konnect-api-publish — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited konnect-api-publish (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Help an operator trace why an API is not reaching the intended developer audience, from managed API presence through catalog readiness and portal publication.
Use workflow language: inspect, trace, publish, validate, and approve. Do not turn this into generic Portal documentation. This skill owns publication-chain diagnosis, not generic Catalog authoring or developer application auth design.
kong-konnect MCP server first for live inspection ofmanaged API, catalog, and portal state.
kongctl-query for read-only checks on API, portal, and adjacentresources.
resources need to change: prefer kongctl-declarative for kongctl YAML, terraform-konnect for HCL-managed Konnect resources, and deck-gateway only when the missing link is in Gateway-entity config within the target control plane.
konnect-api-catalog when the real problem is API objectmodeling, versioning, specification quality, or package readiness rather than publication.
konnect-app-auth once publication is proven and the remainingissue is developer registration, approval, credential issuance, or auth strategy selection.
kong-konnect MCP is not connected, sayso early and continue with CLI or user-provided artifacts.
Default to read-first inspection. Only move to mutation when the missing link in the publication chain is understood.
Load only the reference file that matches the active branch:
references/publication-chain.mdmanaged API presence, catalog readiness, portal publication, and consumer use.
references/portal-visibility-vs-access.mdusable by the intended audience.
references/downstream-auth-handoffs.mdregistration, approval, or credential flow ownership.
Clarify what "not published" means:
Do not use one answer path for all of these. Capture which portal, audience, or viewer is expected to see or use the API before you inspect publication state.
If the operator uses "publish" loosely, load references/publication-chain.md and classify the missing stage before proposing any fix.
Start with the operator source objects:
If the API object or version does not exist, do not continue to portal debugging yet.
Verify:
Separate "API is published somewhere" from "API is published to the portal and audience the operator means."
Use references/publication-chain.md when the managed-API-to-catalog boundary is still unclear.
Do not collapse these into one failure:
Load references/portal-visibility-vs-access.md when the main question is whether the intended audience should actually see or discover the API.
This is where many "publish" issues become access or onboarding issues. Load references/downstream-auth-handoffs.md when registration, approvals, credentials, or auth strategy become the real blocker.
Diagnose one primary break:
by registration or auth requirements.
is absent or stale.
earlier in the chain.
Before answering, verify that you can state:
konnect-api-catalogkonnect-api-catalog when the missing step is API creation, versioning,spec quality, implementation/package modeling, or other upstream Catalog readiness work.
konnect-app-auth when publication is present but developerregistration, approvals, credentials, or auth strategy still block use.
kongctl-declarative or terraform-konnect when the user wants tocreate or update APIs, portals, or related publication resources as code.
deck-gateway when the publication issue is downstream of missing orstale Gateway-entity config inside the control plane.
konnect-access-scope when the API likely exists but the caller cannotsee or administer it.
kongctl-query for exact read-only command syntax during investigation.~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.