Agent skill

Kotlin Rules

by softspark in softspark/ai-toolkit

Kotlin coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit.

Apache-2.0Auto-check passedMobile

Install Kotlin Rules

skills CLI
$ npx skills add softspark/ai-toolkit --skill kotlin-rules -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install softspark/ai-toolkit kotlin-rules --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/app/skills/kotlin-rules .claude/skills/kotlin-rules && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
kotlin-rules
GitHub stars
179
Token cost
~3.2k tokens
SKILL.md length
1,513 words
Files
1
Skills in repo
112
Repo updated
First seen
Licence
Apache-2.0

At a glance

Kotlin coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit.

  • Tasks that involve Android development
  • SKILL.md covers Naming, Null Safety, Data Classes and Functions, plus 21 more sections
  • Calls gradle

What it does

Kotlin Rules is an agent skill from softspark/ai-toolkit. Kotlin coding rules: style, patterns, security, testing. Triggers: .kt, .kts, build.gradle.kts, Ktor, Jetpack Compose, coroutines, kotlinx.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Mobile, covering Android development. It works with Kotlin, Jetpack Compose and Gradle. The repository describes itself as: Professional-grade AI coding toolkit: 94 skills, 44 agents, multi-platform (Claude, Cursor, Windsurf, Copilot, Gemini, Cline, Roo Code, Aider, Augment, Antigravity, Codex CLI… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Android development

Example prompts

  • “/kotlin-rules”

Requirements

  • Pre-approved tools (allowed-tools): Read

What it can do on your machine

Read from SKILL.md and the folder at commit d64db2b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • gradle

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Kotlin Rules loads about 3.2k tokens when it runs. Until then it costs about 38 tokens; SKILL.md has 1,513 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~38
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from softspark/ai-toolkit at commit d64db2b, republished under its Apache-2.0 licence (© softspark). 1,513 words, ~3,231 tokens.

Download SKILL.mdSave it as .claude/skills/kotlin-rules/SKILL.md (or your agent's skills folder).
name
kotlin-rules
description
Kotlin coding rules: style, patterns, security, testing. Triggers: .kt, .kts, build.gradle.kts, Ktor, Jetpack Compose, coroutines, kotlinx.
allowed-tools
Read
effort
medium
user-invocable
false

Kotlin Rules

These rules come from app/rules/kotlin/ in ai-toolkit. They cover the project's standards for coding style, frameworks, patterns, security, and testing in Kotlin. Apply them when writing or reviewing Kotlin code.

Kotlin Coding Style

Naming

  • PascalCase: classes, interfaces, objects, type aliases, enum entries.
  • camelCase: functions, properties, local variables, parameters.
  • UPPER_SNAKE: compile-time constants (const val), top-level val constants.
  • Backing properties: prefix with _ (private val _items, val items: List<T>).
  • Package names: lowercase, no underscores (com.company.project.feature).

Null Safety

  • Use nullable types only when nullability is semantically meaningful.
  • Prefer ?.let { }, ?: (Elvis), and safe calls over !!.
  • Never use !! except in tests or when null is truly impossible.
  • Use requireNotNull() and require() for preconditions at public API boundaries.
  • Use checkNotNull() and check() for state assertions.

Data Classes

  • Use data class for DTOs, value objects, and state containers.
  • Use copy() for immutable updates. Avoid mutable var in data classes.
  • Use sealed class / sealed interface for restricted hierarchies.
  • Use value class (inline class) for type-safe wrappers with zero overhead.
  • Use object for singletons and namespace-like utility groupings.

Functions

  • Use expression body (= expr) for single-expression functions.
  • Use named arguments for functions with >2 parameters of the same type.
  • Use default parameter values instead of overloaded functions.
  • Use extension functions to add behavior without inheritance.
  • Use suspend functions for async operations, not callbacks.

Collections

  • Prefer listOf, mapOf, setOf (immutable) over mutableListOf.
  • Use collection operators: map, filter, groupBy, associate.
  • Use sequence {} for lazy evaluation on large collections.
  • Prefer firstOrNull() over first() for safe access.
  • Use destructuring: val (name, age) = user.

