kotlin-lib-mcp

A Kotlin library research setup with approved commands for Gradle builds and tests, GitHub project information, Kotlin API inspection, and source-code lookup.

In plain words
What is it for?
It is for building and testing Kotlin libraries, checking binary compatibility, reviewing project and pull-request information, and looking up packages, declarations, documentation, dependencies, versions, and source.
Why use it?
It limits routine project actions to specified commands while giving the agent ways to inspect a Kotlin library's code and public API.

Settings file for Claude Code

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add settings/aoreshkov/kotlin-lib-mcp/settings
Clone the repo
git clone --depth 1 https://github.com/aoreshkov/kotlin-lib-mcp

Made for: Claude Code.

Per session not measured What this adds to a session before it is invoked.
When invoked not measured Not applicable: nothing here is loaded into a session.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Security

Grade A, and why

kotlin-lib-mcp scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

Origin

Copies of this mod

1 near-identical copy found in the catalogue:

.claude/settings.json · 58 lines

What it actually says

{
  "$schema": "https://json.schemastore.org/claude-code-settings.json",
  "permissions": {
    "allow": [
      "Bash(./gradlew :*)",
      "Bash(./gradlew build*)",
      "Bash(./gradlew test*)",
      "Bash(./gradlew check*)",
      "Bash(./gradlew updateKotlinAbi*)",
      "Bash(./gradlew checkKotlinAbi*)",
      "Bash(./gradlew tasks*)",
      "Bash(./gradlew help*)",
      "Bash(./gradlew projects*)",
      "Bash(git status:*)",
      "Bash(git diff:*)",
      "Bash(git log:*)",
      "Bash(git show:*)",
      "Bash(git branch:*)",
      "Bash(git check-ignore:*)",
      "Bash(gh pr view:*)",
      "Bash(gh pr diff:*)",
      "Bash(gh pr list:*)",
      "Bash(gh issue view:*)",
      "Bash(gh issue list:*)",
      "Bash(gh run view:*)",
      "Bash(gh run list:*)",
      "mcp__kotlin-lib__list_packages",
      "mcp__kotlin-lib__list_declarations",
      "mcp__kotlin-lib__get_api_signature",
      "mcp__kotlin-lib__get_kdoc",
      "mcp__kotlin-lib__get_source",
      "mcp__kotlin-lib__search_source",
      "mcp__kotlin-lib__get_dependencies",
      "mcp__kotlin-lib__list_versions",
      "mcp__kotlin-lib__get_latest_version",
      "WebFetch(domain:kotlinlang.org)",
      "WebFetch(domain:modelcontextprotocol.io)",
      "WebFetch(domain:docs.github.com)",
      "WebFetch(domain:code.claude.com)",
      "WebFetch(domain:github.com)"
    ],
    "deny": []
  },
  "hooks": {
    "Stop": [
      {
        "hooks": [
          {
            "type": "command",
            "command": "bash ${CLAUDE_PROJECT_DIR}/.claude/hooks/stop-verify.sh",
            "timeout": 300
          }
        ]
      }
    ]
  }
}
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 2d ago First seen · 58 lines scan A 666d15fbbe43

Subscribe to this mod's changes

kotlin-lib-mcp is a settings file published in the GitHub repository aoreshkov/kotlin-lib-mcp (8 stars, last pushed 4d ago), licensed Apache-2.0. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.