Agent skill

Footgun Scan

by maxrave-dev in maxrave-dev/kotlin-footguns

Scan a Kotlin or Compose Multiplatform diff for known footgun shapes and open the matching trap to confirm each hit.

GPL-3.0Auto-check passedMobile

Install Footgun Scan

skills CLI
$ npx skills add maxrave-dev/kotlin-footguns --skill footgun-scan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install maxrave-dev/kotlin-footguns footgun-scan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/maxrave-dev/kotlin-footguns.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/footgun-scan .claude/skills/footgun-scan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
footgun-scan
GitHub stars
1.1k
Token cost
~518 tokens
SKILL.md length
257 words
Files
2 (incl. scripts)
Skills in repo
10
Repo updated
First seen
Licence
GPL-3.0

At a glance

Scan a Kotlin or Compose Multiplatform diff for known footgun shapes and open the matching trap to confirm each hit.

  • Works in 3 steps: Read the trap file the hit points to… → Read the code around the hit and decide,… → Report each confirmed problem with the…
  • Tasks that involve Android development
  • SKILL.md covers Run it, Triage every hit and When the scanner cannot run
  • Runs Python scripts from its folder; calls python3

What it does

Footgun Scan is an agent skill from maxrave-dev/kotlin-footguns. Scan a Kotlin or Compose Multiplatform diff for known footgun shapes and open the matching trap to confirm each hit. Use before committing, when reviewing a Kotlin change, or to audit a codebase.

Its SKILL.md is about 520 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including scripts (for example `scripts/scan.py`).

It sits in Mobile, covering Android development. It works with Kotlin and Jetpack Compose. The repository describes itself as: Battle-tested agent skills mapping the footguns of Kotlin, Compose Multiplatform and the desktop JVM — mined from a production music app, not from documentation. The licence is GPL-3.0.

When your agent uses it

  • Tasks that involve Android development

Example prompts

  • “/footgun-scan”

Requirements

  • Python 3

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Read the trap file the hit points to (the -> path).
  2. Read the code around the hit and decide, by the trap's own conditions, whether it applies.
  3. Report each confirmed problem with the trap's fix and its Verifying step. List dismissed hits one

What it can do on your machine

Read from SKILL.md and the folder at commit f5f0b49. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Python), which the agent can run.

    Shell commands in SKILL.md call:

    • python3

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Footgun Scan loads about 518 tokens when it runs. Until then it costs about 52 tokens; SKILL.md has 257 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~52
When it runs · the whole SKILL.md, loaded when a task matches
~518

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from maxrave-dev/kotlin-footguns at commit f5f0b49, republished under its GPL-3.0 licence (© maxrave-dev). 257 words, ~518 tokens.

Download SKILL.mdSave it as .claude/skills/footgun-scan/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
footgun-scan
description
Scan a Kotlin or Compose Multiplatform diff for known footgun shapes and open the matching trap to confirm each hit. Use before committing, when reviewing a Kotlin change, or to audit a codebase.

Footgun scan

scripts/scan.py matches 32 patterns against the lines a change adds. Each pattern is tied to one trap file in the kotlin-footguns area skills. It finds shapes, not bugs: every hit needs the trap's judgment before it becomes a finding.

Run it

From inside the user's git repository, with this skill's base directory as <skill>:

bash
python3 <skill>/scripts/scan.py                     # lines added in the working tree and index since HEAD
python3 <skill>/scripts/scan.py --base origin/main  # lines added on this branch since it left main
python3 <skill>/scripts/scan.py --all src/          # every line under a path: an audit, and noisier

Pick the scope from the request. Uncommitted work takes the default. A branch or pull request takes --base with its target branch. "Audit the codebase" takes --all, narrowed to the paths that matter. For a pre-commit hook or CI step, add --fail to exit 1 on any likely hit.

