Compose Multiplatform Patterns
monta-app/ocpp-emulator
Compose Multiplatform and Jetpack Compose patterns for KMP projects — state management, navigation, theming, performance, and platform-specific UI.
Remote API traps in Kotlin Multiplatform: Ktor clients, defensive parsing, Resource envelopes, OK responses that dropped your data, auth callbacks, retry backoff, downloads, websockets, clock sync.
$ npx skills add maxrave-dev/kotlin-footguns --skill remote-api-footguns -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install maxrave-dev/kotlin-footguns remote-api-footguns --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/maxrave-dev/kotlin-footguns.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/remote-api-footguns .claude/skills/remote-api-footguns && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "remote-api-footguns" agent skill from https://github.com/maxrave-dev/kotlin-footguns/tree/main/skills/remote-api-footguns into .claude/skills/remote-api-footguns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remote-api-footguns", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/maxrave-dev/kotlin-footguns/tree/main/skills/remote-api-footgunsType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add maxrave-dev/kotlin-footguns --skill remote-api-footguns -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install maxrave-dev/kotlin-footguns remote-api-footguns --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maxrave-dev/kotlin-footguns.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/remote-api-footguns .agents/skills/remote-api-footguns && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "remote-api-footguns" agent skill from https://github.com/maxrave-dev/kotlin-footguns/tree/main/skills/remote-api-footguns into .agents/skills/remote-api-footguns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remote-api-footguns", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add maxrave-dev/kotlin-footguns --skill remote-api-footguns -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install maxrave-dev/kotlin-footguns remote-api-footguns --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maxrave-dev/kotlin-footguns.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/remote-api-footguns .cursor/skills/remote-api-footguns && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "remote-api-footguns" agent skill from https://github.com/maxrave-dev/kotlin-footguns/tree/main/skills/remote-api-footguns into .cursor/skills/remote-api-footguns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remote-api-footguns", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/maxrave-dev/kotlin-footguns.git --path skills/remote-api-footguns--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add maxrave-dev/kotlin-footguns --skill remote-api-footguns -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install maxrave-dev/kotlin-footguns remote-api-footguns --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maxrave-dev/kotlin-footguns.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/remote-api-footguns .gemini/skills/remote-api-footguns && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "remote-api-footguns" agent skill from https://github.com/maxrave-dev/kotlin-footguns/tree/main/skills/remote-api-footguns into .gemini/skills/remote-api-footguns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remote-api-footguns", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install maxrave-dev/kotlin-footguns remote-api-footgunsInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add maxrave-dev/kotlin-footguns --skill remote-api-footguns -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/maxrave-dev/kotlin-footguns.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/remote-api-footguns .github/skills/remote-api-footguns && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "remote-api-footguns" agent skill from https://github.com/maxrave-dev/kotlin-footguns/tree/main/skills/remote-api-footguns into .github/skills/remote-api-footguns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remote-api-footguns", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add maxrave-dev/kotlin-footguns --skill remote-api-footguns -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install maxrave-dev/kotlin-footguns remote-api-footguns --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/maxrave-dev/kotlin-footguns.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/remote-api-footguns .opencode/skills/remote-api-footguns && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "remote-api-footguns" agent skill from https://github.com/maxrave-dev/kotlin-footguns/tree/main/skills/remote-api-footguns into .opencode/skills/remote-api-footguns/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "remote-api-footguns", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
remote-api-footgunsRemote API traps in Kotlin Multiplatform: Ktor clients, defensive parsing, Resource envelopes, OK responses that dropped your data, auth callbacks, retry backoff, downloads, websockets, clock sync.
Remote API Footguns is an agent skill from maxrave-dev/kotlin-footguns. Remote API traps in Kotlin Multiplatform: Ktor clients, defensive parsing, Resource envelopes, OK responses that dropped your data, auth callbacks, retry backoff, downloads, websockets, clock sync. Use when calls succeed but data never lands.
Its SKILL.md is about 2.6k tokens, which your agent loads only when the skill is triggered. The skill folder holds 18 other files, including reference files (for example `references/api-ok-but-ignored.md`, `references/borrowed-wire-protocol-discipline.md` and `references/curl-logger-ktor-plugin.md`).
