Spring Boot
piomin/claude-ai-spring-boot
Spring Boot 3.x development - REST APIs, JPA, Security, Testing, and Cloud-native patterns.
Migrate Spring Security 5 to Spring Security 6 configuration.
$ npx skills add benchflow-ai/skillsbench --skill spring-security-6 -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install benchflow-ai/skillsbench spring-security-6 --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/benchflow-ai/skillsbench.git skills-src && mkdir -p .claude/skills && cp -r skills-src/tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6 .claude/skills/spring-security-6 && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "spring-security-6" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6 into .claude/skills/spring-security-6/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spring-security-6", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/benchflow-ai/skillsbench/tree/main/tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6Type this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add benchflow-ai/skillsbench --skill spring-security-6 -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install benchflow-ai/skillsbench spring-security-6 --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/benchflow-ai/skillsbench.git skills-src && mkdir -p .agents/skills && cp -r skills-src/tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6 .agents/skills/spring-security-6 && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "spring-security-6" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6 into .agents/skills/spring-security-6/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spring-security-6", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add benchflow-ai/skillsbench --skill spring-security-6 -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install benchflow-ai/skillsbench spring-security-6 --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/benchflow-ai/skillsbench.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6 .cursor/skills/spring-security-6 && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "spring-security-6" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6 into .cursor/skills/spring-security-6/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spring-security-6", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/benchflow-ai/skillsbench.git --path tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add benchflow-ai/skillsbench --skill spring-security-6 -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install benchflow-ai/skillsbench spring-security-6 --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/benchflow-ai/skillsbench.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6 .gemini/skills/spring-security-6 && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "spring-security-6" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6 into .gemini/skills/spring-security-6/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spring-security-6", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install benchflow-ai/skillsbench spring-security-6Installs for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add benchflow-ai/skillsbench --skill spring-security-6 -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/benchflow-ai/skillsbench.git skills-src && mkdir -p .github/skills && cp -r skills-src/tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6 .github/skills/spring-security-6 && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "spring-security-6" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6 into .github/skills/spring-security-6/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spring-security-6", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add benchflow-ai/skillsbench --skill spring-security-6 -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install benchflow-ai/skillsbench spring-security-6 --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/benchflow-ai/skillsbench.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6 .opencode/skills/spring-security-6 && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "spring-security-6" agent skill from https://github.com/benchflow-ai/skillsbench/tree/main/tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6 into .opencode/skills/spring-security-6/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spring-security-6", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
spring-security-6Migrate Spring Security 5 to Spring Security 6 configuration.
Spring Security 6 is an agent skill from benchflow-ai/skillsbench. Migrate Spring Security 5 to Spring Security 6 configuration. Use when removing WebSecurityConfigurerAdapter, replacing @EnableGlobalMethodSecurity with @EnableMethodSecurity, converting antMatchers to requestMatchers, or updating to lambda DSL configuration style. Covers SecurityFilterChain beans and authentication manager changes.
Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Backend & APIs, covering Backend development. It works with Spring Boot. The repository describes itself as: SkillsBench evaluates how well skills work and how effective agents are at using them. The licence is Apache-2.0.
11 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 9a1f4dd. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md (its code samples are java and bash).
From the folder's file list and the shell code blocks in SKILL.md.
Links to these hosts (documentation or services it may open):
baeldung.comdocs.spring.ioFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Spring Security 6 loads about 3.2k tokens when it runs. Until then it costs about 88 tokens; SKILL.md has 311 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from benchflow-ai/skillsbench at commit 9a1f4dd, republished under its Apache-2.0 licence (© benchflow-ai). 311 words, ~3,247 tokens.
.claude/skills/spring-security-6/SKILL.md (or your agent's skills folder).Spring Security 6 (included in Spring Boot 3) removes the deprecated WebSecurityConfigurerAdapter and introduces a component-based configuration approach using SecurityFilterChain beans.
The biggest change is moving from class extension to bean configuration.
