kmp-security
Installation
SKILL.md
When to Use This Skill
Use when you need to:
- Pin a server's certificate/public key so the app rejects a MITM proxy even with a trusted root CA installed on the device
- Detect a rooted/jailbroken device, an active debugger, or Frida/Xposed hooking at runtime
- Store a token/credential encrypted at rest, not in plain
SharedPreferences/NSUserDefaults - Strip debug symbols from a release iOS/Kotlin-Native binary
- Check this collection's coverage against the real OWASP Mobile Top 10
Do NOT use this skill for Android-specific obfuscation/minification — load
kmp-proguard-r8 instead, this skill cross-references it rather than
duplicating it.