Agent skill

Audit Jcache Conformance

by ben-manes in ben-manes/caffeine

“JSR-107 (JCache) spec-conformance audit”

— description from SKILL.md by ben-manes
Apache-2.0Auto-check: notes

Install Audit Jcache Conformance

skills CLI
$ npx skills add ben-manes/caffeine --skill audit-jcache-conformance -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ben-manes/caffeine audit-jcache-conformance --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ben-manes/caffeine.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/audit-jcache-conformance .claude/skills/audit-jcache-conformance && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-jcache-conformance
GitHub stars
18k
Token cost
~3.2k tokens
SKILL.md length
1,469 words
Files
1
Skills in repo
33
Repo updated
First seen
Licence
Apache-2.0

At a glance

  • Works in 4 steps: Load the spec and the resource map → Build the spec-surface matrix → Run the differential → …
  • SKILL.md covers When to run, Step 0: Load the spec and the…, Step 1: Build the spec-surface… and Step 2: Run the differential, plus 2 more sections
  • Calls curl; reaches docs.google.com

About this skill

Audit Jcache Conformance is a skill in ben-manes/caffeine (18k stars). Its SKILL.md is about 3.2k tokens. Licence: Apache-2.0.

Requirements

  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash, Agent, Write

Workflow steps

4 steps, taken from the step headings in SKILL.md.

  1. Load the spec and the resource map
  2. Build the spec-surface matrix
  3. Run the differential
  4. Resolve and pin

What it can do on your machine

Read from SKILL.md and the folder at commit e972fb0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash
    • Agent
    • Write

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • docs.google.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Jcache Conformance loads about 3.2k tokens when it runs. Until then it costs about 16 tokens; SKILL.md has 1,469 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~16
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash, Agent, Write

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ben-manes/caffeine at commit e972fb0, republished under its Apache-2.0 licence (© ben-manes). 1,469 words, ~3,228 tokens.

Download SKILL.mdSave it as .claude/skills/audit-jcache-conformance/SKILL.md (or your agent's skills folder).
name
audit-jcache-conformance
description
JSR-107 (JCache) spec-conformance audit
allowed-tools
Read, Grep, Glob, Bash, Agent, Write
context
fork
disable-model-invocation
true

Audit: JSR-107 Conformance

This audit verifies the jcache/ adapter against the full JSR-107 1.1.1 specification — every normative domain, not just the corners the last bug touched. It walks the spec surface and allocates depth by where the TCK is blind.

Why the TCK is the floor, not the verification. The TCK frequently asserts only the observable end-state (containsKey/get), not the event stream (CREATED/UPDATED/EXPIRED/REMOVED) or the statistics (CachePuts, hits/misses, removals, evictions). Two implementations with different events and different counts both pass. Every real bug found in this adapter recently lived in exactly that TCK-blind gap (zero-creation-expiry phantom CREATED; zero-update-expiry put-family suppressing UPDATED). So the audit goes DEEP (full spec→RI→ecosystem→internal-parity differential) on the event/statistic/ expiry/write-through surface, and runs a COVERAGE pass (spec-text correctness + confirm a test pins it) over the rest of the spec — escalating any COVERAGE clause that turns out to hide a TCK-invisible event or statistic to the DEEP differential.

This is a focused, resource-heavy specialization of /audit-sibling-divergence Group G2. Read .claude/docs/jsr107-conformance.md first — it is the resource map (live-fetch recipes, RI/ecosystem class locations for every domain below), the differential methodology, the parity-test pattern, and the catalogue of already-resolved divergences (do not re-flag those).

For this skill, the reference and its standing rulings are read before analysis, overriding the auditor's Phase 1.5 reading order for that document. Verify applicable rulings against current contracts and source before using them to adjudicate a finding.