@Configuration
@EnableWebSecurity
@EnableGlobalMethodSecurity(prePostEnabled = true)
public class SecurityConfig extends WebSecurityConfigurerAdapter {
@Autowired
private UserDetailsService userDetailsService;
@Override
protected void configure(AuthenticationManagerBuilder auth) throws Exception {
auth.userDetailsService(userDetailsService)
.passwordEncoder(passwordEncoder());
}
@Override
protected void configure(HttpSecurity http) throws Exception {
http
.csrf().disable()
.sessionManagement()
.sessionCreationPolicy(SessionCreationPolicy.STATELESS)
.and()
.authorizeRequests()
.antMatchers("/api/public/**").permitAll()
.anyRequest().authenticated();
}
@Bean
@Override
public AuthenticationManager authenticationManagerBean() throws Exception {
return super.authenticationManagerBean();
}
}@Configuration
@EnableWebSecurity
@EnableMethodSecurity(prePostEnabled = true)
public class SecurityConfig {
@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
http
.csrf(csrf -> csrf.disable())
.sessionManagement(session ->
session.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
.authorizeHttpRequests(auth -> auth
.requestMatchers("/api/public/**").permitAll()
.anyRequest().authenticated()
);
return http.build();
}
@Bean
public AuthenticationManager authenticationManager(
AuthenticationConfiguration authConfig) throws Exception {
return authConfig.getAuthenticationManager();
}
@Bean
public PasswordEncoder passwordEncoder() {
return new BCryptPasswordEncoder();
}
}This is a required change. The @EnableGlobalMethodSecurity annotation is removed in Spring Security 6 and must be replaced with @EnableMethodSecurity.
// BEFORE (Spring Security 5 / Spring Boot 2) - WILL NOT COMPILE in Spring Boot 3
@EnableGlobalMethodSecurity(prePostEnabled = true)
// AFTER (Spring Security 6 / Spring Boot 3) - REQUIRED
@EnableMethodSecurity(prePostEnabled = true)// BEFORE
import org.springframework.security.config.annotation.method.configuration.EnableGlobalMethodSecurity;
// AFTER
import org.springframework.security.config.annotation.method.configuration.EnableMethodSecurity;# Replace the annotation in all Java files
find . -name "*.java" -type f -exec sed -i 's/@EnableGlobalMethodSecurity/@EnableMethodSecurity/g' {} +
# Also update the import statement
find . -name "*.java" -type f -exec sed -i 's/EnableGlobalMethodSecurity/EnableMethodSecurity/g' {} +After migration, confirm the new annotation exists:
# This should return results showing your security config class
grep -r "@EnableMethodSecurity" --include="*.java" .If this returns no results but you're using method-level security (@PreAuthorize, @PostAuthorize, etc.), the migration is incomplete.
Spring Security 6 uses lambda-based configuration:
// Before (chained methods)
http
.csrf().disable()
.cors().and()
.sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS)
.and()
.authorizeRequests()
.antMatchers("/public/**").permitAll()
.anyRequest().authenticated();
// After (lambda DSL)
http
.csrf(csrf -> csrf.disable())
.cors(cors -> cors.configurationSource(corsConfigurationSource()))
.sessionManagement(session ->
session.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
.authorizeHttpRequests(auth -> auth
.requestMatchers("/public/**").permitAll()
.anyRequest().authenticated()
);antMatchers() is replaced with requestMatchers():
// Before
.antMatchers("/api/**").authenticated()
.antMatchers(HttpMethod.POST, "/api/users").permitAll()
// After
.requestMatchers("/api/**").authenticated()
.requestMatchers(HttpMethod.POST, "/api/users").permitAll()// Before
.exceptionHandling()
.authenticationEntryPoint((request, response, ex) -> {
response.sendError(HttpServletResponse.SC_UNAUTHORIZED);
})
.and()
// After
.exceptionHandling(ex -> ex
.authenticationEntryPoint((request, response, authException) -> {
response.sendError(HttpServletResponse.SC_UNAUTHORIZED,
authException.getMessage());
})
)// Before
.headers().frameOptions().disable()
// After
.headers(headers -> headers
.frameOptions(frame -> frame.disable())
)// The UserDetailsService bean is auto-detected
// No need to explicitly configure in AuthenticationManagerBuilder
@Service
public class CustomUserDetailsService implements UserDetailsService {
@Override
public UserDetails loadUserByUsername(String username) {
// Implementation
}
}@Configuration
@EnableWebSecurity
@EnableGlobalMethodSecurity(prePostEnabled = true)
public class SecurityConfig extends WebSecurityConfigurerAdapter {
@Autowired
private UserDetailsService userDetailsService;
@Bean
public PasswordEncoder passwordEncoder() {
return new BCryptPasswordEncoder();
}
@Override
protected void configure(AuthenticationManagerBuilder auth) throws Exception {
