Agent skill

Spring Security 6

by benchflow-ai in benchflow-ai/skillsbench

Migrate Spring Security 5 to Spring Security 6 configuration.

Apache-2.0Auto-check passedBackend & APIs

Install Spring Security 6

skills CLI
$ npx skills add benchflow-ai/skillsbench --skill spring-security-6 -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install benchflow-ai/skillsbench spring-security-6 --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/benchflow-ai/skillsbench.git skills-src && mkdir -p .claude/skills && cp -r skills-src/tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6 .claude/skills/spring-security-6 && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
spring-security-6
GitHub stars
1.8k
Token cost
~3.2k tokens
SKILL.md length
311 words
Files
1
Skills in repo
178
Repo updated
First seen
Licence
Apache-2.0

At a glance

Migrate Spring Security 5 to Spring Security 6 configuration.

  • Works in 11 steps: Remove WebSecurityConfigurerAdapter → Method Security Annotation Change… → Lambda DSL Configuration → …
  • Removing WebSecurityConfigurerAdapter
  • SKILL.md covers Overview, Key Changes, Complete Migration Example and Servlet Namespace Change, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Spring Security 6 is an agent skill from benchflow-ai/skillsbench. Migrate Spring Security 5 to Spring Security 6 configuration. Use when removing WebSecurityConfigurerAdapter, replacing @EnableGlobalMethodSecurity with @EnableMethodSecurity, converting antMatchers to requestMatchers, or updating to lambda DSL configuration style. Covers SecurityFilterChain beans and authentication manager changes.

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Backend development. It works with Spring Boot. The repository describes itself as: SkillsBench evaluates how well skills work and how effective agents are at using them. The licence is Apache-2.0.

When your agent uses it

  • Removing WebSecurityConfigurerAdapter
  • Replacing @EnableGlobalMethodSecurity with @EnableMethodSecurity
  • Converting antMatchers to requestMatchers
  • Updating to lambda DSL configuration style

Example prompts

  • “/spring-security-6”

Workflow steps

11 steps, taken from the step headings in SKILL.md.

  1. Remove WebSecurityConfigurerAdapter
  2. Method Security Annotation Change (CRITICAL)
  3. Lambda DSL Configuration
  4. URL Matching Changes
  5. Exception Handling
  6. Headers Configuration
  7. UserDetailsService Configuration
  8. Remove WebSecurityConfigurerAdapter
  9. Replace Method Security Annotation
  10. Replace antMatchers with requestMatchers
  11. Replace authorizeRequests with authorizeHttpRequests

What it can do on your machine

Read from SKILL.md and the folder at commit 9a1f4dd. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are java and bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • baeldung.com
    • docs.spring.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Spring Security 6 loads about 3.2k tokens when it runs. Until then it costs about 88 tokens; SKILL.md has 311 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~88
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from benchflow-ai/skillsbench at commit 9a1f4dd, republished under its Apache-2.0 licence (© benchflow-ai). 311 words, ~3,247 tokens.

Download SKILL.mdSave it as .claude/skills/spring-security-6/SKILL.md (or your agent's skills folder).
name
spring-security-6
description
Migrate Spring Security 5 to Spring Security 6 configuration. Use when removing WebSecurityConfigurerAdapter, replacing @EnableGlobalMethodSecurity with @EnableMethodSecurity, converting antMatchers to requestMatchers, or updating to lambda DSL configuration style. Covers SecurityFilterChain beans and authentication manager changes.

Spring Security 6 Migration Skill

Overview

Spring Security 6 (included in Spring Boot 3) removes the deprecated WebSecurityConfigurerAdapter and introduces a component-based configuration approach using SecurityFilterChain beans.

Key Changes

1. Remove WebSecurityConfigurerAdapter

The biggest change is moving from class extension to bean configuration.