When to run

  • After any change to jcache/src/main touching CacheProxy, LoadingCacheProxy, EntryProcessorEntry/postProcess, EventDispatcher, expiry, statistics, the write-through (CacheWriter) path, or store-by-value copying.
  • Before a release, as a comprehensive 1.1.1 re-verification.
  • Once per quarter as a conformance baseline.
  • When a /audit-sibling-divergence run raises a Group G2 finding — use this to resolve the direction (the static audit cannot, and has guessed wrong before).
  • Not for adapter concurrency: this audit is a single-threaded spec differential. Concurrency windows (live-view vs snapshot races, obligation pairing on executor threads, close/destroy symmetry) belong to /audit-subsystem-safety, /audit-memory-retention, /audit-lifecycle, and /audit-contract-drift's obligation sweep.

Heavyweight (fetches the spec, clones/fetches the ecosystem, may spawn sub-auditors). Not for routine pre-commit review.

Step 0: Load the spec and the resource map

Read .claude/docs/jsr107-conformance.md. Fetch the live spec:

bash
DOC=1ijduF_tmHvBaUS7VBBU2ZN8_eEBiFaXXg9OI0_ZxCrA
curl -fsSL "https://docs.google.com/document/d/$DOC/export?format=txt" -o /tmp/jsr107_spec.txt

Confirm it fetched the real spec (grep for getExpiryForUpdate), not an auth page. The export reflows; reference the spec by section name (the 1.1.1 section headings are listed per-domain in the matrix below). Locate the TCK sources (find ~/.gradle/caches -name 'cache-tests-1.1.1-test-sources.jar' and jcache/build/tck/).

Step 1: Build the spec-surface matrix

Walk the whole 1.1.1 spec. Map each normative domain to its spec section, its adapter code, and the depth it warrants. Do not stop at the write-path/expiry family — that is one DEEP domain among several, and the recent bugs there created a recency bias this matrix exists to correct.

Depth = DEEP — the TCK does not pin the event stream / statistic / expiry timing, so it can mask a real divergence. Run the full differential (Step 2) and add a parity-matrix test. Depth = COVERAGE — the spec text is unambiguous and the TCK's end-state assertion is sufficient. Confirm (a) the adapter matches the spec text and (b) a test pins it; cite the test. Escalate to DEEP the moment a hidden event/stat appears.