Scope Functions

  • let: null-safe chaining and local scoping.
  • apply: configure object after creation.
  • also: side effects (logging, validation) in chains.
  • run: compute a result using receiver's context.
  • with: multiple operations on an object without chaining.
  • Avoid nesting scope functions more than 1 level deep.

Formatting

  • Use ktlint or detekt for automated formatting and linting.
  • Use trailing commas in multi-line parameter/argument lists.
  • Max line length: 120 characters (Kotlin convention).
  • Use when expression over if-else chains for 3+ branches.

Kotlin Frameworks

Ktor (Server)

  • Use routing DSL: routing { get("/users") { call.respond(users) } }.
  • Use install() for plugins: ContentNegotiation, Authentication, CORS.
  • Use call.receive<T>() for typed request body parsing with kotlinx.serialization.
  • Use StatusPages plugin for centralized error handling.
  • Use Routing with nested route("/api/v1") { } blocks for URL grouping.

Ktor (Client)

  • Use HttpClient with engine configuration (CIO, OkHttp, Apache).
  • Use install(ContentNegotiation) { json() } for JSON serialization.
  • Use client.get<T>() with reified type for typed responses.
  • Use HttpTimeout plugin for connection and request timeouts.
  • Close HttpClient when done or use DI lifecycle management.

Spring Boot (Kotlin)

  • Use constructor injection (Kotlin classes are final by default).
  • Apply kotlin-spring plugin for open classes (required for proxying).
  • Use @ConfigurationProperties with data classes for typed config.
  • Use WebFlux with coroutines: coRouter { } and suspend handler functions.
  • Use spring-boot-starter-validation with @Valid on Kotlin data classes.

Exposed (ORM)

  • Use DSL API for type-safe queries: Users.select { Users.name eq "Ada" }.
  • Use DAO API for Active Record-style: User.find { Users.age greaterEq 18 }.
  • Wrap database operations in transaction { } blocks.
  • Use SchemaUtils.create(Users) for schema management in development.

kotlinx.serialization

  • Use @Serializable annotation on data classes for compile-time serialization.
  • Use @SerialName("field_name") for JSON field name mapping.
  • Use Json { ignoreUnknownKeys = true } for lenient deserialization.
  • Use polymorphic serialization with sealed class and @Polymorphic.
  • Prefer kotlinx.serialization over Jackson for pure Kotlin projects.

Koin (DI)

  • Define modules: module { single { UserService(get()) } }.
  • Use by inject<T>() for lazy injection in Android/Ktor.
  • Use factory { } for new instance per injection, single { } for singleton.
  • Use checkModules() in tests to verify DI graph completeness.

Compose (Multiplatform UI)

  • Use @Composable functions for UI components. Keep them stateless.
  • Use remember { } and mutableStateOf() for local state.
  • Hoist state to callers: pass state down, events up.
  • Use LaunchedEffect for side effects tied to composition lifecycle.
  • Use ViewModel with StateFlow for screen-level state management.

Kotlin Patterns

Error Handling

  • Use Result<T> for operations that can fail without exceptions.
  • Use runCatching { } to wrap exception-throwing code into Result.
  • Use sealed class hierarchies for domain errors: sealed class AppError.
  • Prefer fold(), getOrElse(), getOrNull() over getOrThrow().
  • Use require() / check() for preconditions; they throw IllegalArgumentException / IllegalStateException.

Coroutines

  • Use suspend functions for sequential async operations.
  • Use coroutineScope { } for structured concurrency with parallel work.
  • Use async { } + await() for concurrent independent operations.
  • Use supervisorScope { } when child failures should not cancel siblings.
  • Use withContext(Dispatchers.IO) for blocking I/O in coroutine context.
  • Use flow { } for cold asynchronous streams. Collect in lifecycle-aware scope.

Flow Patterns

  • Use stateIn() and shareIn() to convert cold flows to hot shared state.
  • Use combine() to merge multiple flows into derived state.
  • Use flatMapLatest for search-as-you-type patterns (cancel previous).
  • Use catch { } operator for upstream error handling in flows.
  • Use flowOn(Dispatchers.IO) to shift upstream execution context.