auth.userDetailsService(userDetailsService)
.passwordEncoder(passwordEncoder());
}
@Override
@Bean
public AuthenticationManager authenticationManagerBean() throws Exception {
return super.authenticationManagerBean();
}
@Override
protected void configure(HttpSecurity http) throws Exception {
http
.csrf().disable()
.sessionManagement()
.sessionCreationPolicy(SessionCreationPolicy.STATELESS)
.and()
.exceptionHandling()
.authenticationEntryPoint((request, response, ex) -> {
response.sendError(HttpServletResponse.SC_UNAUTHORIZED, ex.getMessage());
})
.and()
.authorizeRequests()
.antMatchers(HttpMethod.POST, "/api/users").permitAll()
.antMatchers("/api/auth/**").permitAll()
.antMatchers("/h2-console/**").permitAll()
.antMatchers("/actuator/health").permitAll()
.anyRequest().authenticated()
.and()
.headers().frameOptions().disable();
}
}@Configuration
@EnableWebSecurity
@EnableMethodSecurity(prePostEnabled = true)
public class SecurityConfig {
@Bean
public PasswordEncoder passwordEncoder() {
return new BCryptPasswordEncoder();
}
@Bean
public AuthenticationManager authenticationManager(
AuthenticationConfiguration authConfig) throws Exception {
return authConfig.getAuthenticationManager();
}
@Bean
public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
http
.csrf(csrf -> csrf.disable())
.sessionManagement(session ->
session.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
.exceptionHandling(ex -> ex
.authenticationEntryPoint((request, response, authException) -> {
response.sendError(HttpServletResponse.SC_UNAUTHORIZED,
authException.getMessage());
})
)
.authorizeHttpRequests(auth -> auth
.requestMatchers(HttpMethod.POST, "/api/users").permitAll()
.requestMatchers("/api/auth/**").permitAll()
.requestMatchers("/h2-console/**").permitAll()
.requestMatchers("/actuator/health").permitAll()
.anyRequest().authenticated()
)
.headers(headers -> headers
.frameOptions(frame -> frame.disable())
);
return http.build();
}
}Don't forget the servlet import change:
// Before
import javax.servlet.http.HttpServletResponse;
// After
import jakarta.servlet.http.HttpServletResponse;Update security test annotations if needed:
@SpringBootTest
@AutoConfigureMockMvc
class SecurityTests {
@Test
@WithMockUser(roles = "ADMIN")
void adminEndpoint_withAdminUser_shouldSucceed() {
// Test implementation
}
}# Find classes extending WebSecurityConfigurerAdapter
grep -r "extends WebSecurityConfigurerAdapter" --include="*.java" .
# The class must be refactored - cannot be automated with sed# Replace @EnableGlobalMethodSecurity with @EnableMethodSecurity
find . -name "*.java" -type f -exec sed -i 's/@EnableGlobalMethodSecurity/@EnableMethodSecurity/g' {} +
# Update import
find . -name "*.java" -type f -exec sed -i 's/import org.springframework.security.config.annotation.method.configuration.EnableGlobalMethodSecurity/import org.springframework.security.config.annotation.method.configuration.EnableMethodSecurity/g' {} +# Replace antMatchers
find . -name "*.java" -type f -exec sed -i 's/\.antMatchers(/.requestMatchers(/g' {} +
# Replace mvcMatchers
find . -name "*.java" -type f -exec sed -i 's/\.mvcMatchers(/.requestMatchers(/g' {} +
# Replace regexMatchers
find . -name "*.java" -type f -exec sed -i 's/\.regexMatchers(/.requestMatchers(/g' {} +find . -name "*.java" -type f -exec sed -i 's/\.authorizeRequests(/.authorizeHttpRequests(/g' {} +# Should return NO results
grep -r "WebSecurityConfigurerAdapter" --include="*.java" .
grep -r "@EnableGlobalMethodSecurity" --include="*.java" .
grep -r "\.antMatchers(" --include="*.java" .
grep -r "\.authorizeRequests(" --include="*.java" .# Should return results
grep -r "@EnableMethodSecurity" --include="*.java" .
grep -r "SecurityFilterChain" --include="*.java" .
grep -r "\.requestMatchers(" --include="*.java" .
grep -r "\.authorizeHttpRequests(" --include="*.java" .@Configuration is now required separately - Before Spring Security 6, @Configuration was part of @EnableWebSecurity. Now you must add it explicitly.
Lambda DSL is mandatory - The old chained method style (http.csrf().disable().and()...) is deprecated and must be converted to lambda style.
AuthenticationManager injection changed - Use AuthenticationConfiguration.getAuthenticationManager() instead of overriding authenticationManagerBean().
UserDetailsService auto-detection - Spring Security 6 automatically detects UserDetailsService beans; no need for explicit configuration.
Method security default changes - @EnableMethodSecurity enables @PreAuthorize and @PostAuthorize by default (unlike the old annotation).
© benchflow-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6 of benchflow-ai/skillsbench.