It sits in Mobile, covering Cross-platform mobile apps, Realtime and WebSockets and Android development. It works with Jetpack Compose and Kotlin. The repository describes itself as: Battle-tested agent skills mapping the footguns of Kotlin, Compose Multiplatform and the desktop JVM — mined from a production music app, not from documentation. The licence is GPL-3.0.
Read from SKILL.md and the folder at commit f5f0b49. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Remote API Footguns loads about 2.6k tokens when it runs, and up to ~36k if it reads all its reference files. Until then it costs about 66 tokens; SKILL.md has 1,467 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from maxrave-dev/kotlin-footguns at commit f5f0b49, republished under its GPL-3.0 licence (© maxrave-dev). 1,467 words, ~2,580 tokens.
.claude/skills/remote-api-footguns/SKILL.md (or your agent's skills folder). This skill also uses 17 other files; get the full folder from GitHub.17 traps mined from a production Kotlin and Compose Multiplatform app, one short file each
under references/. Every file gives the working pattern, the Traps (the specific ways it
fails in practice, and why), and a Verifying it section with commands to run against the
user's own tree.
How to use this index. Match the code about to be written, or the symptom being chased, against the entries below: each names its topic and the symptom that should send you to it. Read every file that plausibly applies with the Read tool before proposing code or a fix; each is under 150 lines. Where a Verifying command names the source project's paths, substitute the equivalent paths in the user's tree.
Cross-references. A backticked trap name inside a file that is not listed here lives in a
sibling area skill: glob ../*/references/<name>.md to open it.
ktor-kmp-client-architecture — A multiplatform HTTP stack where one expect/actual hands back the engine and each integration builds its own client from it — an instrumented client for API calls next to a deliberately bare one for bulk downloads, content negotiation registered per format, and a settings change that rebuilds the client rather than mutating it. Use when standing up networking in a Kotlin Multiplatform module, when a proxy setting appears to be ignored by some requests but not others, or when downloading a large file crawls and floods the log.curl-logger-ktor-plugin — A client plugin that logs every outgoing request as one paste-ready curl command — POSIX single-quoting so a body full of quotes, dollars or newlines survives the shell, the whole command in a single log call, a redaction list, and a body read that does not consume a one-shot channel. Use when you want to replay a failing request outside the app, when a logged command will not run when pasted, or when reproducing a bug means rebuilding a request by hand from a log.parallel-chunked-download — Splitting one file into N byte-range requests issued in parallel over a bare HTTP client, each chunk to its own temp file, merged in order, with progress reported through a channel-backed flow — plus when ranges are actually safe, how big a chunk should be, and why a failure retries one chunk rather than the file. Use when a large download is slower than the link allows, when a download restarts from zero after a hiccup, or when a progress bar sticks just short of full.structural-defensive-parsing — Reading a response whose shape drifts — classify each field by the marker the payload itself declares rather than by its position, treat a filtering map as data loss and count what it drops, refuse to substitute a placeholder for a failed parse, and parse composite strings from their stable end. Use when a parser works in one locale and not another, when a list arrives shorter than the source shows, or when a made-up value turns up somewhere it was never entered.response-to-domain-flow — The five stages a remote response passes through — transport model in a per-integration service module, a pure parser layer, a domain model, a result envelope, then collection — with the rule that each integration is its own module so one source's breakage cannot spread, and the placement rules that keep transport types out of screens. Use when adding a second remote source, when a UI file has started importing response classes, or when a screen shows a spinner forever after a response shape changed.api-ok-but-ignored — A remote write can answer "ok" and still have discarded what you sent, saying so only in a secondary field riding along with the success. Model accepted-but-discarded as its own outcome, read that field on every write, and log a discard loudly. Reach for it when a submission reports success on every call and the data never appears on the other side.unknown-not-a-valid-score — A parse-failure fallback must be a sentinel outside the legal domain, or expressed in the type — never a value the success path can also produce. Expose "not known" as its own question. Use when a field means two different things depending on where it came from, when a placeholder reaches the screen, or when a consumer cannot tell absent from measured.enum-normalize-over-legacy-data — Reading a type marker the remote source declares for itself — normalizing before every comparison because locally stored rows from older app versions hold labels the app invented, treating null as "the source did not say" rather than as a default, exposing an is-known predicate so callers branch on knowledge, and correcting old rows by