Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add TalissonVitorino/kmp-ios-skills --skill kmp-networkinggit clone --depth 1 https://github.com/TalissonVitorino/kmp-ios-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/talissonvitorino/kmp-ios-skills/kmp-networking)<a href="https://agentmods.dev/skills/talissonvitorino/kmp-ios-skills/kmp-networking"><img src="https://agentmods.dev/badge/skills/talissonvitorino/kmp-ios-skills/kmp-networking/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/talissonvitorino/kmp-ios-skills/kmp-networking"><img src="https://agentmods.dev/badge/skills/talissonvitorino/kmp-ios-skills/kmp-networking.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00105 | $0.02875 |
| Opus 5 | $0.00053 | $0.01437 |
| Sonnet 5 | $0.00021 | $0.00575 |
| Haiku 4.5 | $0.00011 | $0.00287 |
Grade A, and why
kmp-networking scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 7d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 380 lines — stays where its author put it; the contents beside it link to each section on GitHub.
KMP Networking with Ktor
Configure Ktor client for cross-platform networking with platform-optimized engines.
TLS/certificate pinning (MITM hardening) is a separate concern applied per engine — see
kmp-tls-pinning(OkHttpCertificatePinneron Android + DarwinhandleChallengeon iOS via expect/actual).
Dependencies
// build.gradle.kts (shared module)
plugins {
kotlin("multiplatform")
kotlin("plugin.serialization")
}
val ktor = "3.5.2" // current 3.x — verify latest at ktor.io/docs/releases
kotlin {
sourceSets {
val commonMain by getting {
dependencies {
implementation("io.ktor:ktor-client-core:$ktor")
implementation("io.ktor:ktor-client-content-negotiation:$ktor")
implementation("io.ktor:ktor-serialization-kotlinx-json:$ktor")
implementation("io.ktor:ktor-client-logging:$ktor")
implementation("io.ktor:ktor-client-auth:$ktor") // bearer-token Auth plugin
implementation("org.jetbrains.kotlinx:kotlinx-serialization-json:1.11.0")
}
}
val androidMain by getting {
dependencies {
implementation("io.ktor:ktor-client-okhttp:$ktor")
}
}
val iosMain by getting {
dependencies {
implementation("io.ktor:ktor-client-darwin:$ktor")
}
}
}
}
HttpClient Factory
// commonMain/kotlin/network/HttpClientFactory.kt
object HttpClientFactory {
fun create(
platform: Platform,
isDebug: Boolean = false
): HttpClient {
return HttpClient(platformEngine()) { // engine factory chosen per platform (expect/actual)
install(HttpTimeout) { // cross-platform timeouts (no engine-specific config needed)
requestTimeoutMillis = 30_000
connectTimeoutMillis = 30_000
}
install(ContentNegotiation) {
json(Json {
ignoreUnknownKeys = true
isLenient = true
encodeDefaults = false
})
}
if (isDebug) {
install(Logging) {
level = LogLevel.INFO
sanitizeHeader { it == HttpHeaders.Authorization } // never log tokens
logger = object : Logger {
override fun log(message: String) {
println("Ktor: $message")
}
}
}
}
install(Auth) {
bearer {
loadTokens {
// From secure storage; return null when signed out
accessTokenStorage.get()?.let { access ->
BearerTokens(access, refreshTokenStorage.get())
}
}
// Runs once on 401; concurrent 401s wait for it, then retry with the new token
refreshTokens { // this: RefreshTokensParams (client, oldTokens, response)
val refresh = oldTokens?.refreshToken ?: return@refreshTokens null
val new: TokenResponse = client.post("auth/refresh") {
markAsRefreshTokenRequest() // excludes this call from auth retry — prevents refresh loops
contentType(ContentType.Application.Json) // required: ContentNegotiation skips bodies with no Content-Type
setBody(RefreshRequest(refresh))
}.body()
accessTokenStorage.save(new.accessToken)
refreshTokenStorage.save(new.refreshToken)
BearerTokens(new.accessToken, new.refreshToken)
}
}
}
defaultRequest {
url {
protocol = URLProtocol.HTTPS
host = "api.example.com"
}
header("X-API-Version", "1.0")
header("X-Platform", platform.name)
}
expectSuccess = true
HttpResponseValidator {
handleResponseExceptionWithRequest { exception, request ->
when (exception) {
is ClientRequestException -> { // 4xx only
when (exception.response.status.value) {
401 -> throw UnauthorizedException()
403 -> throw ForbiddenException()
404 -> throw NotFoundException()
}
}
is ServerResponseException -> throw ServerException() // 5xx
}
}
}
install(ResponseObserver) {
onResponse { response ->
// Track response times, errors
}
}
}
}
}
// commonMain — the engine factory is provided per platform via expect/actual:
expect fun platformEngine(): HttpClientEngineFactory<*>
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 7d ago First seen · 380 lines · 105 tokens per session scan A c7cd25526932
kmp-networking is a skill published in the GitHub repository TalissonVitorino/kmp-ios-skills (12 stars, last pushed 16d ago), licensed MIT. It adds 105 tokens to every session and 2,875 once invoked, about $0.0005 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
compose-multiplatform
Use when building one shared Compose UI in Kotlin across Android, iOS, and desktop — commonMain @Composables, expect/actual, source-set placement, native interop, multiplatform ViewModel/navigation/Koin. NOT a single-platform native build (that is kotlin-android / swift-ios), and NOT Dart/Flutter cross-platform UI…
cmp-upgrade
Migrate an existing Kotlin/Compose Multiplatform (CMP/KMP) project to the next PROVEN-GREEN dependency version set. Use this when the user wants to upgrade Kotlin, KSP, Compose Multiplatform, Room, AGP, Koin, or Ktor versions in a KMP project, bump their KMP dependencies, or asks "upgrade kotlin/compose/KMP versions"…
cmp-doctor
Diagnose and heal both the toolchain AND the project a Kotlin/Compose Multiplatform (CMP/KMP) build needs. Use this when the user wants to set up or fix their CMP/KMP toolchain, install the Android SDK / AVD / emulator for KMP, install Appium and its drivers for a Compose Multiplatform app, set up JDK 17 / Xcode /…
cmp-dev-client
Run a create-cmp Compose Multiplatform app's shared UI in a live desktop window with Compose Hot Reload — the daily dev loop. Use this when the user wants to run their CMP app on desktop, preview the app while developing, iterate on Compose UI without an emulator, or asks "run my CMP app on desktop", "hot reload…
cmp-preview
THE default UI feedback loop while building or editing ANY Compose Multiplatform screen — in a stamped app, use it DURING development, not only when asked: it renders the app's REAL screens headlessly in seconds (no device, no emulator, no manual Gradle) and tells you exactly what each edit changed, so you catch your…
compose-animations
Use when writing or reviewing Jetpack Compose motion: visibility enter/exit, animating one property toward a target, color or size transitions, multiple properties from one state, switching composable content, or choosing between AnimatedVisibility, animateAsState, rememberTransition, AnimatedContent, and Crossfade.