kong-konnect-795ab6 — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited kong-konnect-795ab6 (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Portable Kong skills plus kong-konnect MCP configuration for Cursor, Claude Code, and shared skill installers.
This repo is the contributor-facing source of truth for the packaged skills and install metadata. End users normally consume these assets through marketplace catalogs, plugin bundles, or shared-skill installers rather than by reading this repo directly.
This repository is currently in tech preview. It is actively maintained and updated as the shipped skills, install surfaces, and packaging workflows evolve.
Public issues are welcome during tech preview. Pull requests are currently limited to Kong employees while the preview is in progress.
The repo now uses a plugin-first layout. Root marketplace manifests advertise installable plugin packages, and the first shipped package is plugins/kong-konnect/.
Contributor bootstrap and maintenance guidance lives in CONTRIBUTING.md.
Recommended local validation path for contributors:
mise trust
mise install
mise run preflight
mise run deps
mise run hooks:install
mise run lintThe repo hooks are an opt-in local guardrail. GitHub Actions remains the enforcement path on pull requests and pushes to main.
All install surfaces use the same bearer token model:
Authorization: Bearer ${KONNECT_TOKEN}KONNECT_TOKEN is only needed when you install or use the kong-konnect MCP server through a plugin wrapper or manual MCP setup. A skill-only install via npx skills or gh skill does not require it.
npx skills add kong/ai-marketplace.npx skills add kong/ai-marketplace --skill gateway-plugin-datakit.npx skills update -g -y gateway-plugin-datakit or gh skill update gateway-plugin-datakit.gh skill, preview before install with gh skill preview kong/ai-marketplace gateway-plugin-datakit.Use plugins/kong-konnect/mcp.json as the shared checked-in reference shape for the kong-konnect MCP server.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.