Sealed Hierarchies

  • Use sealed interface over sealed class when no shared state is needed.
  • Use when expressions exhaustively on sealed types (compiler-enforced).
  • Combine sealed types with data classes for typed state machines.
  • Use sealed hierarchies for API responses: Success<T>, Error, Loading.

Delegation

  • Use by lazy { } for thread-safe lazy initialization.
  • Use by map for delegated properties backed by a Map.
  • Use class delegation (class Foo : Bar by impl) to favor composition.
  • Use observable / vetoable delegates for reactive property changes.

Builder Patterns

  • Use DSL-style builders with @DslMarker annotation to prevent scope leakage.
  • Use trailing lambda syntax for configuration blocks.
  • Use apply { } for inline object configuration without a dedicated builder.
  • Use buildList { }, buildMap { }, buildString { } for collection construction.

Anti-Patterns

  • Overusing !!: masks null-safety guarantees. Use safe calls or require.
  • Nesting scope functions: foo.let { it.also { ... }.run { } } -- flatten logic.
  • Blocking the main thread: use withContext(Dispatchers.IO) for I/O.
  • Using GlobalScope.launch: leaks coroutines. Use structured concurrency.
  • Mutable shared state without synchronization: use Mutex or StateFlow.
Show full SKILL.md (605 more words)Show less

Kotlin Security

Input Validation

  • Validate all inputs at API boundaries using Bean Validation or manual checks.
  • Use require() for argument validation: require(age > 0) { "Age must be positive" }.
  • Use data class init blocks for domain validation on construction.
  • Never trust client-provided IDs. Verify resource ownership server-side.
  • Sanitize strings before using in HTML, SQL, or shell commands.

Null Safety as Security

  • Kotlin's null safety prevents null pointer exceptions. Do not circumvent with !!.
  • Use ?. and ?: chains for safe fallback values at boundaries.
  • Treat Java interop as untrusted: platform types can still be null.
  • Use @Nullable / @NotNull annotations on Java code consumed by Kotlin.

SQL Injection

  • Use Exposed DSL or JPA with parameterized queries. Never concatenate input.
  • Use PreparedStatement if writing raw JDBC.
  • Use CriteriaBuilder or Exposed conditions for dynamic query construction.
  • Audit @Query(nativeQuery = true) for parameter interpolation risks.

Serialization

  • Use kotlinx.serialization with @Serializable for compile-time safety.
  • Use Json { ignoreUnknownKeys = true } but validate after deserialization.
  • Never use Java ObjectInputStream for deserialization (RCE risk).
  • Restrict polymorphic deserialization to known sealed class subtypes.

Authentication

  • Use Spring Security or Ktor Authentication plugin. Do not roll your own.
  • Hash passwords with BCrypt or Argon2. Never store plaintext.
  • Use short-lived JWTs (15 min) with refresh token rotation.
  • Validate JWT signature, issuer, audience, and expiration on every request.

Coroutine Security

  • Use withTimeout() to prevent unbounded coroutine execution (DoS vector).
  • Use Mutex for critical sections. Do not use synchronized in suspend functions.
  • Propagate security context through CoroutineContext elements.
  • Cancel coroutine scopes on authentication failure or session expiry.

Secrets Management

  • Use environment variables or Vault for secrets. Never hardcode.
  • Use @ConfigurationProperties with injected secrets, not string literals.
  • Never log request headers containing Authorization tokens.
  • Use separate configuration profiles for dev/staging/prod secrets.

Dependencies

  • Use Dependabot or Renovate for automated dependency updates.
  • Run OWASP Dependency-Check or Gradle dependencyCheckAnalyze.
  • Audit transitive dependencies with gradle dependencies.
  • Pin dependency versions. Avoid dynamic versions like 1.+.

Logging

  • Use parameterized logging: logger.info("User {} logged in", userId).
  • Never log passwords, tokens, or PII.
  • Sanitize user input before logging to prevent log injection.
  • Use structured logging (JSON) for machine-parseable audit trails.

