No red flags found in any of the 11 categories — no credential harvesting, no data exfiltration, no curl-pipe-shell installer. Scanned against the SlowMist agent-security taxonomy, refreshed every 8 hours. Full audit →
by ThisIsSadeghi · Agent Tool · ★ 57
Last updated: · Indexed by AgentSkillsHub · Auto-synced every 8h
🔒 Is KMPilot safe to install? View the security audit →
Describe a feature in plain English — get it designed, built, tested, and reviewed across Android + iOS, with modular Clean Architecture enforced, not hoped for. Spec-driven development for Kotlin Multiplatform. This is a live template, not a starter app — don't it directly. Use the one-line installer in Quick Start: it clones the right release, renames the project to yours, and gives you a fresh git history. [. MVI architecture, Navigation 3, Koin/Hil
Pairlet (formerly CC Pocket / cc-pocket) — Continue your local AI coding tasks from phone, tablet, or desktop.
Drive Claude Code or OpenAI Codex from your phone — resume sessions, stream output, approve tool permissions r
Makes Claude code mobile first
Helping the Agents Compose the Things
Agent Skill for Android development with Kotlin and Jetpack Compose, covering modular architecture, Navigation
Explore other popular agent tool tools:
KMPilot is Turn Claude Code into a design-first Kotlin Multiplatform pipeline — an Android + iOS feature from one prompt, with architecture that doesn't drift. MIT.. It is categorized as a Agent Tool with 57 GitHub stars.
KMPilot is primarily written in Kotlin. It covers topics such as ai-agents, ai-coding, android.
You can find installation instructions and usage details in the KMPilot GitHub repository at github.com/ThisIsSadeghi/KMPilot. The project has 57 stars and 5 forks, indicating an active community.
KMPilot is released under the MIT license, making it free to use and modify according to the license terms.
The top alternatives to KMPilot on Agent Skills Hub include compose-skill, pairlet, cc-pocket. Each offers a different approach to the same problem space — compare them side-by-side by stars, quality score, and community activity.
Grades come from a rule-based scan built on the SlowMist agent-security taxonomy, covering 11 red-flag categories including credential harvesting, data exfiltration, and curl | sh installers. It is a first-layer scan, not a manual audit — we say so rather than overstate it.
The scale of the problem is documented independently: Liu et al. (2026), in a study of 31,132 agent skills, report that 26.1% contain security vulnerabilities. Our own full-catalog census is published as a citable open dataset.
Sources & who's responsible: