Agent skill

Audit Map Contract

by ben-manes in ben-manes/caffeine

Audit ConcurrentMap and Map contract compliance for asMap() view

Apache-2.0Auto-check passed

Install Audit Map Contract

skills CLI
$ npx skills add ben-manes/caffeine --skill audit-map-contract -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ben-manes/caffeine audit-map-contract --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ben-manes/caffeine.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/audit-map-contract .claude/skills/audit-map-contract && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
audit-map-contract
GitHub stars
18k
Token cost
~2k tokens
SKILL.md length
830 words
Files
1
Skills in repo
33
Repo updated
First seen
Licence
Apache-2.0

At a glance

Audit ConcurrentMap and Map contract compliance for asMap() view

  • Works in 6 steps: Map contract: equals/hashCode… → ConcurrentMap contract:… → Null handling: NPE at the correct points… → …
  • SKILL.md covers Cross-reference the latest…, Alignment philosophy — close…, Settle divergences… and Audit dimensions
  • Reaches raw.githubusercontent.com

What it does

Audit Map Contract is an agent skill from ben-manes/caffeine. Audit ConcurrentMap and Map contract compliance for asMap() view

Its SKILL.md is about 2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It works with Java. The repository describes itself as: A high performance caching library for Java. The licence is Apache-2.0.

Example prompts

  • “/audit-map-contract”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Map contract: equals/hashCode consistency (and across map types — HashMap, TreeMap,
  2. ConcurrentMap contract: compute/computeIfAbsent/merge atomicity ("mapping function
  3. Null handling: NPE at the correct points for null keys/values on direct ops;
  4. Entry/EntrySet contracts: Map.Entry.setValue() write-through, entrySet
  5. Collection view contracts: keySet()/values()/entrySet() backed by the cache
  6. Cache semantics interaction: expired-but-present entries visible via asMap()?

What it can do on your machine

Read from SKILL.md and the folder at commit e972fb0. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • raw.githubusercontent.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Audit Map Contract loads about 2k tokens when it runs. Until then it costs about 21 tokens; SKILL.md has 830 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~21
When it runs · the whole SKILL.md, loaded when a task matches
~2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from ben-manes/caffeine at commit e972fb0, republished under its Apache-2.0 licence (© ben-manes). 830 words, ~2,039 tokens.

Download SKILL.mdSave it as .claude/skills/audit-map-contract/SKILL.md (or your agent's skills folder).
name
audit-map-contract
description
Audit ConcurrentMap and Map contract compliance for asMap() view
context
fork
agent
auditor
disable-model-invocation
true

Audit compliance with java.util.concurrent.ConcurrentMap and java.util.Map contracts, and Caffeine's alignment with the Java Collections Framework.

Cross-reference the latest OpenJDK source — do NOT reason from JavaDoc memory

The JavaDoc is silent or ambiguous on the behaviors that actually bite (null inside a bulk collection arg, containsAll(self), equals across map types, the optional NPE points, default-method bodies). WebFetch the real source and read the method body before asserting a contract. Track master (latest) — we stay pragmatically current, not pinned to a JDK version. Fetch the raw form (raw.githubusercontent.com/openjdk/jdk/master/src/ java.base/share/classes/…), not the blob page. These files are large (CHM ~6500 lines) and WebFetch answers a prompt over the content with a small model, so a generic "dump the file" truncates — prompt for the specific method ("quote the exact body of CollectionView.containsAll"), one method per fetch:

