konnect-api-catalog — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited konnect-api-catalog (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Help an operator create, shape, and troubleshoot Catalog APIs and API packages before they become a Dev Portal publishing or consumer-access problem.
Own Catalog readiness diagnosis and object modeling for APIs, versions, specs, documentation, implementations, and packages. Do not absorb Dev Portal publication, app auth, or declarative delivery workflows beyond clear handoffs.
kong-konnect MCP server first for live inspection of APIs,versions, specs, documents, implementations, packages, and portal publications.
surfaces include API, version, implementation, package, and publication listings.
need to change: use terraform-konnect for HCL-managed Catalog resources and kongctl-declarative only when the repo already manages the surrounding Konnect workflow that way.
deck-gateway only when the real missing link is Gateway-entity configbehind an implementation or linked service.
kong-konnect MCP is not connected, say soearly and continue with user-provided artifacts or adjacent CLI/config sources.
into a mutation playbook for Portal, app auth, or Gateway configuration.
Load only the reference file that matches the active branch:
references/managed-api-readiness.mdupstream catalog shape are complete enough before publication.
references/spec-version-and-metadata.mdmetadata alignment.
references/package-and-implementation-boundaries.mdpackage-versus-API modeling is the real issue.
First separate whether the user is trying to make the API:
If the real outcome is not Catalog readiness, hand off early instead of doing partial diagnosis in the wrong layer.
Clarify whether the operator is missing:
Do not jump straight to Portal troubleshooting if the Catalog object model is incomplete.
Load references/managed-api-readiness.md when "missing from catalog" is really a question about what object in the chain is incomplete.
Inspect:
distinct APIs for major versions
Load references/spec-version-and-metadata.md when the versioning or documentation model is the main decision branch.
Verify:
structure
Treat invalid-but-accepted specs as degraded inputs, not as healthy state.
If developers should be able to consume the API through registration, inspect:
implementation
/ control plane scenario
Do not call the API consumer-ready until the implementation story is clear.
When API packages are involved, verify:
Packages are for grouping and presentation, not for hiding a broken API model.
Load references/package-and-implementation-boundaries.md when grouping, implementation linkage, or package boundaries are the main question.
Once API shape, docs, implementations, and packages are understood, hand off:
konnect-api-publish for Portal publication and audience-facing issueskonnect-app-auth when the API exists but developer registration or authbehavior is the real blocker
deck-gateway, terraform-konnect, or kongctl-declarative when theoperator wants to codify or change the resulting config
not treat one healthy field as proof that the rest are aligned.
object existing in Catalog.
underlying API model.
Before answering, verify that you can state:
app auth, or declarative delivery
konnect-api-publish when the Catalog object is ready and the remainingproblem is publication to Portal.
konnect-app-auth when the issue is developer self-service, applicationregistration, or auth strategy behavior.
deck-gateway, terraform-konnect, or kongctl-declarative when theoperator wants to encode or apply the resulting change as config.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.