kora-grpc-client

kora-grpc-client is a skill for Claude Code from kora-projects/kora-skills. It costs 53 tokens per session (2,345 once invoked), scanned A, original, Apache-2.0.

A Kora library guide for creating outbound gRPC clients. gRPC is a way for services to call each other using generated code based on a .proto contract.

In plain words
What is it for?
Use it when generating gRPC stubs, injecting them into a Kora application, configuring clients, or making unary and streaming calls.
Why use it?
It helps you configure Kora’s client wiring, authentication metadata, interceptors, and streaming calls without guessing framework-specific details.

Skill for Claude Code

Written for Claude Code: shipped in a Claude Code plugin.

Needs its repository: it reads a path above its own folder, which exists only inside the repository. The line is **Kora sub-skill — obey the [kora-v1 meta rules](../../SKILL.md) on every task:** **R0** ensure `.kora-agent/` docs+examples are cloned · **R1** read this sub-s.

Part of the kora-v1 plugin — 41 skills shipped together

Good fit Use it when generating gRPC stubs, injecting them into a Kora application, configuring clients, or making unary and streaming calls.

Compare 6 skills from other repositories ↓
Install

Getting it into your agent

It runs from inside its repository, so the clone comes first — what it calls does not travel with the file alone.

Clone the repo
git clone --depth 1 https://github.com/kora-projects/kora-skills
agentmods
npx agentmods add skills/kora-projects/kora-skills/kora-grpc-client

Made for: Claude Code.

Or install kora-v1, the plugin that ships this one along with the rest of its 41 skills.

Wrote this? Show the measurements

A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.

agentmods badge for kora-grpc-client

README.md
[![agentmods](https://agentmods.dev/badge/skills/kora-projects/kora-skills/kora-grpc-client/github.svg)](https://agentmods.dev/skills/kora-projects/kora-skills/kora-grpc-client)
Your own site
<a href="https://agentmods.dev/skills/kora-projects/kora-skills/kora-grpc-client"><img src="https://agentmods.dev/badge/skills/kora-projects/kora-skills/kora-grpc-client/github.svg" alt="Measured on agentmods" height="20"></a>

Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.

agentmods 80×15 button for kora-grpc-client

Your own site · 80×15
<a href="https://agentmods.dev/skills/kora-projects/kora-skills/kora-grpc-client"><img src="https://agentmods.dev/badge/skills/kora-projects/kora-skills/kora-grpc-client.svg" alt="Reviewed on agentmods" width="80" height="20"></a>
Per session 53 Skills are progressive disclosure: only the name and description are preloaded; the body loads when the skill is used.
When invoked 2,345 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. A grade says what 26 rules found in the file — not that it is safe.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5.1 $0.00053 $0.02345
Opus 5 $0.00026 $0.01172
Sonnet 5 $0.00011 $0.00469
Haiku 4.5 $0.00005 $0.00234

Measured 10d ago against content hash ca1b9753e2d7, method: parsed. Prices are Anthropic first-party input rates as of 2026-09-10, from the pricing page.

Security

Grade A, and why

kora-grpc-client scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 10d ago.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

plugins/kora-v1/skills/kora-grpc-client/SKILL.md · 240 lines

How it starts

The opening of the file, as written. The whole thing — 240 lines — stays where its author put it; the contents beside it link to each section on GitHub.

Kora gRPC Client

Kora sub-skill — obey the kora-v1 meta rules on every task: R0 ensure .kora-agent/ docs+examples are cloned · R1 read this sub-skill before writing code · R2 Kora APIs only — no Spring/Micronaut/Quarkus, no invented annotations or config keys · R3 journal any incorrect Kora usage. Add comments/Javadoc only if asked.

Generate gRPC client stubs from a .proto contract and inject them as components through GrpcClientModule. Kora wires the configured channel and the generated stubs into the application graph; your code just builds protobuf requests and calls stub methods.

Read this first when:

  • enabling GrpcClientModule and injecting a generated *BlockingStub/*FutureStub/*Stub,
  • configuring a client under grpcClient.<ServiceName>.*,
  • adding a ClientInterceptor for metadata headers, auth, or logging,
  • making unary or streaming calls.

Key facts (do not get these wrong)

  • Stubs are injected directly by type — no @Tag on the constructor parameter. Kora produces one stub per generated *Grpc class. Injecting UserServiceGrpc.UserServiceBlockingStub is enough.
  • @Tag(ServiceGrpc.class) belongs on a ClientInterceptor, to scope that interceptor to one service's client. It is not used for stub injection.
  • Annotations come from ru.tinkoff.kora.common.* (@Component, @Tag, @KoraApp), not from any annotation.processor.* package.
  • Plaintext vs TLS is chosen by the URL scheme (http:// = plaintext, https:///grpc:// per transport). There is no usePlaintext config key.
  • The mandatory annotation processor must be present: Java annotationProcessor "ru.tinkoff.kora:annotation-processors", Kotlin ksp "ru.tinkoff.kora:symbol-processors".

Quick Start

1. Dependencies

Pin the BOM (kora-parent); never version individual ru.tinkoff.kora:* artifacts.

plugins {
    id "application"
    id "com.google.protobuf" version "0.9.4"
}

configurations {
    koraBom
    annotationProcessor.extendsFrom(koraBom)
    implementation.extendsFrom(koraBom)
}

dependencies {
    koraBom platform("ru.tinkoff.kora:kora-parent:1.2.19")
    annotationProcessor "ru.tinkoff.kora:annotation-processors"

    implementation "ru.tinkoff.kora:grpc-client"
    implementation "ru.tinkoff.kora:config-hocon"
    implementation "ru.tinkoff.kora:logging-logback"
    implementation "io.grpc:grpc-protobuf:1.74.0"
    compileOnly "javax.annotation:javax.annotation-api:1.3.2"
}

protobuf {
    protoc { artifact = "com.google.protobuf:protoc:3.25.3" }
    plugins {
        grpc { artifact = "io.grpc:protoc-gen-grpc-java:1.74.0" }
    }
    generateProtoTasks {
        all()*.plugins { grpc {} }
    }
}

sourceSets {
    main {
        java {
            srcDirs "build/generated/source/proto/main/grpc"
            srcDirs "build/generated/source/proto/main/java"
        }
    }
}

Read the full file on GitHub · 240 lines

Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. 10d ago First seen · 240 lines · 53 tokens per session scan A ca1b9753e2d7

Subscribe to this mod's changes

kora-grpc-client is a skill published in the GitHub repository kora-projects/kora-skills (1 stars, last pushed 9d ago), licensed Apache-2.0. It adds 53 tokens to every session and 2,345 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.