  • ConcurrentHashMap — the primary reference; asMap() is a ConcurrentMap and closest to CHM: https://raw.githubusercontent.com/openjdk/jdk/master/src/java.base/share/classes/java/util/concurrent/ConcurrentHashMap.java
  • ConcurrentSkipListMap — the other JDK ConcurrentMap; the tie-breaker on whether a divergence from CHM is legal (e.g. it also throws UOE on entrySet().add, where CHM's put-through is a nonstandard v8-rewrite addition): https://raw.githubusercontent.com/openjdk/jdk/master/src/java.base/share/classes/java/util/concurrent/ConcurrentSkipListMap.java
  • ConcurrentMap — interface + default methods (getOrDefault, compute*, merge, replaceAll): https://raw.githubusercontent.com/openjdk/jdk/master/src/java.base/share/classes/java/util/concurrent/ConcurrentMap.java
  • Map — base contract + interface default methods: https://raw.githubusercontent.com/openjdk/jdk/master/src/java.base/share/classes/java/util/Map.java
  • AbstractMap — the default-method bodies the views inherit (AbstractMap.equals, and via AbstractCollection/AbstractSet the containsAll/removeAll/retainAll loops): https://raw.githubusercontent.com/openjdk/jdk/master/src/java.base/share/classes/java/util/AbstractMap.java
  • HashMap — the most common equals/hashCode comparison target: https://raw.githubusercontent.com/openjdk/jdk/master/src/java.base/share/classes/java/util/HashMap.java
  • IdentityHashMap — identity-semantics edge, relevant to weak-key identity and the async future-keyed raw view: https://raw.githubusercontent.com/openjdk/jdk/master/src/java.base/share/classes/java/util/IdentityHashMap.java
  • WeakHashMap — relevant to weak keys with automatic removal: https://raw.githubusercontent.com/openjdk/jdk/master/src/java.base/share/classes/java/util/WeakHashMap.java
  • Guava LocalCache — the reference for Caffeine's Guava-compat behavior (the CaffeinatedGuava facade + the uniform null-leniency the philosophy below cites; its asMap() views, removal causes, loader/exception translation): https://raw.githubusercontent.com/google/guava/master/guava/src/com/google/common/cache/LocalCache.java

Alignment philosophy — close to CHM, diverge when better

Be pragmatically close to CHM, but Caffeine may diverge where its behavior is better — and when it does, the divergence must be coherent and recorded (design-decisions.md / the cross-model ledger). Do not treat "differs from CHM" as a bug by itself:

  • CHM is internally inconsistent. e.g. removeAll([null]) throws NPE while containsAll([null]) returns false — an artifact of which methods happened to get an explicit null-guard, not a contract. Don't chase CHM's inconsistencies.
  • Caffeine's own coherent principles are the target, not any one JDK map's quirks: null-hostile on direct single-element ops (put/get/containsKey/contains(null) → NPE — nulls are rejected), but null-tolerant of a null element in a bulk collection arg (containsAll/removeAll skip it — a null is trivially absent); weakly-consistent views; size() is an estimate; expired/collected entries filtered from queries and iteration. The CaffeinatedGuava facade is the deliberate exception — uniformly null-lenient (Guava-compat), overriding native null-hostility only where Guava diverges.
  • A contract-optional behavior (permitted NPE, ordering, equals across types) has a legal spread — check several impls (CHM / CSLM / HashMap / Guava), not one, and note that the collections testlibs usually tolerate both legal choices (e.g. guava-testlib testContainsAll_nullNotAllowed does assertFalse(...) with catch (NPE tolerated)). Flag a divergence only when Caffeine is the incoherent one, or diverges from both CHM and Guava with no better rationale.
Show full SKILL.md (353 more words)Show less

Settle divergences empirically, not from memory

For any "does Caffeine match CHM/Guava?" question, compile a tiny harness and run Caffeine side-by-side with real CHM / CSLM / Guava — don't guess (this session, "we mirror CHM" on containsAll([null]) was empirically wrong — both CHM and Guava return false, Caffeine NPE'd; and the CHMv8 entrySet().add history was non-obvious):

  • Classpath: the built jar caffeine/build/libs/caffeine-*.jar (it has the generated node classes like SSMS; build/classes/java/main does NOT → factory reflection throws), plus real guava from ~/.gradle/caches/**/guava-*.jar.
  • Run under JDK 26 (~/.gradle/jdks/*26*/**/bin/java) — the classes are that bytecode level.
  • Gotcha: a timeout … | grep pipeline reports grep's exit code, not gradle's — read the BUILD line.
  • For a native-view fix, AsMapTest's map param is polymorphic: compute=ASYNC yields the async sync-view (LocalAsyncCache.AsMapView), not BLC/ULC — a view change must cover it.
  • Cross-check the collections testlibs (:caffeine:googleTest/apacheTest/eclipseTest, :guava:test) — they encode the contract's tolerated spread.

