Agent skill

Cometchat iOS Production

by cometchat in cometchat/cometchat-skills

Ship a CometChat iOS (Swift) integration safely — server-minted auth tokens instead of the Auth Key, keeping secrets out of the app binary, and a pre-launch checklist.

MITAuto-check passedMobile

Install Cometchat iOS Production

skills CLI
$ npx skills add cometchat/cometchat-skills --skill cometchat-ios-production -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install cometchat/cometchat-skills cometchat-ios-production --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/cometchat/cometchat-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/cometchat-ios-production .claude/skills/cometchat-ios-production && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
cometchat-ios-production
GitHub stars
130
Token cost
~1.5k tokens
SKILL.md length
621 words
Files
1
Skills in repo
97
Repo updated
First seen
Licence
MIT

At a glance

Ship a CometChat iOS (Swift) integration safely — server-minted auth tokens instead of the Auth Key, keeping secrets out of the app binary, and a pre-launch checklist.

  • Works in 4 steps: Your app authenticates the user (your… → Your server mints a CometChat auth token… → The server returns the token to the app… → …
  • Tasks that involve iOS development
  • SKILL.md covers Companion skills (read first), Use this skill when, The one thing that matters and The production login flow, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Cometchat iOS Production is an agent skill from cometchat/cometchat-skills. Ship a CometChat iOS (Swift) integration safely — server-minted auth tokens instead of the Auth Key, keeping secrets out of the app binary, and a pre-launch checklist. Triggers: 'is my cometchat ios production ready', 'auth token instead of auth key swift', 'secure cometchat ios', 'going live checklist ios', 'harden cometchat swift before launch'.

Its SKILL.md is about 1.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts. Compatibility notes: CometChatUIKitSwift 5.1.22 + CometChatSDK 4.1.7 (exact); Xcode 16+; iOS 15.1+; SPM only

It sits in Mobile, covering iOS development and Product launch strategy. It works with CometChat and iOS. The repository describes itself as: Add CometChat chat & messaging and voice & video calls to any React, Next.js, React Native, Angular, Android, iOS, or Flutter project through your AI coding agent. Works with… The licence is MIT.

When your agent uses it

  • Tasks that involve iOS development
  • Tasks that involve Product launch strategy

Example prompts

  • “is my cometchat ios production ready”
  • “auth token instead of auth key swift”
  • “secure cometchat ios”
  • “/cometchat-ios-production”

Requirements

  • Compatibility (from SKILL.md): CometChatUIKitSwift 5.1.22 + CometChatSDK 4.1.7 (exact); Xcode 16+; iOS 15.1+; SPM only

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Your app authenticates the user (your own auth / sign-in with Apple / your backend).
  2. Your server mints a CometChat auth token for that user's UID via the REST API using the REST API Key ({DOCS_BASE}/rest-api/auth-tokens).
  3. The server returns the token to the app over an authenticated HTTPS request.
  4. The app calls login(authToken:).

What it can do on your machine

Read from SKILL.md and the folder at commit 911b108. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are swift and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    CometChatUIKitSwift 5.1.22 + CometChatSDK 4.1.7 (exact); Xcode 16+; iOS 15.1+; SPM only

    From compatibility in the SKILL.md frontmatter.

Context cost

Cometchat iOS Production loads about 1.5k tokens when it runs. Until then it costs about 94 tokens; SKILL.md has 621 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~94
When it runs · the whole SKILL.md, loaded when a task matches
~1.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from cometchat/cometchat-skills at commit 911b108, republished under its MIT licence (© cometchat). 621 words, ~1,462 tokens.