#Domain1.1.1 sectionDepthVerify
AWrite ops × expiryExpiry Policies; Statistics EffectsDEEPput/putAll/putIfAbsent/getAndPut/replace(K,V)/replace(K,V,V)/getAndReplace — creation-vs-update ZERO/ETERNAL/null expiry; CREATED/UPDATED emission; CachePuts count. Internal parity across all siblings.
BRead & accessExpiry Policies; Integration; Statistics EffectsDEEPget/getAll/containsKey/iterator — getExpiryForAccess ZERO/null/finite; CacheHits/CacheMisses (containsKey must not count); read-through load as get-miss-not-put
CRemove opsCache Entry Listeners; Integration; Statistics EffectsDEEPremove(K)/remove(K,V)/getAndRemove/removeAll(keys)/removeAll()/clear() — REMOVED event + oldValue; removeAll() counts removals, clear() does not; removal-stat gating on an already-expired entry; CacheWriter.delete
DEntry processorsEntry Processors; Statistics EffectsDEEPinvoke/invokeAll — EntryProcessorEntry.Action machine (NONE→READ/CREATED/UPDATED/LOADED/DELETED) vs RI MutableEntryOperation; per-op events + stats; read-through getValue() ending in LOADED counts a miss, not a put (catalogued — confirm, don't re-flag)
EEventsCache Entry ListenersDEEPCREATED/UPDATED/REMOVED/EXPIRED payload (isOldValueAvailable/getOldValue); synchronous vs asynchronous dispatch; CacheEntryEventFilter; per-key ordering (EventDispatcher CompletableFuture chains); runtime register/deregister
FStatisticsStatistics Effects of Cache OperationsDEEPThe full CacheStatisticsMXBean matrix: CacheHits/Misses/Gets/Puts/Removals/Evictions × every op. Failed putIfAbsent/replace accounting; CacheEvictions (the Caffeine-native-eviction→JCache-stat bridge — no sibling resolves this identically); CacheStatisticsMXBean.clear() resets every counter and timer; averages (the RI divides all three by CacheGets, so its put and remove means read 0 until a get)
GIntegration — writerIntegrationDEEPWrite-through: CacheWriter.write/delete ordering vs store and vs event/stat; a writer exception must suppress the event and the CachePuts increment; writeAll/deleteAll partial-failure collection mutation; CacheWriterException wrapping
HIntegration — loaderIntegrationDEEPRead-through get/getAll/invoke; loadAll replaceExistingValues + completion listener; CacheLoaderException wrapping (still required by the 1.1.1 CacheLoaderException javadoc, and asserted by the TCK for get and loadAll)
IStore-by-valueStore-By-Value and Store-By-ReferenceCOVERAGECopy points (put/get/iterator/event payloads); caller-mutation isolation; RISerializingInternalConverter vs RIReferenceInternalConverter. Escalate if a copy is skipped on an event/stat path
JTypesConfigurationCOVERAGEgetKeyType/getValueType metadata; exact type matching in getCache(name, K, V) (ClassCastException on mismatch); optional runtime type checking on put/get
KConfigurationConfigurationCOVERAGEMutableConfiguration snapshot-on-create; Factory<CacheLoader/CacheWriter/ExpiryPolicy>; read-through/write-through/store-by-value/stats/mgmt flags
LLifecycleCaching ProvidersCOVERAGEclose/isClosed → IllegalStateException on every op; CacheManager create(dup→CacheException)/get/destroy; getCacheNames immutable iterator; provider URI/classloader/properties
MManagementCaching Providers (MXBeans)COVERAGECacheMXBean attributes; JMX ObjectName sanitize (catalogued); enable/disable statistics & management at runtime
NNull / adversarial inputsmethod javadocsCOVERAGENullPointerException contract on null key/value/map/filter/processor args across the full API

(Annotations — CDI/Spring @CacheResult etc. — is a separate spec section the adapter does not implement; out of scope.)

Show full SKILL.md (581 more words)Show less

Step 2: Run the differential

For each DEEP domain corner, in order, until the reference behavior is unambiguous:

  1. Spec text — read the governing javadoc/table in /tmp/jsr107_spec.txt. Note deliberately-different wording between sibling operations (create-vs-update is the canonical trap).
  2. TCK — find the test and read what it asserts. End-state only → it cannot settle the event/stat question; proceed. (When TCK and spec javadoc disagree, TCK wins — see .claude/rules/jcache-adapter.md.)
  3. RI — read the oracle class for that domain (the doc's resource map names one per domain: RICache write/remove paths, RICacheStatisticsMXBean, RICacheEventDispatcher, RICache.writeCacheEntry/deleteCacheEntry, etc.).
  4. ≥3 ecosystem impls — fetch the adapter files named in the doc. Classify each; record any split.
  5. Caffeine internal parity — verify every sibling path agrees with the reference and with each other. Internal disagreement = the highest-signal finding (one side is provably wrong).

For each COVERAGE domain: confirm the adapter's behavior matches the spec text, and that a TCK or unit test pins it — cite the test by name. If the only test asserts end-state and the clause hides an event/stat (e.g. does clear() fire REMOVED? does a store-by-value copy happen on the event payload?), escalate that corner to DEEP and run the ladder above. A COVERAGE domain with a correct-but- untested clause is a coverage finding, not a pass.

Spawn one sub-auditor per domain-group — write/read/remove (A–C), entry processors (D), events (E), statistics (F), integration loader+writer (G–H), store-by-value/types/config/lifecycle/management (I–N) — each with the doc + the fetched spec as context, each required to return a concrete witness (operation sequence → divergent event/stat/end-state, or the test that pins the clause). Sub-agents cannot read session memory — paste the doc's divergence catalogue inline so they do not re-derive known false-positives. Direct each sub-auditor to write its report to a group-suffixed path (.local/audits/<model>/audit-jcache-conformance-<group>.md), never the canonical path: parallel groups writing audit-jcache-conformance.md overwrite each other (the 2026-07 run lost two group reports this way and had to recover them from agent transcripts).

