cometchat-android-v5-features — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cometchat-android-v5-features (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Ground truth:com.cometchat:chat-uikit-android:5.x(legacy/maintenance-only; +calls-sdk-android:5.x) — resolved AAR (javap) +ui-kit/android. Official docs: https://www.cometchat.com/docs/fundamentals/extensions-overview · Docs MCP:claude mcp add --transport http cometchat-docs https://www.cometchat.com/docs/mcp(or fetch the URL directly without MCP). Verify symbols against the installed package/source before relying on them.
Companion skills:cometchat-android-v5-corecovers initialization;cometchat-android-v5-customizationcovers deeper component customization;cometchat-android-v5-extensionscovers the extension architecture.
This skill teaches how CometChat features are structured and what work is required to enable each one. Most features require zero code — they are either already built into the UI Kit, toggled via the cometchat apply-feature CLI (extensions + AI features), or activated by adding a dependency (calls).
cometchat-android-v5-customizationcometchat-android-v5-core| Type | What it means | Action required |
|---|---|---|
| Type 1 — Default | Built into the UI Kit at compile time | None — already there |
| Type 2a — Extension | Backend extension, pure boolean toggle | cometchat apply-feature <id> --app-id <X> (CLI hits dashboard API) |
| Type 2b — AI feature | Backend AI feature requiring an OpenAI key | cometchat apply-feature <id> --app-id <X> --openai-key sk-... |
| Type 2c — Dashboard-only | Third-party API key / multi-field config (Giphy, Stipop, Tenor, Chatwoot, Intercom) | Open https://app.cometchat.com → Chat & Messaging → Features → configure |
| Type 3 — Package-install | Requires a separate SDK dependency | Add Gradle dependency |
| Type 4 — Component-toggle | Hide/show via setHide* / disable* methods on the relevant component | Call the setter on the component instance (see catalog) |
| Feature | Component | Notes |
|---|---|---|
| Text messaging | CometChatMessageComposer + CometChatMessageList | Core feature |
| Media sharing (image/video/audio/file) | CometChatMessageComposer | Attachment button |
| Read receipts | CometChatMessageList | setReceiptsVisibility() |
| Typing indicators | CometChatMessageList + CometChatConversations | Auto-enabled |
| User presence (online/offline) | CometChatConversations, CometChatUsers | Requires subscribePresenceForAllUsers() in init |
| Reactions | CometChatMessageList | Long-press message → react |
| Mentions (@user, @all) | CometChatMessageComposer | Type @ to trigger |
| Threaded conversations | CometChatMessageList | setReplyInThreadOptionVisibility() |
| Quoted replies | CometChatMessageList | Swipe to reply |
| Edit/delete messages | CometChatMessageList | Long-press options |
| Group chat | All components | Use setGroup() instead of setUser() |
| Report message | CometChatMessageList | Long-press → Report |
| Search | CometChatSearch | Standalone component |
Android projects don't run cometchat apply, so call the CLI in stateless mode with --app-id:
# Pure boolean extensions:
cometchat apply-feature polls --app-id <your-app-id>
cometchat apply-feature stickers --app-id <your-app-id>
# AI features (require OpenAI key):
cometchat apply-feature smart-replies --app-id <your-app-id> --openai-key sk-...
cometchat apply-feature conversation-summary --app-id <your-app-id>
cometchat apply-feature conversation-starter --app-id <your-app-id>Requires cometchat auth login once per machine.
Extensions (CLI-toggleable — pure boolean):
AI Features (CLI-toggleable — needs `--openai-key`): Conversation Starter, Conversation Summary, Smart Reply
Dashboard-only (third-party config — open https://app.cometchat.com → Chat & Messaging → Features): Stickers (Stipop), Giphy, Tenor, Chatwoot, Intercom — these require API keys / webhooks the user must enter manually.
Add the calling SDK:
implementation 'com.cometchat:calls-sdk-android:5.+'The UI Kit auto-detects the calling SDK and enables call buttons in CometChatMessageHeader. No additional code needed — CometChatIncomingCall, CometChatOutgoingCall, and CometChatOngoingCall activate automatically.
Configure call buttons visibility:
CometChatMessageHeader header = findViewById(R.id.header);
header.setVoiceCallButtonVisibility(View.VISIBLE);
header.setVideoCallButtonVisibility(View.VISIBLE);cometchat apply-feature <id> --app-id <X> (extension) or ... --openai-key sk-... (ai-feature). The CLI flips the dashboard toggle via API. Never tell the user to "open the dashboard and toggle X" for an extension or ai-feature — that's what the CLI does.cometchat apply-feature <id>'s manual-action-required response.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.