Agent skill

Remote API Footguns

by maxrave-dev in maxrave-dev/kotlin-footguns

Remote API traps in Kotlin Multiplatform: Ktor clients, defensive parsing, Resource envelopes, OK responses that dropped your data, auth callbacks, retry backoff, downloads, websockets, clock sync.

GPL-3.0Auto-check passedMobile

Install Remote API Footguns

skills CLI
$ npx skills add maxrave-dev/kotlin-footguns --skill remote-api-footguns -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install maxrave-dev/kotlin-footguns remote-api-footguns --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/maxrave-dev/kotlin-footguns.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/remote-api-footguns .claude/skills/remote-api-footguns && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
remote-api-footguns
GitHub stars
1k
Token cost
~2.6k tokens
SKILL.md length
1,467 words
Files
18 (incl. references)
Skills in repo
10
Repo updated
First seen
Licence
GPL-3.0

At a glance

Remote API traps in Kotlin Multiplatform: Ktor clients, defensive parsing, Resource envelopes, OK responses that dropped your data, auth callbacks, retry backoff, downloads, websockets, clock sync.

  • Calls succeed but data never lands
  • SKILL.md covers Clients, parsing and response…, Auth, retries and account state and Realtime sessions and wire…
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Tasks that involve Cross-platform mobile apps

What it does

Remote API Footguns is an agent skill from maxrave-dev/kotlin-footguns. Remote API traps in Kotlin Multiplatform: Ktor clients, defensive parsing, Resource envelopes, OK responses that dropped your data, auth callbacks, retry backoff, downloads, websockets, clock sync. Use when calls succeed but data never lands.

Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 18 other files, including reference files (for example `references/api-ok-but-ignored.md`, `references/borrowed-wire-protocol-discipline.md` and `references/curl-logger-ktor-plugin.md`).

It sits in Mobile, covering Cross-platform mobile apps, Realtime and WebSockets and Android development. It works with Jetpack Compose and Kotlin. The repository describes itself as: Battle-tested agent skills mapping the footguns of Kotlin, Compose Multiplatform and the desktop JVM — mined from a production music app, not from documentation. The licence is GPL-3.0.

When your agent uses it

  • Calls succeed but data never lands
  • Tasks that involve Cross-platform mobile apps
  • Tasks that involve Realtime and WebSockets

Example prompts

  • “/remote-api-footguns”

What it can do on your machine

Read from SKILL.md and the folder at commit f5f0b49. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Remote API Footguns loads about 2.6k tokens when it runs, and up to ~36k if it reads all its reference files. Until then it costs about 66 tokens; SKILL.md has 1,467 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~2.6k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~36k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from maxrave-dev/kotlin-footguns at commit f5f0b49, republished under its GPL-3.0 licence (© maxrave-dev). 1,467 words, ~2,580 tokens.

Download SKILL.mdSave it as .claude/skills/remote-api-footguns/SKILL.md (or your agent's skills folder). This skill also uses 17 other files; get the full folder from GitHub.
name
remote-api-footguns
description
Remote API traps in Kotlin Multiplatform: Ktor clients, defensive parsing, Resource envelopes, OK responses that dropped your data, auth callbacks, retry backoff, downloads, websockets, clock sync. Use when calls succeed but data never lands.

Remote API footguns

17 traps mined from a production Kotlin and Compose Multiplatform app, one short file each under references/. Every file gives the working pattern, the Traps (the specific ways it fails in practice, and why), and a Verifying it section with commands to run against the user's own tree.

How to use this index. Match the code about to be written, or the symptom being chased, against the entries below: each names its topic and the symptom that should send you to it. Read every file that plausibly applies with the Read tool before proposing code or a fix; each is under 150 lines. Where a Verifying command names the source project's paths, substitute the equivalent paths in the user's tree.

Cross-references. A backticked trap name inside a file that is not listed here lives in a sibling area skill: glob ../*/references/<name>.md to open it.