Step 3: Resolve and pin

For each confirmed real divergence:

  • State the spec text, the RI behavior, the ecosystem tally, and the Caffeine internal-parity result. The fix direction follows the spec + RI; if the static finding assumed the opposite direction, say so (this has happened — the zero-update-expiry fix direction was inverted from what the static audit guessed).
  • Implement the fix as a minimal, surgical change, then add a parity-matrix test (writeOp_*/readOp_*/removeOp_* over every sibling op) asserting they all produce the same event count, statistic delta, and end-state. The TCK is not the regression guard — the parity test is.
  • Run :jcache:test and :jcache:tckTest (per .claude/rules/jcache-adapter.md; the TCK encodes interpretations unit tests miss).
  • Update .claude/docs/jsr107-conformance.md's catalogue and ecosystem matrix so the next run does not re-litigate it.

For a COVERAGE-tier clause that is correct but untested, record it as a coverage gap (which test to add), not a bug.

Output

The orchestrator (not the sub-auditors) writes .local/audits/<model>/audit-jcache-conformance.md — the consolidated adjudication across the group-suffixed reports — using the standard .claude/docs/finding-taxonomy.md schema (severity / category / confidence / classification).

Lead with the spec-surface coverage matrix: every domain A–N → depth → verdict (conformant / divergence / coverage-gap) → the witness or the pinning-test citation. A clean run must show every domain was reached, so "clean" means the full 1.1.1 surface was walked — not just the recent-bug corners.

Then, for each finding: the spec citation (by section name), the RI behavior, the ecosystem tally, the Caffeine internal-parity result, the witness (operation → divergent observable), and the resolution direction with its justification. A finding with no spec/RI/ecosystem backing for its direction is not ready — record it as escalated, not as a fix.

© ben-manes, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/audit-jcache-conformance of ben-manes/caffeine.

Open the folder on GitHubat commit e972fb0

Compare with similar skills

Audit Jcache Conformance next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Jcache Conformance compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Jcache Conformance this skillben-manes/caffeine18k—~3.2kAutomated safety check: NotesApache-2.0
Resolve Conformsamuelgursky/davinci-resolve-mcp3.4k—~2.1kAutomated safety check: PassMIT
Bio Conformer GenerationGPTomics/bioSkills1.2k2 repos~5.4kAutomated safety check: PassMIT
Tsz Conformancetsz-org/tsz577—~985Automated safety check: PassApache-2.0
Commonmark Conformancejolars/panache236—~1.1kAutomated safety check: PassMIT
HTML Conformancejolars/panache236—~5.6kAutomated safety check: PassMIT

Similar skills

  • Resolve Conform

    samuelgursky/davinci-resolve-mcp

    Conforming, relinking, and finishing prep in the DaVinci Resolve MCP.

    3.4k GitHub stars~2.1k tokensUpdated today
    Agent WorkflowsAuto-check passed
  • Bio Conformer Generation

    GPTomics/bioSkills

    Generates 3D conformer ensembles using RDKit ETKDGv3 with knowledge-enhanced distance geometry, MMFF94/UFF force-field optimization, CREST + GFN2-xTB semi-empirical refinement, and macrocycle-aware…

    1.2k GitHub starsUsed in 2 repos~5.4k tokens
    Research & ScienceAuto-check passed
  • Tsz Conformance

    tsz-org/tsz

    Triage and maintain TSZ diagnostic conformance. An agent skill from tsz-org/tsz.