Triage every hit

  1. Read the trap file the hit points to (the -> path).
  2. Read the code around the hit and decide, by the trap's own conditions, whether it applies. A likely hit is wrong unless the exception the trap names holds. A look hit is a place the trap says to inspect before trusting it.
  3. Report each confirmed problem with the trap's fix and its Verifying step. List dismissed hits one line each with the reason, for example "column is NOT NULL" or "the fade goes to black".

Hits of one detector in one file are grouped: triage the group once, then check the listed lines for exceptions.

When the scanner cannot run

It needs python3 and git. Without them, read scripts/scan.py: the DETECTORS list gives each pattern, its message and its trap. Run those patterns with the Grep tool over the changed files and triage the same way.

© maxrave-dev, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (scripts) in skills/footgun-scan of maxrave-dev/kotlin-footguns.

  • SKILL.md
  • scripts/scan.py

Open the folder on GitHubat commit f5f0b49

Compare with similar skills

Footgun Scan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Footgun Scan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Footgun Scan this skillmaxrave-dev/kotlin-footguns1.1k—~518Automated safety check: PassGPL-3.0
Compose Multiplatform Patternsmonta-app/ocpp-emulator1805 repos~2kAutomated safety check: PassApache-2.0
Android Developmentdpconde/claude-android-skill337—~1.7kAutomated safety check: PassMIT
Diagnosing Compose StabilityrosuH/EasyWatermark1.9k1 repos~3.3kAutomated safety check: PassApache-2.0
Claude Android NinjaDrjacky/claude-android-ninja124—~5.2kAutomated safety check: PassApache-2.0
Jetpack Composedarriousliu/PiPixiv263—~1.5kAutomated safety check: PassApache-2.0

Similar skills

  • Compose Multiplatform Patterns

    monta-app/ocpp-emulator

    Compose Multiplatform and Jetpack Compose patterns for KMP projects — state management, navigation, theming, performance, and platform-specific UI.

    180 GitHub starsUsed in 5 repos~2k tokens
    MobileAuto-check passed
  • Android Development

    dpconde/claude-android-skill

    Create production-quality Android applications following Google's official architecture guidance and NowInAndroid best practices.

    337 GitHub stars~1.7k tokensUpdated 10 mo ago
    MobileAuto-check passed
  • Diagnosing Compose Stability

    rosuH/EasyWatermark

    A skill your agent uses to diagnose Jetpack Compose stability problems by enabling and reading the Compose Compiler Reports (classes.txt, composables.txt, composables.csv, module.json).

    1.9k GitHub starsUsed in 1 repo~3.3k tokens
    MobileAuto-check passed
  • Claude Android Ninja

    Drjacky/claude-android-ninja

    Build and migrate Android apps with Kotlin, Jetpack Compose, MVVM, Hilt, Room 3 (KSP, SQLiteDriver, Flow/suspend DAOs), Navigation3, and multi-module Gradle.

    124 GitHub stars~5.2k tokensUpdated 10 days ago
    MobileAuto-check passed
  • Jetpack Compose

    darriousliu/PiPixiv

    Jetpack Compose expert skill for Android UI development. An agent skill from darriousliu/PiPixiv.

    263 GitHub stars~1.5k tokensUpdated yesterday
    MobileAuto-check passed
  • Coding Style

    sk2andy/candy-browser

    Apply Candy Browser's project-specific Kotlin, Jetpack Compose, Android/WebView, testing, and generator conventions.

    508 GitHub stars~548 tokensUpdated yesterday
    MobileAuto-check passed

More from maxrave-dev/kotlin-footguns

All 10 skills in this repo
  • Desktop And Build Footguns

    maxrave-dev/kotlin-footguns

    Desktop JVM and build traps: JNA natives, bundling, memory, packaging, code signing, R8, deep links, Gradle and CI releases.

    1.1k GitHub stars~3.8k tokensUpdated 14 days ago
    Auto-check passed
  • Kmp Architecture Footguns

    maxrave-dev/kotlin-footguns

    Kotlin Multiplatform structure and language traps: module splits, expect/actual, Koin and ViewModel scoping, layers, version catalogs, erased overloads, Char and string-resource formatting limits.