Audit dimensions

  1. Map contract: equals/hashCode consistency (and across map types — HashMap, TreeMap, IdentityHashMap), putAll atomicity (if weigher throws mid-batch), replaceAll per-entry atomicity, containsValue consistency.

  2. ConcurrentMap contract: compute/computeIfAbsent/merge atomicity ("mapping function applied at most once"), getOrDefault on expired entries, forEach with concurrent mutations, compute returning null (should remove entry), the interface default methods.

  3. Null handling: NPE at the correct points for null keys/values on direct ops; null elements in bulk args (containsAll/removeAll/retainAll) per the philosophy above; mapping functions returning null (compute→remove, merge→remove); putIfAbsent(key, null).

  4. Entry/EntrySet contracts: Map.Entry.setValue() write-through, entrySet remove/contains checking both key AND value, snapshot vs live entries, entrySet().add UOE.

  5. Collection view contracts: keySet()/values()/entrySet() backed by the cache (bidirectional), contains/containsAll/remove/removeAll/retainAll/removeIf, containsAll(self) short-circuit, view equals/hashCode over the logical (filtered) set.

  6. Cache semantics interaction: expired-but-present entries visible via asMap()? Collected weak keys visible? asMap() operations triggering listeners? asMap().put() vs cache.put() differences (access time, stats, refresh)? Async raw view vs sync view.

For each finding: quote the requirement from the fetched OpenJDK source (the method + actual body, not remembered JavaDoc), show Caffeine's behavior (ideally via the harness), name the reference spread (CHM / CSLM / HashMap / Guava) and whether Caffeine is coherent, and provide a test case. If Caffeine's divergence is intentional and better, the output is a design-decisions.md / ledger note, not a bug.

© ben-manes, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/audit-map-contract of ben-manes/caffeine.

Open the folder on GitHubat commit e972fb0

Compare with similar skills

Audit Map Contract next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Audit Map Contract compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Audit Map Contract this skillben-manes/caffeine18k—~2kAutomated safety check: PassApache-2.0
Brainstormingxpinjection/test-driven-spring-boot11254 repos~2.6kAutomated safety check: PassMIT
Android API Diffgkd-kit/gkd43k—~796Automated safety check: PassGPL-3.0
Video Cover Imageitwanger/toBeBetterJavaer18k—~3.3kAutomated safety check: PassNone
Lancedb Update Lance Dependencylancedb/lancedb12k—~1.1kAutomated safety check: PassApache-2.0
Java SDK E2E Test with Replay Snapshotgithub/copilot-sdk11k—~1.8kAutomated safety check: PassMIT

Similar skills

  • Brainstorming

    xpinjection/test-driven-spring-boot

    You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior.

    112 GitHub starsUsed in 54 repos~2.6k tokens
    Agent WorkflowsAuto-check passed
  • Android API Diff

    gkd-kit/gkd

    Looks up Android framework Java and AIDL APIs across versions with the android-api-diff CLI: signatures, availability, source files and hidden-API access code.

    43k GitHub stars~796 tokensUpdated today
    MobileAuto-check passed
  • Video Cover Image

    itwanger/toBeBetterJavaer

    Generate matched 3:4, 16:9, and 4:3 short-video cover images from toBeBetterJavaer video scripts or AI/Java technical topics.

    18k GitHub stars~3.3k tokensUpdated today
    Media & CreativeAuto-check passed
  • Update LanceDB to a specific Lance release or tag. An agent skill from lancedb/lancedb.

    12k GitHub stars~1.1k tokensUpdated today
    DatabasesAuto-check passed
  • Official

    Creates a Java SDK end-to-end test for the Copilot SDK that runs against a recorded YAML snapshot through a replay proxy, so CI needs no real authentication.