Kotlin Testing

Framework

  • Use JUnit 5 as the test runner.
  • Use Kotest for Kotlin-idiomatic BDD-style testing (alternative).
  • Use MockK for mocking (Kotlin-native, supports coroutines).
  • Use Testcontainers for integration tests with external services.

File Naming

  • Test files: FooTest.kt in src/test/kotlin/ mirroring source package.
  • Integration tests: FooIT.kt or use @Tag("integration").
  • Use @Nested inner classes to group related test cases.

Structure

  • Use @DisplayName for human-readable test names.
  • Use backtick function names for readable test names: `returns 404 when user not found`.
  • Use @BeforeEach for per-test setup. Avoid shared mutable state.
  • Use @ParameterizedTest with @MethodSource for table-driven tests.

MockK

  • Use mockk<UserRepository>() to create mocks.
  • Use every { mock.find(any()) } returns user for stubbing.
  • Use coEvery { ... } and coVerify { ... } for coroutine mocking.
  • Use spyk() for partial mocks on real objects.
  • Use slot<T>() and captured to inspect arguments.
  • Clear mocks in @AfterEach to prevent state leakage.

Coroutine Testing

  • Use runTest { } from kotlinx-coroutines-test for coroutine tests.
  • Use TestDispatcher to control coroutine execution timing.
  • Use advanceUntilIdle() to complete all pending coroutines.
  • Use turbine library for testing Flow emissions.

Assertions

  • Use AssertJ or Kotest assertions for fluent, readable checks.
  • Use shouldBe, shouldThrow, shouldContain (Kotest matchers).
  • Use assertSoftly { } to collect multiple assertion failures.
  • Use assertThrows<FooException> { ... } for exception testing.

Test Data

  • Use factory functions for test data: fun aUser(name: String = "Ada") = User(...).
  • Use default parameters for minimal test data setup.
  • Use copy() on data classes for variations of base test objects.
  • Use faker library for realistic test data generation.

Spring Integration

  • Use @SpringBootTest with @AutoConfigureMockMvc for API tests.
  • Use @WebMvcTest for controller-only tests (faster).
  • Use @MockkBean instead of @MockBean for MockK integration.
  • Use @Transactional on test classes for automatic rollback.

© softspark, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in app/skills/kotlin-rules of softspark/ai-toolkit.

Open the folder on GitHubat commit d64db2b

Compare with similar skills

Kotlin Rules next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Kotlin Rules compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Kotlin Rules this skillsoftspark/ai-toolkit179—~3.2kAutomated safety check: PassApache-2.0
Android Developmentdpconde/claude-android-skill336—~1.7kAutomated safety check: PassMIT
Diagnosing Compose StabilityrosuH/EasyWatermark1.9k1 repos~3.3kAutomated safety check: PassApache-2.0
Claude Android NinjaDrjacky/claude-android-ninja124—~5.2kAutomated safety check: PassApache-2.0
Desktop And Build Footgunsmaxrave-dev/kotlin-footguns1k—~3.8kAutomated safety check: PassGPL-3.0
Flake Triageyschimke/compose-ai-tools117—~1.5kAutomated safety check: PassApache-2.0

Similar skills

  • Android Development

    dpconde/claude-android-skill

    Create production-quality Android applications following Google's official architecture guidance and NowInAndroid best practices.

    336 GitHub stars~1.7k tokensUpdated 10 mo ago
    MobileAuto-check passed
  • Diagnosing Compose Stability

    rosuH/EasyWatermark

    A skill your agent uses to diagnose Jetpack Compose stability problems by enabling and reading the Compose Compiler Reports (classes.txt, composables.txt, composables.csv, module.json).

    1.9k GitHub starsUsed in 1 repo~3.3k tokens
    MobileAuto-check passed
  • Claude Android Ninja

    Drjacky/claude-android-ninja

    Build and migrate Android apps with Kotlin, Jetpack Compose, MVVM, Hilt, Room 3 (KSP, SQLiteDriver, Flow/suspend DAOs), Navigation3, and multi-module Gradle.