Open the folder on GitHubat commit 9a1f4dd
Spring Security 6 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Spring Security 6 this skillbenchflow-ai/skillsbench | 1.8k | — | ~3.2k | Automated safety check: Pass | Apache-2.0 | |
| Spring Bootpiomin/claude-ai-spring-boot | 1.3k | — | ~2k | Automated safety check: Pass | Apache-2.0 | |
| Dr Jskilljdubois/dr-jskill | 342 | — | ~4.6k | Automated safety check: Notes | Apache-2.0 | |
| WxJava Integration Guidebinarywang/WxJava | 33k | — | ~123 | Automated safety check: Pass | Apache-2.0 | |
| Grails Developer Guideapache/grails-core | 2.9k | — | ~4.9k | Automated safety check: Pass | Apache-2.0 | |
| Flycms Devsunkaifei/FlyCms | 656 | — | ~827 | Automated safety check: Pass | MIT |
piomin/claude-ai-spring-boot
Spring Boot 3.x development - REST APIs, JPA, Security, Testing, and Cloud-native patterns.
jdubois/dr-jskill
Creates Java + Spring Boot projects: Web applications, full-stack apps with Vue.js or Angular or React or vanilla JS, PostgreSQL, REST APIs, and Docker.
binarywang/WxJava
Plans a WxJava setup for Java, Spring Boot or Solon projects that call WeChat services, from module and BOM choice to config and a minimal working call.
apache/grails-core
Guides building Grails web applications and REST APIs with GORM, controllers, services, views, plugins and Spock and Geb testing.
sunkaifei/FlyCms
FlyCms 项目(backend/ Spring Boot 4.1.1 + frontend/ vue-vben-admin v5)的架构地图与开发规范总纲。凡在本仓库做任何开发——写后端接口、新增/修改模块、管理页面、数据库变更、修 bug、重构——都要先加载本 skill 再动手,即使用户只说"改一下""加个功能";前端登录/菜单/权限专项另见…
ruanrongman/IntelliConnect
Create or update IntelliConnect Spring Boot service/serviceimpl code in this repository style.
benchflow-ai/skillsbench
This skill should be used when working on Lean 4 formalization projects to maintain persistent memory of successful proof patterns, failed approaches, project conventions, and user preferences…
benchflow-ai/skillsbench
World-class data engineering skill for building scalable data pipelines, ETL/ELT systems, real-time streaming, and data infrastructure.
benchflow-ai/skillsbench
AC branch pi-model power flow equations (P/Q and |S|) with transformer tap ratio and phase shift, matching acopf-math-model.md and MATPOWER branch fields.
benchflow-ai/skillsbench
Civilization 6 district mechanics library. An agent skill from benchflow-ai/skillsbench.
benchflow-ai/skillsbench
Build deterministic, verifiable data visualizations with D3.js (v6).
benchflow-ai/skillsbench
DC power flow analysis for power systems. An agent skill from benchflow-ai/skillsbench.
Works with
Categories
Migrate Spring Security 5 to Spring Security 6 configuration. Spring Security 6 is an agent skill from benchflow-ai/skillsbench. Migrate Spring Security 5 to Spring Security 6 configuration.
Spring Security 6 fits situations like: removing WebSecurityConfigurerAdapter; replacing @EnableGlobalMethodSecurity with @EnableMethodSecurity; converting antMatchers to requestMatchers; updating to lambda DSL configuration style.
Run `npx skills add benchflow-ai/skillsbench --skill spring-security-6 -a claude-code`. Or copy the skill folder (tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6 in benchflow-ai/skillsbench) into .claude/skills/spring-security-6 in your project. Claude Code loads it when a task matches its description.
Run `npx skills add benchflow-ai/skillsbench --skill spring-security-6 -a codex`. Or copy the skill folder (tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6 in benchflow-ai/skillsbench) into .agents/skills/spring-security-6 in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add benchflow-ai/skillsbench --skill spring-security-6 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spring-security-6, .gemini/skills/spring-security-6, .github/skills/spring-security-6 and .opencode/skills/spring-security-6 in your project.
SKILL.md names no scripts, command-line tools or credentials: Spring Security 6 is instructions for the agent only.
SKILL.md names 2 domains. As links in the text: baeldung.com and docs.spring.io. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Spring Security 6 is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Spring Security 6: Spring Boot (piomin/claude-ai-spring-boot, 1.3k stars), Dr Jskill (jdubois/dr-jskill, 342 stars), WxJava Integration Guide (binarywang/WxJava, 33k stars) and Grails Developer Guide (apache/grails-core, 2.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
benchflow-ai (a GitHub organization) maintains it in benchflow-ai/skillsbench, which has 1,832 GitHub stars. The repository holds 178 skills in this directory. The repository was last updated on July 23, 2026.
Source: benchflow-ai/skillsbench on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.