Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add TalissonVitorino/kmp-ios-skills --skill swiftlintgit clone --depth 1 https://github.com/TalissonVitorino/kmp-ios-skillsWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/talissonvitorino/kmp-ios-skills/swiftlint)<a href="https://agentmods.dev/skills/talissonvitorino/kmp-ios-skills/swiftlint"><img src="https://agentmods.dev/badge/skills/talissonvitorino/kmp-ios-skills/swiftlint/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/talissonvitorino/kmp-ios-skills/swiftlint"><img src="https://agentmods.dev/badge/skills/talissonvitorino/kmp-ios-skills/swiftlint.svg" alt="Reviewed on agentmods" width="80" height="20"></a>- NVIDIA SkillSpector pass
What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00251 | $0.04211 |
| Opus 5 | $0.00125 | $0.02106 |
| Sonnet 5 | $0.00050 | $0.00842 |
| Haiku 4.5 | $0.00025 | $0.00421 |
Grade A, and why
swiftlint scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 341 lines — stays where its author put it; the contents beside it link to each section on GitHub.
SwiftLint (iOS / Swift)
Static analysis and style enforcement for Swift. This skill covers configuration
authoring, build integration, and rollout — grounded in the realm/SwiftLint
and SimplyDanny/SwiftLintPlugins docs. For a fintech codebase the goal is a lint gate
that blocks new violations without a big-bang cleanup of the existing ones.
- SwiftLint has two rule engines: lint rules (syntactic, AST via SourceKit) run by
swiftlint lint(default), and analyzer rules run byswiftlint analyzeagainst a compiler log. - Ships default-on rules plus a large opt-in set.
swiftlint ruleslists every rule and whether it's enabled;swiftlint reporterslists output formats.
Contents
- Install
- .swiftlint.yml
- Rule severity & thresholds
- Custom rules (regex)
- Inline suppression
- Build integration (SPM plugin / run script)
- Analyzer rules
- Reporters
- strict vs lenient
- Baselines (legacy rollout)
- CI
- Rollout strategy
- Checklist
- References:
references/config-reference.md,references/custom-rules.md,references/ci-recipes.md
Install
Pin the version so every machine and CI runner lints identically — a floating SwiftLint silently changes what fails.
brew install swiftlint # local dev (unversioned; fine for editors)
mint install realm/SwiftLint # Mintfile-pinned
- Preferred for reproducibility: the SPM build-tool plugin (below) — it vendors a pinned binary per package, so no separate install step and no version drift between developers and CI.
- Avoid the CocoaPods
SwiftLintpod on new projects; the SPM plugin supersedes it.
.swiftlint.yml
Place at the repo root (or a target/subdirectory root — SwiftLint walks up from each file and applies the nearest config). Keys:
# --- rule selection ---
disabled_rules: # turn OFF default-on rules
- todo
- trailing_whitespace
opt_in_rules: # turn ON rules that are off by default
- empty_count
- first_where
- force_unwrapping
- explicit_init
- all # special: enable EVERY opt-in rule (minus disabled_rules)
# only_rules: # allow-list: ONLY these run. Mutually exclusive with
# - force_cast # disabled_rules AND opt_in_rules — do not combine.
# - force_try
analyzer_rules: # separate list, run only by `swiftlint analyze` (all opt-in)
- unused_import
- unused_declaration
# --- paths (case-sensitive, relative to the config file) ---
included: # if set, lint ONLY these (still minus `excluded`)
- Sources
excluded: # skip these; wins over `included`
- Tests
- .build
- Pods
- "**/Generated" # generated code (protobuf, Sourcery, R.swift) — never lint
# --- output ---
reporter: "xcode" # default; see Reporters section
# --- global severity ---
strict: false # true → warnings become errors (nonzero exit)
lenient: false # true → errors become warnings (never fails)
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 341 lines · 251 tokens per session scan A 6b03d967e65a
swiftlint is a skill published in the GitHub repository TalissonVitorino/kmp-ios-skills (12 stars, last pushed 17d ago), licensed MIT. It adds 251 tokens to every session and 4,211 once invoked, about $0.0013 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-09-03.
Other skills, from other repositories
compose-multiplatform
Use when building one shared Compose UI in Kotlin across Android, iOS, and desktop — commonMain @Composables, expect/actual, source-set placement, native interop, multiplatform ViewModel/navigation/Koin. NOT a single-platform native build (that is kotlin-android / swift-ios), and NOT Dart/Flutter cross-platform UI…
cmp-upgrade
Migrate an existing Kotlin/Compose Multiplatform (CMP/KMP) project to the next PROVEN-GREEN dependency version set. Use this when the user wants to upgrade Kotlin, KSP, Compose Multiplatform, Room, AGP, Koin, or Ktor versions in a KMP project, bump their KMP dependencies, or asks "upgrade kotlin/compose/KMP versions"…
cmp-dev-client
Run a create-cmp Compose Multiplatform app's shared UI in a live desktop window with Compose Hot Reload — the daily dev loop. Use this when the user wants to run their CMP app on desktop, preview the app while developing, iterate on Compose UI without an emulator, or asks "run my CMP app on desktop", "hot reload…
cmp-preview
THE default UI feedback loop while building or editing ANY Compose Multiplatform screen — in a stamped app, use it DURING development, not only when asked: it renders the app's REAL screens headlessly in seconds (no device, no emulator, no manual Gradle) and tells you exactly what each edit changed, so you catch your…
cmp-doctor
Diagnose and heal both the toolchain AND the project a Kotlin/Compose Multiplatform (CMP/KMP) build needs. Use this when the user wants to set up or fix their CMP/KMP toolchain, install the Android SDK / AVD / emulator for KMP, install Appium and its drivers for a Compose Multiplatform app, set up JDK 17 / Xcode /…
kotlin-concurrency-and-flow
Use when writing or reviewing Kotlin coroutine scope ownership, raw Thread or Executor work, init launches, non-suspending launch APIs, runBlocking, cancellation, StateFlow, SharedFlow, Channel, stateIn, SharingStarted, state updates, or one-shot events.