Clients, parsing and response handling

  • ktor-kmp-client-architecture — A multiplatform HTTP stack where one expect/actual hands back the engine and each integration builds its own client from it — an instrumented client for API calls next to a deliberately bare one for bulk downloads, content negotiation registered per format, and a settings change that rebuilds the client rather than mutating it. Use when standing up networking in a Kotlin Multiplatform module, when a proxy setting appears to be ignored by some requests but not others, or when downloading a large file crawls and floods the log.
  • curl-logger-ktor-plugin — A client plugin that logs every outgoing request as one paste-ready curl command — POSIX single-quoting so a body full of quotes, dollars or newlines survives the shell, the whole command in a single log call, a redaction list, and a body read that does not consume a one-shot channel. Use when you want to replay a failing request outside the app, when a logged command will not run when pasted, or when reproducing a bug means rebuilding a request by hand from a log.
  • parallel-chunked-download — Splitting one file into N byte-range requests issued in parallel over a bare HTTP client, each chunk to its own temp file, merged in order, with progress reported through a channel-backed flow — plus when ranges are actually safe, how big a chunk should be, and why a failure retries one chunk rather than the file. Use when a large download is slower than the link allows, when a download restarts from zero after a hiccup, or when a progress bar sticks just short of full.
  • structural-defensive-parsing — Reading a response whose shape drifts — classify each field by the marker the payload itself declares rather than by its position, treat a filtering map as data loss and count what it drops, refuse to substitute a placeholder for a failed parse, and parse composite strings from their stable end. Use when a parser works in one locale and not another, when a list arrives shorter than the source shows, or when a made-up value turns up somewhere it was never entered.
  • response-to-domain-flow — The five stages a remote response passes through — transport model in a per-integration service module, a pure parser layer, a domain model, a result envelope, then collection — with the rule that each integration is its own module so one source's breakage cannot spread, and the placement rules that keep transport types out of screens. Use when adding a second remote source, when a UI file has started importing response classes, or when a screen shows a spinner forever after a response shape changed.
  • api-ok-but-ignored — A remote write can answer "ok" and still have discarded what you sent, saying so only in a secondary field riding along with the success. Model accepted-but-discarded as its own outcome, read that field on every write, and log a discard loudly. Reach for it when a submission reports success on every call and the data never appears on the other side.
  • unknown-not-a-valid-score — A parse-failure fallback must be a sentinel outside the legal domain, or expressed in the type — never a value the success path can also produce. Expose "not known" as its own question. Use when a field means two different things depending on where it came from, when a placeholder reaches the screen, or when a consumer cannot tell absent from measured.
  • enum-normalize-over-legacy-data — Reading a type marker the remote source declares for itself — normalizing before every comparison because locally stored rows from older app versions hold labels the app invented, treating null as "the source did not say" rather than as a default, exposing an is-known predicate so callers branch on knowledge, and correcting old rows by write-through instead of a migration. Use when a stored type column holds several spellings, when an item is treated as the wrong kind, or before adding a database migration to fix historical values.
Show full SKILL.md (676 more words)Show less

Auth, retries and account state

  • oauth-callback-not-through-nav — Deliver a returning auth callback's token straight to session state and let the login screen close itself by observing the stored session — routing the token through navigation pushes a second login screen and the post-login close peels the wrong one. Use when a browser-based login succeeds but the user is left staring at the login screen.
  • retry-needs-backoff-and-cap — Give every reconnect loop exponential backoff, a ceiling, a class of failures it refuses to retry, and a lifecycle gate — then give the feature a health signal, because one that fails silently stays broken for months. Use when a background connection drains the battery, when a bad credential produces an endless reconnect, or when an integration quietly stopped working.
  • login-state-fans-out-to-settings — Logging out must reset every setting that depended on being logged in, at the logout choke point itself — otherwise a gated switch stays on for a service you are no longer authenticated to and silently no-ops forever, or errors on every tick. Use when a feature toggle is stuck on, cannot be switched off, or keeps running against a credential that is gone.
  • nested-flag-settings-auto-disable — A child toggle gated by a parent condition must key its auto-disable effect on the parent's current value, grey out rather than hide when the gate is closed, and be gated again at the consumer — otherwise the child sticks ON with no way for the user to clear it. Use when a settings switch is stuck on, is greyed out while reading enabled, or keeps acting after its precondition is gone.

Realtime sessions and wire protocols

  • monotonic-clock-offset-sync — Estimate a peer's clock offset from ping/pong round trips — take the peer's own processing time out before halving, weight each sample against the best round trip seen, insist the local time source is monotonic, and fall back to the uncorrected value while the estimate is not yet usable. Use when several devices must agree what time it is before they can agree where a stream is, when a group drifts apart on a congested network, or when a position correction jumps after the device adjusts its clock.
  • protobuf-without-codegen-kmp — Speak protobuf from shared Kotlin by annotating ordinary data classes with field numbers instead of generating a code layer — with the encoder setting that makes the bytes match a generated encoder, the equality override a byte-array field needs, and the conformance test that pins the equivalence. Use when a schema-driven protocol has to work on every target rather than only the JVM, when encoding a message with an absent nested field throws, or when round-trip tests pass while real peers reject the frames.
  • borrowed-wire-protocol-discipline — Rules for implementing a protocol someone else defined — no renaming, no reordering, constants the schema omits read off the counterpart implementation rather than guessed, unknown message types decoded to null instead of thrown, and negotiated capabilities narrowed but never widened. Use when your client must interoperate with an implementation you do not control, when a connection opens and then never gets anywhere, or when a peer on a newer version breaks your session.
  • websocket-session-handshake-lifecycle — The order a WebSocket session has to be brought up and torn down — reader started before the first message because the answer comes back through it, the handshake settled on a deferred with a timeout, the close frame sent under a non-cancellable context, and an event buffer that suspends rather than drops. Use when a socket connects but the session never becomes usable, when a deliberate disconnect leaves the peer thinking you are still there, or when clients drift out of sync after a burst of traffic.
  • publish-a-snapshot-on-taking-the-role — Every publisher in a shared session is edge-triggered off a change, so a participant who was already running when they took the publishing role emits nothing and the group sits in silence — publish a full snapshot on becoming the source, and again when a new member arrives. Use when a session starts empty until someone touches the transport, when a late joiner sees nothing, or when your state watchers all look correct and the group still knows nothing.