write-through instead of a migration. Use when a stored type column holds several spellings, when an item is treated as the wrong kind, or before adding a database migration to fix historical values.oauth-callback-not-through-nav — Deliver a returning auth callback's token straight to session state and let the login screen close itself by observing the stored session — routing the token through navigation pushes a second login screen and the post-login close peels the wrong one. Use when a browser-based login succeeds but the user is left staring at the login screen.retry-needs-backoff-and-cap — Give every reconnect loop exponential backoff, a ceiling, a class of failures it refuses to retry, and a lifecycle gate — then give the feature a health signal, because one that fails silently stays broken for months. Use when a background connection drains the battery, when a bad credential produces an endless reconnect, or when an integration quietly stopped working.login-state-fans-out-to-settings — Logging out must reset every setting that depended on being logged in, at the logout choke point itself — otherwise a gated switch stays on for a service you are no longer authenticated to and silently no-ops forever, or errors on every tick. Use when a feature toggle is stuck on, cannot be switched off, or keeps running against a credential that is gone.nested-flag-settings-auto-disable — A child toggle gated by a parent condition must key its auto-disable effect on the parent's current value, grey out rather than hide when the gate is closed, and be gated again at the consumer — otherwise the child sticks ON with no way for the user to clear it. Use when a settings switch is stuck on, is greyed out while reading enabled, or keeps acting after its precondition is gone.monotonic-clock-offset-sync — Estimate a peer's clock offset from ping/pong round trips — take the peer's own processing time out before halving, weight each sample against the best round trip seen, insist the local time source is monotonic, and fall back to the uncorrected value while the estimate is not yet usable. Use when several devices must agree what time it is before they can agree where a stream is, when a group drifts apart on a congested network, or when a position correction jumps after the device adjusts its clock.protobuf-without-codegen-kmp — Speak protobuf from shared Kotlin by annotating ordinary data classes with field numbers instead of generating a code layer — with the encoder setting that makes the bytes match a generated encoder, the equality override a byte-array field needs, and the conformance test that pins the equivalence. Use when a schema-driven protocol has to work on every target rather than only the JVM, when encoding a message with an absent nested field throws, or when round-trip tests pass while real peers reject the frames.borrowed-wire-protocol-discipline — Rules for implementing a protocol someone else defined — no renaming, no reordering, constants the schema omits read off the counterpart implementation rather than guessed, unknown message types decoded to null instead of thrown, and negotiated capabilities narrowed but never widened. Use when your client must interoperate with an implementation you do not control, when a connection opens and then never gets anywhere, or when a peer on a newer version breaks your session.websocket-session-handshake-lifecycle — The order a WebSocket session has to be brought up and torn down — reader started before the first message because the answer comes back through it, the handshake settled on a deferred with a timeout, the close frame sent under a non-cancellable context, and an event buffer that suspends rather than drops. Use when a socket connects but the session never becomes usable, when a deliberate disconnect leaves the peer thinking you are still there, or when clients drift out of sync after a burst of traffic.publish-a-snapshot-on-taking-the-role — Every publisher in a shared session is edge-triggered off a change, so a participant who was already running when they took the publishing role emits nothing and the group sits in silence — publish a full snapshot on becoming the source, and again when a new member arrives. Use when a session starts empty until someone touches the transport, when a late joiner sees nothing, or when your state watchers all look correct and the group still knows nothing.© maxrave-dev, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 17 other files (references) in skills/remote-api-footguns of maxrave-dev/kotlin-footguns.
Open the folder on GitHubat commit f5f0b49
Remote API Footguns next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Remote API Footguns this skillmaxrave-dev/kotlin-footguns | 1k | — | ~2.6k | Automated safety check: Pass | GPL-3.0 | |
| Compose Multiplatform Patternsmonta-app/ocpp-emulator | 179 | 5 repos | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Claude Android NinjaDrjacky/claude-android-ninja | 124 | — | ~5.2k | Automated safety check: Pass | Apache-2.0 | |
| Ksafeioannisa/KSafe | 332 | — | ~17k | Automated safety check: Pass | Apache-2.0 | |
| KtormonitorCosminMihuMDC/KtorMonitor | 254 | — | ~2.5k | Automated safety check: Pass | Apache-2.0 | |
| Improve Code Coveragealexvanyo/composelife | 267 | — | ~1.1k | Automated safety check: Pass | Apache-2.0 |
monta-app/ocpp-emulator
Compose Multiplatform and Jetpack Compose patterns for KMP projects — state management, navigation, theming, performance, and platform-specific UI.