Download SKILL.mdSave it as .claude/skills/cometchat-ios-production/SKILL.md (or your agent's skills folder).
name
cometchat-ios-production
description
Ship a CometChat iOS (Swift) integration safely — server-minted auth tokens instead of the Auth Key, keeping secrets out of the app binary, and a pre-launch checklist. Triggers: 'is my cometchat ios production ready', 'auth token instead of auth key swift', 'secure cometchat ios', 'going live checklist ios', 'harden cometchat swift before launch'.
compatibility
CometChatUIKitSwift 5.1.22 + CometChatSDK 4.1.7 (exact); Xcode 16+; iOS 15.1+; SPM only
license
MIT
metadata.author
CometChat
metadata.version
1.0.0
metadata.tags
cometchat ios swift production security auth-token hardening appstore

Ground truth: CometChatUIKitSwift 5.1.22 + CometChatSDK 4.1.7 (symbols verified vs catalogs/ios-v5.json). The login/auth-token API is FETCHED via cometchat-ios-core/references/docs-map.md; the REST auth-token endpoint is {DOCS_BASE}/rest-api/auth-tokens. The iOS UI Kit docs have no single production-hardening page — this checklist is the pack's own guidance from RULES.md §4 + cometchat-ios-core/references/setup-credentials.md, labelled as such. Tracked DOCS GAP.

Companion skills (read first)

  • cometchat-ios-core — references/setup-credentials.md (the Secrets.xcconfig → Info.plist → Bundle.main flow) and references/swiftui.md (the init→login launch hook) this hardens.
  • cometchat-security — the enterprise auth model this client-side hardening plugs into: wiring your IdP / SSO into the token flow (your IdP → your server → mint the CometChat auth token; CometChat is not an IdP), token expiry/refresh + re-login, RBAC roles + group (SBAC) scopes, and Auth Key vs auth token vs REST API Key. Load it for a security review or any SSO question.

Use this skill when

Moving off the development setup: TestFlight/App Store submission, a security review, or "is this safe to ship."

The one thing that matters

Never embed the Auth Key in the app binary.

The Auth Key can mint a session for any user in your app. Anything baked into the app — an xcconfig value promoted into Info.plist, a string constant — is recoverable from the shipped .ipa (strings, class-dump). Treat it as public.

DevelopmentProduction
LoginCometChatUIKit.login(uid:...)CometChatUIKit.login(authToken:...)
Auth Keyin Secrets.xcconfignot in the build
Token sourcen/ayour backend, per authenticated user
REST API Keynever in the appserver only

The production login flow

  1. Your app authenticates the user (your own auth / sign-in with Apple / your backend).
  2. Your server mints a CometChat auth token for that user's UID via the REST API using the REST API Key ({DOCS_BASE}/rest-api/auth-tokens).
  3. The server returns the token to the app over an authenticated HTTPS request.
  4. The app calls login(authToken:).
swift
// UID comes from the SERVER session, never from the client
let authToken = try await fetchCometChatToken()   // your authenticated endpoint
CometChatUIKit.login(authToken: authToken) { result in /* handle success/failure */ }

init must resolve first (initFromSettings), then login — calling login before init resolves fails silently (cometchat-ios-core).

Keep secrets out of the build

Development reads the Auth Key from a gitignored Secrets.xcconfig promoted into Info.plist. For production, ship App ID + Region only (not secrets — they identify the app) and log in with a token; leave the Auth-Key value empty in the release configuration.

bash
# after an archive/build, confirm the key is not in the app binary
strings "$APP_BUNDLE/YourApp" | grep -q "<your-auth-key>" && echo "LEAK" || echo "clean"

Also verify Secrets.xcconfig is in .gitignore (only a committed placeholder), and that it is not bundled as a resource.

Show full SKILL.md (249 more words)Show less

Also before launch

  • Users are created server-side as part of signup — not from the app with the Auth Key.
  • Log out properly: CometChatUIKit.logout(), then clear derived state and unregister VoIP/APNs push tokens (cometchat-ios-push).
  • Pin exact versions — the kit is a prebuilt binary compiled against one Chat SDK version; a drifting CometChatSDK breaks it (cometchat-ios-core Install).
  • App Transport Security: keep HTTPS; do not add broad NSAllowsArbitraryLoads exceptions.
  • Calls need permissions: NSCameraUsageDescription + NSMicrophoneUsageDescription with real strings, or App Review rejects; VoIP push needs the entitlement.
  • Region must match the dashboard app.
  • Enable dashboard extensions/AI on the PRODUCTION app, not just dev.

