AI Tools
TrustPin ships two Agent Skills that teach AI coding agents to integrate and review TrustPin certificate pinning in iOS, macOS, Android, Flutter, and React Native apps (bare and Expo), and to keep pins current in CI/CD, including automatic pinning when an AWS ACM certificate renews.
| Skill | Use it to |
|---|---|
trustpin-integration | Add the SDK to an app, review an existing integration, diagnose pinning errors |
trustpin-cicd | Automate pin rotation and release checks with the TrustPin CLI in a pipeline or on AWS |
Once installed, ask your agent:
- “Integrate TrustPin into this app.”
- “Review our TrustPin integration.”
- “Requests fail with PINS_MISMATCH, what do I do?”
- “Automate pin rotation in CI.”
- “Pin automatically when our ACM certificate renews.”
Your agent picks the matching skill from your request. Install both: trustpin-cicd reuses the CLI safety rules and reference in trustpin-integration. The skills are published at github.com/trustpin-cloud/ai-tools .
What the skills do
trustpin-integration
- Detects the platform and the HTTP client your app already uses, adds the SDK, the config file, the setup call, and wires pinning into that client.
- Lists the hosts your code connects to, so you can confirm each one is registered in your TrustPin project before shipping. In strict mode an unregistered host is refused.
- Reviews an existing integration against a checklist and diagnoses pinning errors.
trustpin-cicd
- Writes the pipeline definition that keeps pins current with
trustpin-cli: a scheduled pin refresh, pinning when an AWS ACM certificate renews (EventBridge and Lambda), CodeBuild and CodePipeline jobs, a self-hosted configuration on S3 and CloudFront, and release gates. - Covers GitHub Actions, GitLab CI, Azure DevOps, Jenkins, and CircleCI, and mobile CI services for release checks and embedded-configuration regeneration.
- Keeps staging separate from signing, signs only when something changed, and puts an approval step in front of a production publish. An unattended job that signs publishes to every installed app, and the skill says so when it proposes one.
- Does not create cloud resources, deploy infrastructure, or enable a pipeline. You create the secrets, apply the infrastructure, and turn the pipeline on.
The CI/CD guidance follows the DevOps guide, including AWS ACM: Automated Certificate Pinning on Renewal.
What they do not do
- They cannot create your project, choose key management, add domains, or publish. Those steps stay with you, in the dashboard or the CLI. See Project setup.
- They never ask for your API token, master password, or private key, and they never publish a configuration without your explicit go-ahead.
- They add no MCP server, no hooks, and no background process. They are instructions and reference text, plus a script (in
trustpin-integration) that lists hostnames found in your source files. The script makes no network requests and writes no files.
Install
Claude Code
/plugin marketplace add trustpin-cloud/ai-tools
/plugin install trustpin@trustpinTo enable it for everyone on a project, commit this to the project’s .claude/settings.json:
{
"extraKnownMarketplaces": {
"trustpin": { "source": { "source": "github", "repo": "trustpin-cloud/ai-tools" } }
},
"enabledPlugins": { "trustpin@trustpin": true }
}The plugin installs both skills. Check that they are active: type / and look for trustpin:trustpin-integration and trustpin:trustpin-cicd, or open /plugin and look under Installed. To update later: /plugin marketplace update trustpin.
Claude (web and desktop)
Download trustpin-integration.skill (and trustpin-cicd.skill for CI/CD automation) from the latest release and add them under Settings, Capabilities, Skills.
Cursor, GitHub Copilot, Codex, and other agents that read Agent Skills
Copy the skill folders into your project:
git clone https://github.com/trustpin-cloud/ai-tools
mkdir -p .agents/skills
cp -r ai-tools/skills/trustpin-integration ai-tools/skills/trustpin-cicd .agents/skills/.agents/skills/ is the shared project location these agents read. Agent-specific locations also work: .claude/skills/, .cursor/skills/, .github/skills/. Check your agent’s documentation if the skill is not picked up.
Agents without skills support
Keep the folders in your repository and add this line to AGENTS.md:
When working with TrustPin or certificate pinning, read
.agents/skills/trustpin-integration/SKILL.mdfirst.
Versions
The integration skill is verified against TrustPinKit 6.4.0, kotlin-sdk 6.4.0, trustpin_sdk 6.4.0, and @trustpin/react-native 6.4.0. The CI/CD skill targets trustpin-cli 6.0.0 and is written from TrustPin’s DevOps guide. The SDK API references are the most current source: Swift , Kotlin , Flutter , and React Native . If your installed SDK behaves differently, the SDK is the source of truth: tell your agent, or open an issue.
Feedback
Issues and corrections: github.com/trustpin-cloud/ai-tools/issues . Technical support: support@trustpin.cloud. Other inquiries: contact@trustpin.cloud. The skills are provided under the TrustPin Binary License Agreement (see the repository’s LICENSE).