konnect-app-auth — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited konnect-app-auth (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Help an operator configure or troubleshoot how developers register applications, receive credentials, and use APIs through Konnect Dev Portal and Konnect Application Auth.
Own the application-auth branch only: strategy choice, application registration, approvals, credentials, and the publication-to-enforcement path. Do not keep Portal sign-in, SSO, or generic API publication diagnosis in this skill after the surface is classified.
kong-konnect MCP server first for live inspection of portals,publications, application auth strategies, applications, registrations, and related approvals.
need to change: use terraform-konnect for HCL-managed resources and kongctl-declarative only when the surrounding repo already uses kongctl for this Konnect workflow.
deck-gateway only when the real change is downstream Gateway-entityconfig rather than Portal app-auth configuration.
kong-konnect MCP is not connected, say soearly and continue with user-provided artifacts or repo context.
classify that early and stop instead of debugging app credentials here.
Load only the reference file that matches the active branch:
references/auth-strategy-selection.mdmain decision.
references/registration-and-approval-flows.mdregistration state still block developers.
references/linked-service-and-enforcement.mdlinked Gateway Service path.
Clarify whether the problem is:
Do not use one answer path for all of these. If the blocker is mainly Portal sign-in or non-app-specific access, stop and hand off before investigating app registrations or credentials.
For developer self-service to work as intended, inspect:
If any link is missing, stop there before debugging credentials.
Load references/linked-service-and-enforcement.md when the chain appears complete on the portal side but runtime enforcement still looks wrong.
Choose based on who creates and owns the client credential material, not on which option happens to be easiest to name in the UI. Keep the strategy choice separate from publication state or downstream Gateway enforcement.
Load references/auth-strategy-selection.md when the main question is which strategy model fits the intended developer workflow.
If the strategy is correct but access still fails, inspect:
Treat “published but unusable” as a workflow-state problem until proven otherwise.
Load references/registration-and-approval-flows.md when pending, approved, rejected, or RBAC-gated state is the likely blocker.
Application auth only works the intended way when the API is linked to a Gateway Service and the auth strategy can be enforced there.
If there is no linked service, or the wrong service is linked, fix that model before changing strategy details.
Classify the primary issue as:
Gateway Service path, not just to Portal presentation.
intended.
linked-service enforcement are incomplete.
Before answering, verify that you can state:
approval, or runtime enforcement
konnect-api-publish when the API is not yet published or is published tothe wrong audience.
konnect-api-catalog when the API or implementation model itself is notready.
konnect-access-scope when the problem is mainly who can view oradminister the Portal or auth resources, or when org/team/role scoping is broader than one app-auth workflow.
application-auth work.
terraform-konnect or kongctl-declarative when the operator wants toencode or apply the resulting auth changes as config.
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.