cometchat-android-v6-extensions — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited cometchat-android-v6-extensions (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Ground truth:com.cometchat:chatuikit-{compose,kotlin}-android:6.x(+calls-sdk-android:5.x) — resolved AAR (javap) +ui-kit/android/v6. Official docs: https://www.cometchat.com/docs/fundamentals/extensions-overview · Docs MCP:claude mcp add --transport http cometchat-docs https://www.cometchat.com/docs/mcp(or fetch the URL directly without MCP). Verify symbols against the installed package/source before relying on them.
Companion skills: cometchat-android-v6-features (feature catalog), cometchat-android-v6-kotlin-customization, cometchat-android-v6-compose-customization
Extend the CometChat UIKit v6 data layer using the clean architecture DataSource/Repository pattern. Create custom DataSource implementations, override repository behavior, and register custom message types.
cometchat-*-customization — that's the BubbleFactory layer)cometchat-*-components)The chatuikit-core module follows clean architecture with three layers:
┌─────────────────────────────────────────┐
│ UI Layer (chatuikit-kotlin / compose) │
│ Components observe ViewModel state │
├─────────────────────────────────────────┤
│ ViewModel Layer (core/viewmodel/) │
│ Calls use cases / repositories │
├─────────────────────────────────────────┤
│ Domain Layer (core/domain/) │
│ Repository interfaces, Use cases │
├─────────────────────────────────────────┤
│ Data Layer (core/data/) │
│ DataSource interfaces + impls │
│ Repository implementations │
└─────────────────────────────────────────┘Each feature area has a DataSource interface and default implementation:
core/data/datasource/
├── ConversationListDataSource.kt (interface)
├── ConversationListDataSourceImpl.kt (default implementation)
├── MessageListDataSource.kt
├── MessageListDataSourceImpl.kt
├── ...| DataSource | Implementation | What it provides |
|---|---|---|
CallButtonsDataSource | CallButtonsDataSourceImpl | Call button actions |
CallLogsDataSource | CallLogsDataSourceImpl | Call history fetching |
CollaborativeDataSource | CollaborativeDataSourceImpl | Document/whiteboard data |
ConversationListDataSource | ConversationListDataSourceImpl | Conversation list fetching |
GroupMembersDataSource | GroupMembersDataSourceImpl | Group member operations |
GroupsDataSource | GroupsDataSourceImpl | Group list fetching |
MessageComposerDataSource | MessageComposerDataSourceImpl | Composer actions/attachments |
MessageHeaderDataSource | MessageHeaderDataSourceImpl | Header data (name, status) |
MessageInformationDataSource | MessageInformationDataSourceImpl | Read receipts, delivery info |
MessageListDataSource | MessageListDataSourceImpl | Message fetching/pagination |
PollDataSource | PollDataSourceImpl | Poll creation/voting |
ReactionListDataSource | ReactionListDataSourceImpl | Reaction data |
SearchDataSource | SearchDataSourceImpl | Global search |
StickerDataSource | StickerDataSourceImpl | Sticker fetching |
UsersDataSource | UsersDataSourceImpl | User list fetching |
| File | Purpose |
|---|---|
MessageReceiptEventListener.kt | Listens for receipt events at the data layer |
Repositories in core/data/repository/ implement domain interfaces from core/domain/repository/:
core/data/repository/
├── CallButtonsRepositoryImpl.kt
├── CallLogsRepositoryImpl.kt
├── ConversationListRepositoryImpl.kt
├── GroupMembersRepositoryImpl.kt
├── GroupsRepositoryImpl.kt
├── MessageComposerRepositoryImpl.kt
├── MessageHeaderRepositoryImpl.kt
├── MessageInformationRepositoryImpl.kt
├── MessageListRepositoryImpl.kt
├── PollRepositoryImpl.kt
├── ReactionListRepositoryImpl.kt
├── SearchRepositoryImpl.kt
├── StickerRepositoryImpl.kt
├── UsersRepositoryImpl.ktEach repository wraps a DataSource and adds business logic, caching, or transformation.
ViewModels in core/viewmodel/ consume repositories and expose UI state:
// Example: CometChatConversationsViewModel
// - Injected via CometChatConversationsViewModelFactory
// - Exposes StateFlow<ConversationListUIState>
// - Calls ConversationListRepositoryImpl internallyViewModel factories in core/factory/ handle dependency injection:
| Factory | ViewModel |
|---|---|
CometChatConversationsViewModelFactory | CometChatConversationsViewModel |
CometChatMessageListViewModelFactory | CometChatMessageListViewModel |
CometChatGroupsViewModelFactory | CometChatGroupsViewModel |
CometChatUsersViewModelFactory | CometChatUsersViewModel |
CometChatCallLogsViewModelFactory | CometChatCallLogsViewModel |
CometChatMessageComposerViewModelFactory | CometChatMessageComposerViewModel |
CometChatMessageHeaderViewModelFactory | CometChatMessageHeaderViewModel |
CometChatGroupMembersViewModelFactory | CometChatGroupMembersViewModel |
CometChatMessageInformationViewModelFactory | CometChatMessageInformationViewModel |
CometChatReactionListViewModelFactory | CometChatReactionListViewModel |
CometChatSearchViewModelFactory | CometChatSearchViewModel |
CometChatCallButtonsViewModelFactory | CometChatCallButtonsViewModel |
CometChatCreatePollViewModelFactory | CometChatCreatePollViewModel |
CometChatThreadHeaderViewModelFactory | CometChatThreadHeaderViewModel |
CometChatStickerKeyboardViewModelFactory | CometChatStickerKeyboardViewModel |
CometChatIncomingCallViewModelFactory | CometChatIncomingCallViewModel |
CometChatOutgoingCallViewModelFactory | CometChatOutgoingCallViewModel |
CometChatAIAssistantChatHistoryViewModelFactory | CometChatAIAssistantChatHistoryViewModel |
Each ViewModel exposes a sealed UI state from core/state/:
| State Class | Used By |
|---|---|
CallLogsUIState | Call logs |
MessageListUIState | Message list |
GroupsUIState | Groups list |
UsersUIState | Users list |
GroupMembersUIState | Group members |
MessageComposerUIState | Composer |
MessageHeaderUIState | Header |
MessageInformationUIState | Message info |
ReactionListUIState | Reactions |
SearchUIState | Search |
CallButtonsUIState | Call buttons |
CreatePollUIState | Poll creation |
ThreadHeaderUIState | Thread header |
StickerKeyboardUIState | Sticker keyboard |
IncomingCallUIState | Incoming call |
OutgoingCallUIState | Outgoing call |
ChatHistoryUIState | AI chat history |
ConversationStarterUIState | AI conversation starter |
ConversationSummaryUIState | AI conversation summary |
SmartRepliesUIState | AI smart replies |
DeleteState | Delete operations |
UIState | Base UI state |
User Action → Component → ViewModel → Repository → DataSource → CometChat SDK
↓
UI Update ← Component ← ViewModel ← StateFlow ← Repository ← SDK ResponseDataSource decorator / ChatConfigurator pattern for bubble customization does NOT exist in v6 — use BubbleFactory instead (see cometchat-*-customization)chatuikit-core~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.