All skills
kotlin avatar

/kotlin-tooling-kotlin-toolchain-plugin-authoring

@0ad228e official
by kotlinkotlin/kotlin-agent-skills1.1k stars
42

Load when authoring, writing, or designing a Kotlin Toolchain local plugin to extend the declarative build with code generation, build-time processing, custom verification, or packaging that module.yaml cannot express, or when referencing @TaskAction, @Configurable, plugin.yaml, or jvm/amper-plugin. Skip for porting an existing Gradle plugin.

Use this Skill: https://skilld.dev/gh/kotlin/kotlin-agent-skills/kotlin-tooling-kotlin-toolchain-plugin-authoring

This session only. Nothing lands on disk.

SKILL.md

β‰ˆ99 tokens always: the name and description. β‰ˆ2.2k when used: this file. β‰ˆ1.6k more on demand in 1 file.

Kotlin Toolchain Plugin Authoring

Local plugins are the official escape hatch from declarative YAML: a jvm/amper-plugin module shipping task actions, settings, and generated sources/resources alongside your project. Code patterns to adapt are in references/examples.md.

When to write a plugin

Write one when you need:

  • A build-time step a library's workflow expects (code generation, schema compilation, resource transformation, version stamping).
  • Custom verification wired into the build (pre-release checks, schema validation, contract tests).
  • A build-time value published into the JAR classpath or downstream tasks β€” the closest analog to Gradle's project.version.
  • A named CLI command for a repeated workflow (./kotlin do release).

Don't write one when module.yaml already covers it (dependencies, JDK provisioning, source layouts, basic packaging), and never to reuse a Gradle plugin β€” the Kotlin Toolchain cannot consume them.

Layout

repo-root/
β”œβ”€β”€ kotlin, kotlin.bat            # wrappers (from `kotlin init`)
β”œβ”€β”€ project.yaml                  # registers the plugin
β”œβ”€β”€ plugins/<name>/
β”‚   β”œβ”€β”€ module.yaml               # product: jvm/amper-plugin
β”‚   β”œβ”€β”€ plugin.yaml               # tasks: + commands: + generated:
β”‚   └── src/
β”‚       β”œβ”€β”€ Settings.kt           # @Configurable interface
β”‚       β”œβ”€β”€ tasks/                # one @TaskAction per file
β”‚       β”‚   β”œβ”€β”€ Foo.kt
β”‚       β”‚   └── FooSteps.kt       # internal shared helpers (not @TaskAction)
β”‚       └── <domain logic>/
└── <consumer-module>/
    └── module.yaml               # plugins: { <name>: enabled: true, ... }

Keep at least one consumer module in the repo β€” it is the only way to exercise the plugin end-to-end, and plugins cannot be published to any public registry yet.

project.yaml

modules:
  - consumer-app
  - plugins/<name>

plugins:
  - ./plugins/<name>

Without the top-level plugins: block the plugin id is unresolvable from any consumer.

module.yaml β€” the plugin module

product: jvm/amper-plugin          # marks the module as a plugin

dependencies:
  - <coordinate>:<version>
  - <coordinate>:<version>: runtime-only   # required only at runtime
  - <coordinate>:<version>: compile-only

pluginInfo:
  id: <plugin-id>                                  # what consumers write under `plugins:`
  settingsClass: <fully.qualified.Settings>        # the @Configurable interface

settings:
  jvm:
    jdk:
      version: 21
  kotlin:
    languageVersion: 2.1

@Configurable interface Settings

Defaults go in interface property getters; nested blocks become nested @Configurable interfaces.

@Configurable
interface Settings {
    val someValue: String get() = "default"
    val checks: ChecksSettings
}

@Configurable
interface ChecksSettings {
    val strict: Boolean get() = true
}

Consumers override what they need in module.yaml; omitted values fall back to the getter default:

plugins:
  <plugin-id>:
    enabled: true
    someValue: "override"
    checks:
      strict: false

@TaskAction

Task actions are top-level funs, called when the matching plugin.yaml entry executes.

@TaskAction
fun foo(
    @Input moduleRootDir: Path,
    @Output outputDir: Path,
    settings: Settings,
) {
    // body
}
  • @Input path: Path β€” declared input; Kotlin Toolchain snapshots its contents for execution avoidance.
  • @Output path: Path β€” declared output directory; Kotlin Toolchain creates it and passes the path in. Write to the exact Path you received, or downstream references won't find the result.
  • settings: Settings (or any @Configurable) β€” typed configuration, wired in plugin.yaml.
  • Plain Path / primitives β€” passed literally from plugin.yaml.
  • println(...) is the output channel; Kotlin Toolchain captures stdout.