© maxrave-dev, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 17 other files (references) in skills/remote-api-footguns of maxrave-dev/kotlin-footguns.

  • SKILL.md
  • references/api-ok-but-ignored.md
  • references/borrowed-wire-protocol-discipline.md
  • references/curl-logger-ktor-plugin.md
  • references/enum-normalize-over-legacy-data.md
  • references/ktor-kmp-client-architecture.md
  • references/login-state-fans-out-to-settings.md
  • references/monotonic-clock-offset-sync.md
  • references/nested-flag-settings-auto-disable.md
  • references/oauth-callback-not-through-nav.md
  • references/parallel-chunked-download.md
  • references/protobuf-without-codegen-kmp.md
  • references/publish-a-snapshot-on-taking-the-role.md
  • references/response-to-domain-flow.md
  • references/retry-needs-backoff-and-cap.md
  • references/structural-defensive-parsing.md
  • references/unknown-not-a-valid-score.md
  • references/websocket-session-handshake-lifecycle.md

Open the folder on GitHubat commit f5f0b49

Compare with similar skills

Remote API Footguns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Remote API Footguns compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Remote API Footguns this skillmaxrave-dev/kotlin-footguns1k—~2.6kAutomated safety check: PassGPL-3.0
Compose Multiplatform Patternsmonta-app/ocpp-emulator1795 repos~2kAutomated safety check: PassApache-2.0
Claude Android NinjaDrjacky/claude-android-ninja124—~5.2kAutomated safety check: PassApache-2.0
Ksafeioannisa/KSafe332—~17kAutomated safety check: PassApache-2.0
KtormonitorCosminMihuMDC/KtorMonitor254—~2.5kAutomated safety check: PassApache-2.0
Improve Code Coveragealexvanyo/composelife267—~1.1kAutomated safety check: PassApache-2.0

Similar skills

  • Compose Multiplatform Patterns

    monta-app/ocpp-emulator

    Compose Multiplatform and Jetpack Compose patterns for KMP projects — state management, navigation, theming, performance, and platform-specific UI.

    179 GitHub starsUsed in 5 repos~2k tokens
    MobileAuto-check passed
  • Claude Android Ninja

    Drjacky/claude-android-ninja

    Build and migrate Android apps with Kotlin, Jetpack Compose, MVVM, Hilt, Room 3 (KSP, SQLiteDriver, Flow/suspend DAOs), Navigation3, and multi-module Gradle.

    124 GitHub stars~5.2k tokensUpdated 8 days ago
    MobileAuto-check passed
  • Ksafe

    ioannisa/KSafe

    Required before any reply that touches KSafe (by ksafe(...), ksafe.get/put, :ksafe-compose, :ksafe-biometrics), even a 'can KSafe do X?' question or a one-line change that looks like plain Kotlin.

    332 GitHub stars~17k tokensUpdated 4 days ago
    MobileAuto-check passed
  • Ktormonitor

    CosminMihuMDC/KtorMonitor

    KtorMonitor is a Kotlin Multiplatform library for real-time HTTP traffic monitoring.

    254 GitHub stars~2.5k tokensUpdated 24 days ago
    MobileAuto-check passed
  • Improve Code Coverage

    alexvanyo/composelife

    Helps increment code coverage in this Kotlin Multiplatform project.

    267 GitHub stars~1.1k tokensUpdated today
    MobileAuto-check passed
  • Clerk Android

    geekskai/blog

    Implement Clerk authentication for native Android apps using Kotlin and Jetpack Compose with clerk-android source-guided patterns.