Pre-launch checklist

  • Auth Key not in the app binary (strings-verified)
  • login(authToken:) in production; UID from the server session
  • REST API Key server-side only
  • Secrets.xcconfig gitignored; only a placeholder committed
  • Exact kit/SDK/Calls versions pinned
  • Camera/mic usage strings + VoIP entitlement present (if calling)
  • Logout clears session, state and push tokens
  • Dashboard extensions/AI enabled for the production app
  • Tested against the production app's credentials

Common pitfalls

  1. Auth Key recoverable from the .ipa — the critical one.
  2. Token endpoint trusting a client-supplied UID — impersonation.
  3. Login before init resolves — silent no-render (order invariant).
  4. Missing usage-description strings — App Review rejection for calling apps.
  5. Dashboard configured on the dev app only — features silently missing in production.

Verify it works

Archived build's binary contains no Auth Key (strings) · login works via token · a tampered UID is rejected by the server · logout fully clears · calls request permission and connect · features enabled on the production app.

© cometchat, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/cometchat-ios-production of cometchat/cometchat-skills.

Open the folder on GitHubat commit 911b108

Compare with similar skills

Cometchat iOS Production next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Cometchat iOS Production compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Cometchat iOS Production this skillcometchat/cometchat-skills130—~1.5kAutomated safety check: PassMIT
Hig Project Contextraintree-technology/hig-doctor1435 repos~1.2kAutomated safety check: PassMIT
Hig Components Contentraintree-technology/hig-doctor1435 repos~1.3kAutomated safety check: PassMIT
iOS Simulator Skilln0an/VivaDicta1311 repos~2.5kAutomated safety check: PassMIT
Inspector Implementationipedro/Inspector170—~729Automated safety check: PassMIT
Run iOS SimulatoriPlug2/iPlug2OOS158—~711Automated safety check: PassNone

Similar skills

  • Hig Project Context

    raintree-technology/hig-doctor

    Create or update a shared Apple design context document that other HIG skills use to tailor guidance.

    143 GitHub starsUsed in 5 repos~1.2k tokens
    MobileAuto-check passed
  • Hig Components Content

    raintree-technology/hig-doctor

    Apple Human Interface Guidelines for content display components.

    143 GitHub starsUsed in 5 repos~1.3k tokens
    MobileAuto-check passed
  • iOS Simulator Skill

    n0an/VivaDicta

    21 production-ready scripts for iOS app testing, building, and automation.

    131 GitHub starsUsed in 1 repo~2.5k tokens
    MobileAuto-check passed
  • Inspector Implementation

    ipedro/Inspector

    A skill your agent uses when an agent needs to implement or modify the Inspector library itself — panel UI, hierarchy/runtime behavior, custom property models, macros, or Example-app dogfooding.

    170 GitHub stars~729 tokensUpdated 5 mo ago
    MobileAuto-check passed
  • Run iOS Simulator

    iPlug2/iPlug2OOS

    Build and run an iPlug2 iOS app in the iOS Simulator. An agent skill from iPlug2/iPlug2OOS.

    158 GitHub stars~711 tokensUpdated 23 days ago
    MobileAuto-check passed
  • Official

    Evaluates a bitwarden/ios "Update SDK to" PR against the sdk-swift commit range for compile-time, runtime and serialization breaking changes, maps affected symbols to iOS call sites, and applies…

    695 GitHub stars~2.6k tokensUpdated yesterday
    MobileAuto-check passed

More from cometchat/cometchat-skills

All 97 skills in this repo
  • CometChat Android Calls SDK v5

    cometchat/cometchat-skills

    Adds voice and video calling to an Android app in Kotlin with the headless CometChat Calls SDK v5, covering meeting-style rooms, 1:1 ringing calls, call logs and recording.

    130 GitHub stars~5.2k tokensUpdated 3 days ago
    Auto-check passed
  • CometChat Android v5 Headless SDK

    cometchat/cometchat-skills

    Builds chat on Android with your own UI against the headless CometChat Chat SDK v5, covering install, Jetifier conflicts, credentials and init-before-login ordering.

