) and Flutter App (ccplugins/awesome-claude-code-plugins, 970 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cometchat Flutter V6 Production?

cometchat (a GitHub organization) maintains it in cometchat/cometchat-skills, which has 131 GitHub stars. The repository holds 97 skills in this directory. The repository was last updated on October 5, 2026.

Source: cometchat/cometchat-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.