    1.1k GitHub stars~4.4k tokensUpdated 14 days ago
    Auto-check passed
  • Media Playback Footguns

    maxrave-dev/kotlin-footguns

    Media player traps on Media3/ExoPlayer and desktop engines: crossfade, audio focus, fades, loudness, DSP, queues and shuffle, position restore, service lifecycle, group listening.

    1.1k GitHub stars~4.6k tokensUpdated 14 days ago
    Auto-check passed
  • Remote API Footguns

    maxrave-dev/kotlin-footguns

    Remote API traps in Kotlin Multiplatform: Ktor clients, defensive parsing, Resource envelopes, OK responses that dropped your data, auth callbacks, retry backoff, downloads, websockets, clock sync.

    1.1k GitHub stars~2.6k tokensUpdated 14 days ago
    Auto-check passed
  • State And Background Footguns

    maxrave-dev/kotlin-footguns

    Reactive state and background-work traps: StateFlow conflation, flatMapLatest, job lifecycles, ViewModel bases, WorkManager, backups, crash reporting, logging, Glance widgets.

    1.1k GitHub stars~3.9k tokensUpdated 14 days ago
    Auto-check passed
  • Compose Screens Footguns

    maxrave-dev/kotlin-footguns

    Compose screen and interaction traps: navigation, adaptive layout, window insets, pagers, toolbars, sheets, list drag and selection, sliders, text fields, settings UI, one-shot effects.

    1.1k GitHub stars~5.5k tokensUpdated 14 days ago
    Auto-check passed

Categories

Questions about Footgun Scan

What does Footgun Scan do?

Scan a Kotlin or Compose Multiplatform diff for known footgun shapes and open the matching trap to confirm each hit. Footgun Scan is an agent skill from maxrave-dev/kotlin-footguns. Scan a Kotlin or Compose Multiplatform diff for known footgun shapes and open the matching trap to confirm each hit.

When should I use Footgun Scan?

Footgun Scan fits situations like: tasks that involve Android development.

How do I install Footgun Scan in Claude Code?

Run `npx skills add maxrave-dev/kotlin-footguns --skill footgun-scan -a claude-code`. Or copy the skill folder (skills/footgun-scan in maxrave-dev/kotlin-footguns) into .claude/skills/footgun-scan in your project. Claude Code loads it when a task matches its description.

How do I install Footgun Scan in Codex?

Run `npx skills add maxrave-dev/kotlin-footguns --skill footgun-scan -a codex`. Or copy the skill folder (skills/footgun-scan in maxrave-dev/kotlin-footguns) into .agents/skills/footgun-scan in your project. Codex loads it when a task matches its description.

Can I use Footgun Scan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add maxrave-dev/kotlin-footguns --skill footgun-scan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/footgun-scan, .gemini/skills/footgun-scan, .github/skills/footgun-scan and .opencode/skills/footgun-scan in your project.

What does Footgun Scan need to run?

Going by SKILL.md and its folder, Footgun Scan needs Python for the scripts in its folder and the command-line tools its instructions call (python3). Our summary lists: Python 3.

Does Footgun Scan access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Footgun Scan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Footgun Scan use?

Footgun Scan is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Footgun Scan use?

About 518 tokens (SKILL.md is roughly 2.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Footgun Scan?

Skills that share tags, products or a category with Footgun Scan: Compose Multiplatform Patterns (monta-app/ocpp-emulator, 180 stars), Android Development (dpconde/claude-android-skill, 337 stars), Diagnosing Compose Stability (rosuH/EasyWatermark, 1.9k stars) and Claude Android Ninja (Drjacky/claude-android-ninja, 124 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Footgun Scan?

maxrave-dev (a GitHub user) maintains it in maxrave-dev/kotlin-footguns, which has 1,085 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 25, 2026.

Source: maxrave-dev/kotlin-footguns on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.