Drjacky/claude-android-ninja
Build and migrate Android apps with Kotlin, Jetpack Compose, MVVM, Hilt, Room 3 (KSP, SQLiteDriver, Flow/suspend DAOs), Navigation3, and multi-module Gradle.
ioannisa/KSafe
Required before any reply that touches KSafe (by ksafe(...), ksafe.get/put, :ksafe-compose, :ksafe-biometrics), even a 'can KSafe do X?' question or a one-line change that looks like plain Kotlin.
CosminMihuMDC/KtorMonitor
KtorMonitor is a Kotlin Multiplatform library for real-time HTTP traffic monitoring.
alexvanyo/composelife
Helps increment code coverage in this Kotlin Multiplatform project.
geekskai/blog
Implement Clerk authentication for native Android apps using Kotlin and Jetpack Compose with clerk-android source-guided patterns.
maxrave-dev/kotlin-footguns
Scan a Kotlin or Compose Multiplatform diff for known footgun shapes and open the matching trap to confirm each hit.
maxrave-dev/kotlin-footguns
Desktop JVM and build traps: JNA natives, bundling, memory, packaging, code signing, R8, deep links, Gradle and CI releases.
maxrave-dev/kotlin-footguns
Kotlin Multiplatform structure and language traps: module splits, expect/actual, Koin and ViewModel scoping, layers, version catalogs, erased overloads, Char and string-resource formatting limits.
maxrave-dev/kotlin-footguns
Media player traps on Media3/ExoPlayer and desktop engines: crossfade, audio focus, fades, loudness, DSP, queues and shuffle, position restore, service lifecycle, group listening.
maxrave-dev/kotlin-footguns
Reactive state and background-work traps: StateFlow conflation, flatMapLatest, job lifecycles, ViewModel bases, WorkManager, backups, crash reporting, logging, Glance widgets.
maxrave-dev/kotlin-footguns
Compose screen and interaction traps: navigation, adaptive layout, window insets, pagers, toolbars, sheets, list drag and selection, sliders, text fields, settings UI, one-shot effects.
Works with
Categories
Remote API traps in Kotlin Multiplatform: Ktor clients, defensive parsing, Resource envelopes, OK responses that dropped your data, auth callbacks, retry backoff, downloads, websockets, clock sync. Remote API Footguns is an agent skill from maxrave-dev/kotlin-footguns. Remote API traps in Kotlin Multiplatform: Ktor clients, defensive parsing, Resource envelopes, OK responses that dropped your data, auth callbacks, retry backoff, downloads, websockets, clock sync.
Remote API Footguns fits situations like: calls succeed but data never lands; tasks that involve Cross-platform mobile apps; tasks that involve Realtime and WebSockets.
Run `npx skills add maxrave-dev/kotlin-footguns --skill remote-api-footguns -a claude-code`. Or copy the skill folder (skills/remote-api-footguns in maxrave-dev/kotlin-footguns) into .claude/skills/remote-api-footguns in your project. Claude Code loads it when a task matches its description.
Run `npx skills add maxrave-dev/kotlin-footguns --skill remote-api-footguns -a codex`. Or copy the skill folder (skills/remote-api-footguns in maxrave-dev/kotlin-footguns) into .agents/skills/remote-api-footguns in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add maxrave-dev/kotlin-footguns --skill remote-api-footguns -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/remote-api-footguns, .gemini/skills/remote-api-footguns, .github/skills/remote-api-footguns and .opencode/skills/remote-api-footguns in your project.
SKILL.md names no scripts, command-line tools or credentials: Remote API Footguns is instructions for the agent only.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Remote API Footguns is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.6k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 34k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Remote API Footguns: Compose Multiplatform Patterns (monta-app/ocpp-emulator, 179 stars), Claude Android Ninja (Drjacky/claude-android-ninja, 124 stars), Ksafe (ioannisa/KSafe, 332 stars) and Ktormonitor (CosminMihuMDC/KtorMonitor, 254 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
maxrave-dev (a GitHub user) maintains it in maxrave-dev/kotlin-footguns, which has 1,010 GitHub stars. The repository holds 10 skills in this directory. The repository was last updated on September 25, 2026.
Source: maxrave-dev/kotlin-footguns on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.