    11k GitHub stars~1.8k tokensUpdated today
    Testing & QAAuto-check passed
  • Fory Release

    apache/fory

    Prepare an Apache Fory release candidate from a clean release branch, including the version bump, RC tag, JVM staging, ASF source artifacts, SVN upload, and vote email.

    4.6k GitHub stars~2.9k tokensUpdated yesterday
    Auto-check passed

More from ben-manes/caffeine

All 33 skills in this repo
  • Runs controlled JMH experiments on the Caffeine cache to find shared contention and hot-path waste, then reviews correctness and returns a reviewable patch.

    18k GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Git History Bug Audit

    ben-manes/caffeine

    Audits a module by walking its git history commit by commit, tracking unresolved issues forward, and reporting the ones that survive to HEAD as findings.

    18k GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Adversarial Codebase Audit

    ben-manes/caffeine

    Runs a hostile review of the Caffeine Java caching library with parallel subagents that get no design docs, then challenges and consolidates their findings.

    18k GitHub stars~1.9k tokensUpdated today
    Auto-check: notes
  • Caffeine Performance Audit

    ben-manes/caffeine

    Audits the Caffeine cache source for hot-path costs such as allocations, contention and memory layout, reporting only findings tied to specific lines.

    18k GitHub stars~559 tokensUpdated today
    Auto-check passed
  • Audit Sibling Divergence

    ben-manes/caffeine

    Compares code paths that should behave the same, such as sync and async cache methods, and requires a concrete scenario where the two observably disagree.

    18k GitHub stars~4.3k tokensUpdated today
    Auto-check: notes
  • Climber Step Minimization

    ben-manes/caffeine

    Prices each step of the window climber algorithm by disabling it in turn, to find steps that no longer earn their keep and branches that no longer fire.

    18k GitHub stars~3k tokensUpdated today
    Auto-check: notes

Works with

Questions about Audit Map Contract

What does Audit Map Contract do?

Audit ConcurrentMap and Map contract compliance for asMap() view. Audit Map Contract is an agent skill from ben-manes/caffeine.

How do I install Audit Map Contract in Claude Code?

Run `npx skills add ben-manes/caffeine --skill audit-map-contract -a claude-code`. Or copy the skill folder (.claude/skills/audit-map-contract in ben-manes/caffeine) into .claude/skills/audit-map-contract in your project. Claude Code loads it when a task matches its description.

How do I install Audit Map Contract in Codex?

Run `npx skills add ben-manes/caffeine --skill audit-map-contract -a codex`. Or copy the skill folder (.claude/skills/audit-map-contract in ben-manes/caffeine) into .agents/skills/audit-map-contract in your project. Codex loads it when a task matches its description.

Can I use Audit Map Contract in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ben-manes/caffeine --skill audit-map-contract -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/audit-map-contract, .gemini/skills/audit-map-contract, .github/skills/audit-map-contract and .opencode/skills/audit-map-contract in your project.

What does Audit Map Contract need to run?

SKILL.md names no scripts, command-line tools or credentials: Audit Map Contract is instructions for the agent only.

Does Audit Map Contract access the network?

SKILL.md names 1 domain. In commands or code: raw.githubusercontent.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.

Is Audit Map Contract safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Audit Map Contract use?

Audit Map Contract is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Audit Map Contract use?

About 2k tokens (SKILL.md is roughly 8.2k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Audit Map Contract?

Skills that share tags, products or a category with Audit Map Contract: Brainstorming (xpinjection/test-driven-spring-boot, 112 stars), Android API Diff (gkd-kit/gkd, 43k stars), Video Cover Image (itwanger/toBeBetterJavaer, 18k stars) and Lancedb Update Lance Dependency (lancedb/lancedb, 12k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Audit Map Contract?

ben-manes (a GitHub user) maintains it in ben-manes/caffeine, which has 17,881 GitHub stars. The repository holds 33 skills in this directory. The repository was last updated on October 9, 2026.

Source: ben-manes/caffeine on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.