    124 GitHub stars~5.2k tokensUpdated 8 days ago
    MobileAuto-check passed
  • Desktop And Build Footguns

    maxrave-dev/kotlin-footguns

    Desktop JVM and build traps: JNA natives, bundling, memory, packaging, code signing, R8, deep links, Gradle and CI releases.

    1k GitHub stars~3.8k tokensUpdated 13 days ago
    MobileAuto-check passed
  • Flake Triage

    yschimke/compose-ai-tools

    Decide whether a preview the visual-diff bot flagged actually regressed or is simply nondeterministic, using a repeat-render oracle at a single commit.

    117 GitHub stars~1.5k tokensUpdated today
    MobileAuto-check passed
  • Composewebview Development

    parkwoocheol/compose-webview

    Builds, tests, and formats ComposeWebView multiplatform library.

    103 GitHub stars~1.3k tokensUpdated 1 mo ago
    MobileAuto-check passed

More from softspark/ai-toolkit

All 112 skills in this repo
  • Prepare Test Env

    softspark/ai-toolkit

    Prepare or verify a project QA environment with source identity, readiness, browser access, evidence paths and owned cleanup.

    179 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check: notes
  • A11y Validate

    softspark/ai-toolkit

    Accessibility validator: WCAG 2.1 AA, EN 301 549, EAA. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~3.8k tokensUpdated yesterday
    Auto-check: notes
  • Analyze

    softspark/ai-toolkit

    Analyzes code quality, complexity, patterns across codebase.

    179 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Autonomous Dev

    softspark/ai-toolkit

    Drives a brief, specification, issue or existing PR through implementation, review, tests and QA to a ready PR.

    179 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check: notes
  • Brand Voice

    softspark/ai-toolkit

    Direct technical voice for docs, README, user-facing text. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • CI

    softspark/ai-toolkit

    Detect/generate/debug CI pipeline config (GitHub Actions, GitLab CI).

    179 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check: notes

Categories

Questions about Kotlin Rules

What does Kotlin Rules do?

Kotlin coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit. Kotlin Rules is an agent skill from softspark/ai-toolkit. Kotlin coding rules: style, patterns, security, testing.

When should I use Kotlin Rules?

Kotlin Rules fits situations like: tasks that involve Android development.

How do I install Kotlin Rules in Claude Code?

Run `npx skills add softspark/ai-toolkit --skill kotlin-rules -a claude-code`. Or copy the skill folder (app/skills/kotlin-rules in softspark/ai-toolkit) into .claude/skills/kotlin-rules in your project. Claude Code loads it when a task matches its description.

How do I install Kotlin Rules in Codex?

Run `npx skills add softspark/ai-toolkit --skill kotlin-rules -a codex`. Or copy the skill folder (app/skills/kotlin-rules in softspark/ai-toolkit) into .agents/skills/kotlin-rules in your project. Codex loads it when a task matches its description.

Can I use Kotlin Rules in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add softspark/ai-toolkit --skill kotlin-rules -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/kotlin-rules, .gemini/skills/kotlin-rules, .github/skills/kotlin-rules and .opencode/skills/kotlin-rules in your project.

What does Kotlin Rules need to run?

Going by SKILL.md and its folder, Kotlin Rules needs the command-line tools its instructions call (gradle). Its frontmatter pre-approves these tools: Read.

Does Kotlin Rules access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Kotlin Rules safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Kotlin Rules use?

Kotlin Rules is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Kotlin Rules use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Kotlin Rules?

Skills that share tags, products or a category with Kotlin Rules: Android Development (dpconde/claude-android-skill, 336 stars), Diagnosing Compose Stability (rosuH/EasyWatermark, 1.9k stars), Claude Android Ninja (Drjacky/claude-android-ninja, 124 stars) and Desktop And Build Footguns (maxrave-dev/kotlin-footguns, 1k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Kotlin Rules?

softspark (a GitHub user) maintains it in softspark/ai-toolkit, which has 179 GitHub stars. The repository holds 112 skills in this directory. The repository was last updated on October 7, 2026.

Source: softspark/ai-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.