Comm — Security skill for Claude Code
by CommE2E - Serves as a development reference for E2E-encrypted messaging applications with code organization architecture, security implementation details, and testing procedures.
How to install Comm
This entry records only its repository, not the path inside it, so there is no
exact command to give. Open CommE2E/comm and copy the folder into
~/.claude/skills/, or the file into ~/.claude/agents/.
What Comm does
Comm is an E2E-encrypted messaging app. You can think of it as Signal with an IRC-like federated community layer.
Alternatives in Security
- 02 Cross Reference Audit — Cross-Reference Audit 1.1k ★
- Review Artifact — Creates one polished, self-contained HTML artifact from review findings, audit notes, PR feedback, code review 652 ★
- Dotclaude — A comprehensive development environment with specialized AI agents for code review, security analysis, and tec 435 ★
README
Comm
Comm is an E2E-encrypted messaging app. You can think of it as Signal with an IRC-like federated community layer.
- DMs and group chats are E2EE between devices using pairwise Double Ratchet sessions initiated via X3DH.
- Communities, which consist of a tree structure of channels, are hosted on federated user-run backends that we call keyservers. Communication is encrypted via TLS.
Learn more at [comm.app](https://comm.app)!
Repo structure
The client apps and keyserver layer are mostly written in Flow-typed Javascript. These projects are organized in a monorepo structure using Yarn Workspaces.
nativecontains the code for the React Native app, which supports both iOS and Android.keyservercontains the code for the Node/Express server. This includes the application server for the communities layer (the "keyserver"), and can be configured to servewebandlandingas well (see below).webcontains the code for the React desktop website.landingcontains the code for the Comm landing page.libcontains code that is shared across multiple other workspaces, including most of the Redux stack that is shared across native/web.
Comm's backend services are centralized and never touch plaintext data. They are written in Rust and deployed with Terraform to AWS. These projects are organized in a monorepo structure using Cargo Workspaces.
servicescontains the various different backend services.sharedcontains gRPC and protobuf definitions, and shared Rust libraries.
Dev environment
Note that it’s currently it’s only possible to contribute to this project from macOS. This is primarily due to iOS native development only being supported in macOS.
Check out our [doc on how to set up our dev environment](docs/nix_dev_env.md).
Related Skills
Pareto Mac
by ParetoSecurity - Serves as development guide for Mac security audit tool with build instructions, contribut
Ke Autonomous
Orchestrate an approved project through product analysis, architecture, implementation, automated testing, QA,
Horde Test Skill
Execute comprehensive testing plans using horde-swarm to dispatch parallel test agents across multiple test ca
Genai Security Demo
A chatbot implementation that demonstrates security defenses for generative AI. Created for the talk: Hacking
Security Engineer
Expert application security engineer specializing in threat modeling, vulnerability assessment, secure code re
Reactnative Expo AI Agent System Workflow
AI-powered development toolkit with 7 production agents for React Native/Expo mobile apps. Automates accessibi
Related Agents
Playwright Test Expert
Playwright E2E testing specialist for this monorepo. Use PROACTIVELY for creating E2E tests, test organization
Ba Analyst
Analyze features and document use cases with all scenarios for development and E2E testing
Flutter Testing
Use this agent when writing tests for Flutter applications. Specializes in unit tests, widget tests, integrati