konnect-platform-router — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited konnect-platform-router (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Turn broad Konnect requests into one primary downstream skill with a clear next step and one concrete thing that skill should prove next.
Use this skill as a classifier and handoff layer. Do not turn it into a product guide or a second copy of specialist workflows.
kong-konnect MCP server when the request depends on liveKonnect state.
kong-konnect MCP is unavailable, say so early and continue withkongctl-query, repository artifacts, logs, or user-provided state.
user between decK, kongctl, and Terraform unless they ask.
when behavior, product coverage, or limits may have changed.
specialist tool skill handle sandbox retry guidance instead of classifying it as a product failure here.
These defaults are intentionally short. Specialist skills may restate the same guidance because they can trigger directly without this router.
Bypass this router when the request already has one obvious owner.
Hand off directly when the user already named:
or AI Gateway
kongctl, Terraform, or decKkong-skill-authoring rather than aKonnect product workflow
Use this router only when the request is broad, cross-surface, or still ambiguous after the first read.
Classify the user's immediate need first:
If the request is already a direct declarative-tool request, hand off to the tool skill after checking whether a domain skill should diagnose first.
Use one primary destination:
konnect-access-scopeissues, resources that likely exist but cannot be seen or edited
konnect-control-plane-bootstrapdata plane choices, early ownership boundaries
konnect-gateway-triagelive gateway drift, traffic failures that may be control-plane or data-plane related
konnect-observability-triagegaps after traffic already exists
konnect-api-catalogstate before publication
konnect-api-publishvisibility gaps, published-but-not-discoverable problems
konnect-app-authpublished APIs that developers still cannot use
konnect-ai-gatewaylatency issues, governance around LLM traffic
konnect-event-gatewayissues in Event Gateway
Use kongctl-query when the user mainly needs:
After domain classification, preserve the toolchain already present in the repo:
kongctl-declarativekongctl YAML repos, plan/apply workflows, Konnect APIOps, adoption intokongctl
terraform-konnectdeck-gatewaydecK state files, diff/sync/dump, Gateway-sideconfig generation
terraform-kong-gatewayprovider
If the user asks for config changes but the failure domain is still ambiguous, route to the domain skill first and let it hand off to the tool skill once the missing link is known.
konnect-app-auth if theAPI may not be published yet. Publication comes before consumer auth.
konnect-api-publish when the issue is upstream catalog readiness.
gateway health is understood.
plane, data plane, and traffic presence are reasonably confirmed.
simply be in the wrong org, region, or team scope.
because the word "Konnect" appears in the skill package path.
Before handing off, verify that you can state:
broad triage
adjacent skill you ruled out
truth
prove first
When responding from this router:
kong-konnect MCP only when live state matterstop two candidates instead of guessing
skill
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.