    103 GitHub starsUsed in 1 repo~2.1k tokens
    MobileAuto-check passed

More from maxrave-dev/kotlin-footguns

All 10 skills in this repo
  • Footgun Scan

    maxrave-dev/kotlin-footguns

    Scan a Kotlin or Compose Multiplatform diff for known footgun shapes and open the matching trap to confirm each hit.

    1k GitHub stars~518 tokensUpdated 12 days ago
    Auto-check passed
  • Desktop And Build Footguns

    maxrave-dev/kotlin-footguns

    Desktop JVM and build traps: JNA natives, bundling, memory, packaging, code signing, R8, deep links, Gradle and CI releases.

    1k GitHub stars~3.8k tokensUpdated 12 days ago
    Auto-check passed
  • Kmp Architecture Footguns

    maxrave-dev/kotlin-footguns

    Kotlin Multiplatform structure and language traps: module splits, expect/actual, Koin and ViewModel scoping, layers, version catalogs, erased overloads, Char and string-resource formatting limits.

    1k GitHub stars~4.4k tokensUpdated 12 days ago
    Auto-check passed
  • Media Playback Footguns

    maxrave-dev/kotlin-footguns

    Media player traps on Media3/ExoPlayer and desktop engines: crossfade, audio focus, fades, loudness, DSP, queues and shuffle, position restore, service lifecycle, group listening.

    1k GitHub stars~4.6k tokensUpdated 12 days ago
    Auto-check passed
  • State And Background Footguns

    maxrave-dev/kotlin-footguns

    Reactive state and background-work traps: StateFlow conflation, flatMapLatest, job lifecycles, ViewModel bases, WorkManager, backups, crash reporting, logging, Glance widgets.

    1k GitHub stars~3.9k tokensUpdated 12 days ago
    Auto-check passed
  • Compose Screens Footguns

    maxrave-dev/kotlin-footguns

    Compose screen and interaction traps: navigation, adaptive layout, window insets, pagers, toolbars, sheets, list drag and selection, sliders, text fields, settings UI, one-shot effects.

    1k GitHub stars~5.5k tokensUpdated 12 days ago
    Auto-check passed

Categories

Questions about Remote API Footguns

What does Remote API Footguns do?

Remote API traps in Kotlin Multiplatform: Ktor clients, defensive parsing, Resource envelopes, OK responses that dropped your data, auth callbacks, retry backoff, downloads, websockets, clock sync. Remote API Footguns is an agent skill from maxrave-dev/kotlin-footguns. Remote API traps in Kotlin Multiplatform: Ktor clients, defensive parsing, Resource envelopes, OK responses that dropped your data, auth callbacks, retry backoff, downloads, websockets, clock sync.

When should I use Remote API Footguns?

Remote API Footguns fits situations like: calls succeed but data never lands; tasks that involve Cross-platform mobile apps; tasks that involve Realtime and WebSockets.

How do I install Remote API Footguns in Claude Code?

Run `npx skills add maxrave-dev/kotlin-footguns --skill remote-api-footguns -a claude-code`. Or copy the skill folder (skills/remote-api-footguns in maxrave-dev/kotlin-footguns) into .claude/skills/remote-api-footguns in your project. Claude Code loads it when a task matches its description.

How do I install Remote API Footguns in Codex?

Run `npx skills add maxrave-dev/kotlin-footguns --skill remote-api-footguns -a codex`. Or copy the skill folder (skills/remote-api-footguns in maxrave-dev/kotlin-footguns) into .agents/skills/remote-api-footguns in your project. Codex loads it when a task matches its description.

Can I use Remote API Footguns in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add maxrave-dev/kotlin-footguns --skill remote-api-footguns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/remote-api-footguns, .gemini/skills/remote-api-footguns, .github/skills/remote-api-footguns and .opencode/skills/remote-api-footguns in your project.

What does Remote API Footguns need to run?

SKILL.md names no scripts, command-line tools or credentials: Remote API Footguns is instructions for the agent only.

Does Remote API Footguns access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Remote API Footguns safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Remote API Footguns use?

Remote API Footguns is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Remote API Footguns use?

About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 34k tokens, read only when the agent opens those files.

What are the alternatives to Remote API Footguns?

Skills that share tags, products or a category with Remote API Footguns: Compose Multiplatform Patterns (monta-app/ocpp-emulator, 179 stars), Claude Android Ninja (Drjacky/claude-android-ninja, 124 stars), Ksafe (ioannisa/KSafe, 332 stars) and Ktormonitor (CosminMihuMDC/KtorMonitor, 254 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Remote API Footguns?

maxrave-dev (a GitHub user) maintains it in maxrave-dev/kotlin-footguns, which has 1,010 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 25, 2026.

Source: maxrave-dev/kotlin-footguns on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.