Source profileQuality 84/100Review permissions

affaan-m/ECC/skills/springboot-verification/SKILL.md

springboot-verification

Verification loop for Spring Boot projects: build, static analysis, tests with coverage, security scans, and diff review before release or PR.

Source repository stars
234,327
Declared platforms
0
Static risk flags
1
Last source update
2026-07-27
Source checked
2026-07-28

Decision brief

What it does—and where it fits

Run before PRs, after major changes, and pre-deploy.

Best for

    Not for

    • Tasks that require unconfirmed production actions or broad system permissions.
    • Environments where the pinned source and install steps cannot be inspected.

    Compatibility matrix

    Platform support, with evidence labels

    PlatformStatusEvidenceWhat to check
    CodexNot declaredNo explicit evidencePortability before use
    Claude CodeNot declaredNo explicit evidencePortability before use
    CursorNot declaredNo explicit evidencePortability before use
    Gemini CLINot declaredNo explicit evidencePortability before use
    Open the compatibility checker

    Installation

    Inspect first. Install second.

    The source command is displayed only when detected. A safe inspection prompt is always available so your agent can explain every action before execution.

    Source-detected install commandSource
    npx skills add https://github.com/affaan-m/ECC --skill "skills/springboot-verification"
    Safe inspection promptEditorial

    Inspect the Agent Skill "springboot-verification" from https://github.com/affaan-m/ECC/blob/4e973d3eaf92d97f8d2e2d8abb39d8bdc8711b38/skills/springboot-verification/SKILL.md at commit 4e973d3eaf92d97f8d2e2d8abb39d8bdc8711b38. List every install step, command, network request, credential, file read/write, external action, and rollback step. Explain whether it fits my task. Do not install or execute anything until I approve.

    Workflow

    What the source asks the agent to do

    1. 01

      Phase 1: Build

      bash mvn -T 4 clean verify -DskipTests

      bash mvn -T 4 clean verify -DskipTests
    2. 02

      Phase 2: Static Analysis

      Review the “Phase 2: Static Analysis” section in the pinned source before continuing.

      Review and apply the “Phase 2: Static Analysis” source section.
    3. 03

      Phase 3: Tests + Coverage

      bash mvn -T 4 test mvn jacoco:report verify 80%+ coverage

      bash mvn -T 4 test mvn jacoco:report verify 80%+ coverage
    4. 04

      Phase 4: Security Scan

      Review the “Phase 4: Security Scan” section in the pinned source before continuing.

      Review and apply the “Phase 4: Security Scan” source section.
    5. 05

      Phase 5: Lint/Format (optional gate)

      Review the “Phase 5: Lint/Format (optional gate)” section in the pinned source before continuing.

      Review and apply the “Phase 5: Lint/Format (optional gate)” source section.

    Permission review

    Static risk signals and limitations

    Runs scripts

    medium · line 166

    The documentation asks the agent to run terminal commands or scripts.

    git secrets --scan # if configured

    Runs scripts

    medium · line 192

    The documentation asks the agent to run terminal commands or scripts.

    git diff --stat

    Evidence record

    Why each signal appears

    EvidenceSourceComputedTestedEditorial
    SignalValueEvidence typeMeaning
    Quality score84/100ComputedDocumentation, specificity, maintenance, and trust rules
    Repository stars234,327SourceRepository attention, not individual Skill quality
    Compatibility0 platformsSourceDeclared in the catalog source record
    Usage guideautomated source guideEditorialGenerated or reviewed according to the visible evidence level

    Pinned source

    Provenance and original SKILL.md

    Repository
    affaan-m/ECC
    Skill path
    skills/springboot-verification/SKILL.md
    Commit
    4e973d3eaf92d97f8d2e2d8abb39d8bdc8711b38
    License
    MIT
    Collected
    2026-07-28
    Default branch
    main
    View the original SKILL.md

    Spring Boot Verification Loop

    Run before PRs, after major changes, and pre-deploy.

    When to Activate

    • Before opening a pull request for a Spring Boot service
    • After major refactoring or dependency upgrades
    • Pre-deployment verification for staging or production
    • Running full build → lint → test → security scan pipeline
    • Validating test coverage meets thresholds

    Phase 1: Build

    mvn -T 4 clean verify -DskipTests
    # or
    ./gradlew clean assemble -x test
    

    If build fails, stop and fix.