Execution avoidance

A @TaskAction is skipped when its declared inputs are unchanged. Tasks whose real inputs are Git history, the network, or environment variables cannot be fingerprinted, so opt out:

@TaskAction(executionAvoidance = ExecutionAvoidance.Disabled)
fun foo(@Output outputDir: Path, settings: Settings) { /* ... */ }

Tasks with no @Output are never cached and always re-run β€” correct for purely side-effecting tasks (releases, deployments, pushes).

plugin.yaml

tasks:
  foo:
    action: !<fully.qualified.foo>
      moduleRootDir: ${module.rootDir}
      outputDir: ${taskOutputDir}
      settings: ${pluginSettings}

  bar:
    action: !<fully.qualified.bar>
      input: ${tasks.foo.action.outputDir}/result.txt
      settings: ${pluginSettings}

generated:
  resources:
    - directory: ${tasks.foo.action.outputDir}

commands:
  - foo
Reference Resolves to
${module.rootDir} Directory containing the consumer's module.yaml. Pass as @Input to inspect the consumer's tree.
${taskOutputDir} Toolchain-managed per-task output directory. Pass as @Output.
${pluginSettings} The @Configurable object built from the consumer's module.yaml.
${tasks.<task>.action.<param>} Another task's parameter β€” used in generated.* and to wire one task's @Input to another's @Output.

generated.resources / generated.sources

Both register a directory (usually a task's @Output) as a contribution to the consumer's build, and both auto-wire the producing task to run first:

  • generated.resources β€” added to the JAR classpath, reachable via getResourceAsStream("/path/in/jar").
  • generated.sources β€” added as a Kotlin source root and compiled with the consumer's src/.

Tasks vs commands

Tasks are the implementation, addressed as ./kotlin task :<module>:<task>@<plugin-id> β€” the docs advise against relying on that mangled name. Commands are the public API: ./kotlin do <command-name>, listed via ./kotlin show commands (-m <module> to scope).

  • A task whose @Output feeds generated.resources/generated.sources is a build-graph contributor. Keep it out of commands:; it runs automatically and exposing it invites users to run it by hand.
  • A task users invoke directly must be in commands:.

File-based task communication

There is no shared mutable build state β€” no project.version, no extension property maps. Tasks talk through matched paths:

  1. The producer takes @Output outputDir: Path and writes files into it.
  2. plugin.yaml points a consumer task's @Input at ${tasks.<producer>.action.outputDir}/<file>.
  3. The Toolchain infers the dependency from the path match β€” no dependsOn API needed.

The same @Output directory can serve build-time consumers (via @Input) and runtime consumers (registered under generated.resources, read via getResourceAsStream) simultaneously.

Runtime overrides via environment variables

There is no -Pkey=value. Read env vars inside the action for ephemeral overrides:

val forced = System.getenv("MYPLUGIN_FORCE_VALUE")?.takeIf { it.isNotBlank() }
val skipChecks = System.getenv("MYPLUGIN_SKIP_CHECKS")?.equals("true", ignoreCase = true) == true

Pass the env map in as a constructor parameter rather than calling System.getenv() deep in the call stack, so logic stays unit-testable. Document every recognised variable in the plugin's README. Env vars are ephemeral overrides, not a trust boundary β€” validate a value before using it in a file path or process argument.

Sharing logic across task actions

Tasks often share steps (verify β†’ create β†’ push). Don't compose an atomic user-facing task from a chain of build-graph tasks: separate invocations re-open shared resources and open a window where another process observes intermediate state.

Limitations to design around

  • Plugins are local-only; no public registry publishing yet.
  • Plugins are module-level; there is no project-wide plugin. Every consumer module lists it under plugins:, and cross-module effects flow through files.
  • No ${...} interpolation in module.yaml (as of 0.11) β€” consumer settings are literal values.
  • No Project.afterEvaluate, no lazy Provider/Property graph. Compute derived values in the action body.
  • -h/--help does not list plugin commands; use ./kotlin show commands.

Validate against a consumer

  1. Add a small consumer module (demo-app/, sample/) enabling the plugin with realistic settings.
  2. Have its main.kt or a test read whatever the plugin publishes.
  3. Put the exact commands and expected output in the plugin's README, so a fresh clone can paste and compare.

Plugin docs: https://kotlin-toolchain.org/dev/user-guide/plugins/

Source: SKILL.md on GitHub

No alerts20d3 checks Β· Risk SAFE
  • Gen Agent Trust Hub20d

    The skill provides guidance for authoring local plugins for the Kotlin Toolchain. It is generally safe for development purposes, but it documents a pattern where build-time tasks ingest untrusted configuration data from environment variables and YAML files, creating a potential attack surface for indirect prompt injection.

  • Socket20d

    No alerts

  • Snyk20d

    Risk: LOW Β· No issues

Signed by skilld at 0ad228e. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 3 weeks ago.

Activeupdated last month
metadata
{
  "author": "github:@singleton11",
  "version": "0.1.0"
}

README badge

README badge for kotlin/kotlin-agent-skills/kotlin-tooling-kotlin-toolchain-plugin-authoring