    577 GitHub stars~985 tokensUpdated 29 days ago
    Auto-check passed
  • Grow Panache's CommonMark spec conformance under Flavor::CommonMark by running every spec.txt example through the shared parser, comparing rendered HTML against the spec's expected HTML…

    236 GitHub stars~1.1k tokensUpdated today
    DatabasesAuto-check passed
  • HTML Conformance

    jolars/panache

    Incrementally make Panache's CST shape for HTML-block / raw-HTML conform to pandoc's AST shape under Flavor::Pandoc, so downstream consumers (linter, salsa anchor index, LSP, formatter) see the same…

    236 GitHub stars~5.6k tokensUpdated today
    DevelopmentAuto-check passed
  • Xls Template Conformity

    XRPLF/XRPL-Standards

    Check that an XLS specification conforms to the XRPL-Standards templates.

    288 GitHub stars~859 tokensUpdated today
    DevelopmentAuto-check passed

More from ben-manes/caffeine

All 33 skills in this repo
  • Runs controlled JMH experiments on the Caffeine cache to find shared contention and hot-path waste, then reviews correctness and returns a reviewable patch.

    18k GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Git History Bug Audit

    ben-manes/caffeine

    Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings.

    18k GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Adversarial Codebase Audit

    ben-manes/caffeine

    Runs a hostile review of the Caffeine Java caching library with parallel subagents that get no design docs, then challenges and consolidates their findings.

    18k GitHub stars~1.9k tokensUpdated today
    Auto-check: notes
  • Caffeine Performance Audit

    ben-manes/caffeine

    Audits the Caffeine cache source for hot-path costs such as allocations, contention and memory layout, reporting only findings tied to specific lines.

    18k GitHub stars~559 tokensUpdated today
    Auto-check passed
  • Audit Sibling Divergence

    ben-manes/caffeine

    Compares code paths that should behave the same, such as sync and async cache methods, and requires a concrete scenario where the two observably disagree.

    18k GitHub stars~4.3k tokensUpdated today
    Auto-check: notes
  • Climber Step Minimization

    ben-manes/caffeine

    Prices each step of the window climber algorithm by disabling it in turn, to find steps that no longer earn their keep and branches that no longer fire.

    18k GitHub stars~3k tokensUpdated today
    Auto-check: notes

Questions about Audit Jcache Conformance

How do I install Audit Jcache Conformance in Claude Code?

Run `npx skills add ben-manes/caffeine --skill audit-jcache-conformance -a claude-code`. Or copy the skill folder (.claude/skills/audit-jcache-conformance in ben-manes/caffeine) into .claude/skills/audit-jcache-conformance in your project. Claude Code loads it when a task matches its description.

How do I install Audit Jcache Conformance in Codex?

Run `npx skills add ben-manes/caffeine --skill audit-jcache-conformance -a codex`. Or copy the skill folder (.claude/skills/audit-jcache-conformance in ben-manes/caffeine) into .agents/skills/audit-jcache-conformance in your project. Codex loads it when a task matches its description.

Can I use Audit Jcache Conformance in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ben-manes/caffeine --skill audit-jcache-conformance -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-jcache-conformance, .gemini/skills/audit-jcache-conformance, .github/skills/audit-jcache-conformance and .opencode/skills/audit-jcache-conformance in your project.

What does Audit Jcache Conformance need to run?

Going by SKILL.md and its folder, Audit Jcache Conformance needs the command-line tools its instructions call (curl). Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash, Agent, Write.

Does Audit Jcache Conformance access the network?

SKILL.md names 1 domain. In commands or code: docs.google.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Audit Jcache Conformance safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Audit Jcache Conformance use?

Audit Jcache Conformance is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Jcache Conformance use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Jcache Conformance?

Skills that share tags, products or a category with Audit Jcache Conformance: Resolve Conform (samuelgursky/davinci-resolve-mcp, 3.4k stars), Bio Conformer Generation (GPTomics/bioSkills, 1.2k stars), Tsz Conformance (tsz-org/tsz, 577 stars) and Commonmark Conformance (jolars/panache, 236 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Jcache Conformance?

ben-manes (a GitHub user) maintains it in ben-manes/caffeine, which has 17,881 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 9, 2026.

Source: ben-manes/caffeine on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.