    Phase 2: Static Analysis

    Maven (common plugins):

    mvn -T 4 spotbugs:check pmd:check checkstyle:check
    

    Gradle (if configured):

    ./gradlew checkstyleMain pmdMain spotbugsMain
    

    Phase 3: Tests + Coverage

    mvn -T 4 test
    mvn jacoco:report   # verify 80%+ coverage
    # or
    ./gradlew test jacocoTestReport
    

    Report:

    • Total tests, passed/failed
    • Coverage % (lines/branches)

    Unit Tests

    Test service logic in isolation with mocked dependencies:

    @ExtendWith(MockitoExtension.class)
    class UserServiceTest {
    
      @Mock private UserRepository userRepository;
      @InjectMocks private UserService userService;
    
      @Test
      void createUser_validInput_returnsUser() {
        var dto = new CreateUserDto("Alice", "alice@example.com");
        var expected = new User(1L, "Alice", "alice@example.com");
        when(userRepository.save(any(User.class))).thenReturn(expected);
    
        var result = userService.create(dto);
    
        assertThat(result.name()).isEqualTo("Alice");
        verify(userRepository).save(any(User.class));
      }
    
      @Test
      void createUser_duplicateEmail_throwsException() {
        var dto = new CreateUserDto("Alice", "existing@example.com");
        when(userRepository.existsByEmail(dto.email())).thenReturn(true);
    
        assertThatThrownBy(() -> userService.create(dto))
            .isInstanceOf(DuplicateEmailException.class);
      }
    }
    

    Integration Tests with Testcontainers

    Test against a real database instead of H2:

    @SpringBootTest
    @Testcontainers
    class UserRepositoryIntegrationTest {
    
      @Container
      static PostgreSQLContainer<?> postgres = new PostgreSQLContainer<>("postgres:16-alpine")
          .withDatabaseName("testdb");
    
      @DynamicPropertySource
      static void configureProperties(DynamicPropertyRegistry registry) {
        registry.add("spring.datasource.url", postgres::getJdbcUrl);
        registry.add("spring.datasource.username", postgres::getUsername);
        registry.add("spring.datasource.password", postgres::getPassword);
      }
    
      @Autowired private UserRepository userRepository;
    
      @Test
      void findByEmail_existingUser_returnsUser() {
        userRepository.save(new User("Alice", "alice@example.com"));
    
        var found = userRepository.findByEmail("alice@example.com");
    
        assertThat(found).isPresent();
        assertThat(found.get().getName()).isEqualTo("Alice");
      }
    }
    

    API Tests with MockMvc

    Test controller layer with full Spring context:

    @WebMvcTest(UserController.class)
    class UserControllerTest {
    
      @Autowired private MockMvc mockMvc;
      @MockBean private UserService userService;
    
      @Test
      void createUser_validInput_returns201() throws Exception {
        var user = new UserDto(1L, "Alice", "alice@example.com");
        when(userService.create(any())).thenReturn(user);
    
        mockMvc.perform(post("/api/users")
                .contentType(MediaType.APPLICATION_JSON)
                .content("""
                    {"name": "Alice", "email": "alice@example.com"}
                    """))
            .andExpect(status().isCreated())
            .andExpect(jsonPath("$.name").value("Alice"));
      }
    
      @Test
      void createUser_invalidEmail_returns400() throws Exception {
        mockMvc.perform(post("/api/users")
                .contentType(MediaType.APPLICATION_JSON)
                .content("""
                    {"name": "Alice", "email": "not-an-email"}
                    """))
            .andExpect(status().isBadRequest());
      }
    }
    

    Phase 4: Security Scan

    # Dependency CVEs
    mvn org.owasp:dependency-check-maven:check
    # or
    ./gradlew dependencyCheckAnalyze
    
    # Secrets in source
    grep -rn "password\s*=\s*\"" src/ --include="*.java" --include="*.yml" --include="*.properties"
    grep -rn "sk-\|api_key\|secret" src/ --include="*.java" --include="*.yml"
    
    # Secrets (git history)
    git secrets --scan  # if configured
    

    Common Security Findings

    # Check for System.out.println (use logger instead)
    grep -rn "System\.out\.print" src/main/ --include="*.java"
    
    # Check for raw exception messages in responses
    grep -rn "e\.getMessage()" src/main/ --include="*.java"
    
    # Check for wildcard CORS
    grep -rn "allowedOrigins.*\*" src/main/ --include="*.java"
    

    Phase 5: Lint/Format (optional gate)

    mvn spotless:apply   # if using Spotless plugin
    ./gradlew spotlessApply
    

    Phase 6: Diff Review

    git diff --stat
    git diff
    

    Checklist:

    • No debugging logs left (System.out, log.debug without guards)
    • Meaningful errors and HTTP statuses
    • Transactions and validation present where needed
    • Config changes documented

    Output Template

    VERIFICATION REPORT
    ===================
    Build:     [PASS/FAIL]
    Static:    [PASS/FAIL] (spotbugs/pmd/checkstyle)
    Tests:     [PASS/FAIL] (X/Y passed, Z% coverage)
    Security:  [PASS/FAIL] (CVE findings: N)
    Diff:      [X files changed]
    
    Overall:   [READY / NOT READY]
    
    Issues to Fix:
    1. ...
    2. ...
    

    Continuous Mode

    • Re-run phases on significant changes or every 30–60 minutes in long sessions
    • Keep a short loop: mvn -T 4 test + spotbugs for quick feedback

    Remember: Fast feedback beats late surprises. Keep the gate strict—treat warnings as defects in production systems.

    Alternatives

    Compare before choosing