Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add rcosteira79/android-skillsnpx agentmods add plugins/rcosteira79/android-skills/android-skillsgit clone --depth 1 https://github.com/rcosteira79/android-skillsGrade A, and why
android-skills scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 3d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "android-skills",
"description": "Android and KMP development skills for Claude Code — architecture, Compose, coroutines, flows, networking (Retrofit, Ktor), persistent storage (Room, DataStore), pagination, dependency injection (Hilt, Koin), testing, debugging, Gradle, and Material Design 3",
"version": "5.6.0",
"author": {
"name": "Ricardo Costeira"
},
"homepage": "https://github.com/rcosteira79/android-skills",
"repository": "https://github.com/rcosteira79/android-skills",
"license": "MIT",
"keywords": [
"android",
"kotlin",
"kmp",
"compose",
"coroutines",
"flows",
"ktor",
"room",
"datastore",
"paging",
"koin",
"hilt",
"material3",
"jetpack",
"gradle"
]
}
What it installs
The manifest is a name and a version. 21 skills travel with it, and installing the plugin installs all of them — 1,751 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill android-debugging A 55 tokens
- Skill android-dev A 217 tokens
- Skill android-ux A 61 tokens
- Skill compose A 201 tokens
- Skill android-testing A 100 tokens
- Skill kotlin-flows A 53 tokens
- Skill kmp-boundaries A 106 tokens
- Skill kmp-ktor A 51 tokens
- Skill koin A 96 tokens
- Skill kotlin-coroutines A 43 tokens
- Skill pdf-annotations A 141 tokens
- Skill android-data-layer A 66 tokens
- Skill datastore A 98 tokens
- Skill paging A 92 tokens
- Skill rxjava-migration A 24 tokens
- Skill android-gradle-logic A 35 tokens
- Skill android-retrofit A 41 tokens
- Skill android-source-search A 60 tokens
- Skill coil-compose A 53 tokens
- Skill gradle-build-performance A 44 tokens
- Skill modularization A 114 tokens
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 3d ago First seen · 29 lines scan A 6011b9cc9de0
android-skills is a plugin published in the GitHub repository rcosteira79/android-skills (136 stars, last pushed 8d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
build-swift-apps
Build, debug, profile, test, refactor, and release Swift apps across iOS, macOS, Xcode, SwiftUI, SwiftPM, Tuist, and App Store Connect.
apple-dev-skills marketplace
Apple platform development skills, agents, commands, and MCP servers (App Store Connect + Apple developer docs). Covers Swift 6, SwiftUI, design, accessibility, concurrency, Apple review auditing, CI build checks, ASC API automation, and live Apple documentation lookup.
compose-skill
Compose and Compose Multiplatform expert skill — state, animations, navigation, performance, design-to-code, PR review mode, M3 motion.
app-intents
Reviews and writes Swift App Intents code, exposing app actions and data to Siri, Shortcuts, Spotlight, and Apple Intelligence.
create-cmp
Build production mobile apps (Android + iOS, one codebase) with AI — the delivery harness for Kotlin/Compose Multiplatform, the current generation of cross-platform (Google-backed KMP, Compose iOS stable since May 2025, the strongest stack for AI-driven development — sourced case in docs/WHY-CMP.md). Use it when asked.
widgets
Reviews and writes Swift WidgetKit code: timeline providers, configurations, families, accented/tinted rendering, interactive widgets, Controls, Live Activities, Smart Stack relevance, push-updated widgets, data loading, deep links, animations, and SiriKit/ClockKit migration.