    130 GitHub stars~4k tokensUpdated 3 days ago
    Auto-check passed
  • CometChat Angular Component Picker

    cometchat/cometchat-skills

    Picks and customizes CometChat's Angular UI Kit components by their verified component list, exact input and output event names, and the surfaces that have no kit component at all.

    130 GitHub stars~2.6k tokensUpdated 3 days ago
    Auto-check passed
  • CometChat Angular Features

    cometchat/cometchat-skills

    Enables or builds CometChat features such as polls, reactions, smart replies and pinned messages in an Angular app, first classifying how much client code each one needs.

    130 GitHub stars~2.6k tokensUpdated 3 days ago
    Auto-check passed
  • CometChat Angular Chat Placement

    cometchat/cometchat-skills

    Decides where CometChat chat UI goes in an Angular app: a dedicated route, a dashboard panel, a support widget or the full multi-pane app, with thread and search panels.

    130 GitHub stars~2.2k tokensUpdated 3 days ago
    Auto-check passed
  • Cometchat iOS V5 SDK

    cometchat/cometchat-skills

    Add voice & video calling to any iOS app FROM SCRATCH with the headless CometChat Calls SDK v5 (CometChatCallsSDK, via Swift Package Manager) — no UI Kit.

    130 GitHub stars~5.2k tokensUpdated 3 days ago
    Auto-check passed

Works with

Categories

Questions about Cometchat iOS Production

What does Cometchat iOS Production do?

Ship a CometChat iOS (Swift) integration safely — server-minted auth tokens instead of the Auth Key, keeping secrets out of the app binary, and a pre-launch checklist. Cometchat iOS Production is an agent skill from cometchat/cometchat-skills. Ship a CometChat iOS (Swift) integration safely — server-minted auth tokens instead of the Auth Key, keeping secrets out of the app binary, and a pre-launch checklist.

When should I use Cometchat iOS Production?

Cometchat iOS Production fits situations like: tasks that involve iOS development; tasks that involve Product launch strategy.

How do I install Cometchat iOS Production in Claude Code?

Run `npx skills add cometchat/cometchat-skills --skill cometchat-ios-production -a claude-code`. Or copy the skill folder (skills/cometchat-ios-production in cometchat/cometchat-skills) into .claude/skills/cometchat-ios-production in your project. Claude Code loads it when a task matches its description.

How do I install Cometchat iOS Production in Codex?

Run `npx skills add cometchat/cometchat-skills --skill cometchat-ios-production -a codex`. Or copy the skill folder (skills/cometchat-ios-production in cometchat/cometchat-skills) into .agents/skills/cometchat-ios-production in your project. Codex loads it when a task matches its description.

Can I use Cometchat iOS Production in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add cometchat/cometchat-skills --skill cometchat-ios-production -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/cometchat-ios-production, .gemini/skills/cometchat-ios-production, .github/skills/cometchat-ios-production and .opencode/skills/cometchat-ios-production in your project.

What does Cometchat iOS Production need to run?

SKILL.md names no scripts, command-line tools or credentials: Cometchat iOS Production is instructions for the agent only. Compatibility (from SKILL.md): CometChatUIKitSwift 5.1.22 + CometChatSDK 4.1.7 (exact); Xcode 16+; iOS 15.1+; SPM only.

Does Cometchat iOS Production access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Cometchat iOS Production safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Cometchat iOS Production use?

Cometchat iOS Production is published under the MIT licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Cometchat iOS Production use?

About 1.5k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Cometchat iOS Production?

Skills that share tags, products or a category with Cometchat iOS Production: Hig Project Context (raintree-technology/hig-doctor, 143 stars), Hig Components Content (raintree-technology/hig-doctor, 143 stars), iOS Simulator Skill (n0an/VivaDicta, 131 stars) and Inspector Implementation (ipedro/Inspector, 170 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Cometchat iOS Production?

cometchat (a GitHub organization) maintains it in cometchat/cometchat-skills, which has 130 GitHub stars. The repository holds 97 skills in this directory. The repository was last updated on October 5, 2026.

Source: cometchat/cometchat-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.