Before (Spring Security 5 / Spring Boot 2)
java
@Configuration
@EnableWebSecurity
@EnableGlobalMethodSecurity(prePostEnabled = true)
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Autowired
    private UserDetailsService userDetailsService;

    @Override
    protected void configure(AuthenticationManagerBuilder auth) throws Exception {
        auth.userDetailsService(userDetailsService)
            .passwordEncoder(passwordEncoder());
    }

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .csrf().disable()
            .sessionManagement()
                .sessionCreationPolicy(SessionCreationPolicy.STATELESS)
            .and()
            .authorizeRequests()
                .antMatchers("/api/public/**").permitAll()
                .anyRequest().authenticated();
    }

    @Bean
    @Override
    public AuthenticationManager authenticationManagerBean() throws Exception {
        return super.authenticationManagerBean();
    }
}
After (Spring Security 6 / Spring Boot 3)
java
@Configuration
@EnableWebSecurity
@EnableMethodSecurity(prePostEnabled = true)
public class SecurityConfig {

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .csrf(csrf -> csrf.disable())
            .sessionManagement(session ->
                session.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
            .authorizeHttpRequests(auth -> auth
                .requestMatchers("/api/public/**").permitAll()
                .anyRequest().authenticated()
            );
        return http.build();
    }

    @Bean
    public AuthenticationManager authenticationManager(
            AuthenticationConfiguration authConfig) throws Exception {
        return authConfig.getAuthenticationManager();
    }

    @Bean
    public PasswordEncoder passwordEncoder() {
        return new BCryptPasswordEncoder();
    }
}
2. Method Security Annotation Change (CRITICAL)

This is a required change. The @EnableGlobalMethodSecurity annotation is removed in Spring Security 6 and must be replaced with @EnableMethodSecurity.

java
// BEFORE (Spring Security 5 / Spring Boot 2) - WILL NOT COMPILE in Spring Boot 3
@EnableGlobalMethodSecurity(prePostEnabled = true)

// AFTER (Spring Security 6 / Spring Boot 3) - REQUIRED
@EnableMethodSecurity(prePostEnabled = true)
Import Change
java
// BEFORE
import org.springframework.security.config.annotation.method.configuration.EnableGlobalMethodSecurity;

// AFTER
import org.springframework.security.config.annotation.method.configuration.EnableMethodSecurity;
Quick Migration Command
bash
# Replace the annotation in all Java files
find . -name "*.java" -type f -exec sed -i 's/@EnableGlobalMethodSecurity/@EnableMethodSecurity/g' {} +

# Also update the import statement
find . -name "*.java" -type f -exec sed -i 's/EnableGlobalMethodSecurity/EnableMethodSecurity/g' {} +
Verify @EnableMethodSecurity Is Present

After migration, confirm the new annotation exists:

bash
# This should return results showing your security config class
grep -r "@EnableMethodSecurity" --include="*.java" .

If this returns no results but you're using method-level security (@PreAuthorize, @PostAuthorize, etc.), the migration is incomplete.

3. Lambda DSL Configuration

Spring Security 6 uses lambda-based configuration:

java
// Before (chained methods)
http
    .csrf().disable()
    .cors().and()
    .sessionManagement().sessionCreationPolicy(SessionCreationPolicy.STATELESS)
    .and()
    .authorizeRequests()
        .antMatchers("/public/**").permitAll()
        .anyRequest().authenticated();

// After (lambda DSL)
http
    .csrf(csrf -> csrf.disable())
    .cors(cors -> cors.configurationSource(corsConfigurationSource()))
    .sessionManagement(session ->
        session.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
    .authorizeHttpRequests(auth -> auth
        .requestMatchers("/public/**").permitAll()
        .anyRequest().authenticated()
    );
4. URL Matching Changes

antMatchers() is replaced with requestMatchers():

java
// Before
.antMatchers("/api/**").authenticated()
.antMatchers(HttpMethod.POST, "/api/users").permitAll()

// After
.requestMatchers("/api/**").authenticated()
.requestMatchers(HttpMethod.POST, "/api/users").permitAll()
5. Exception Handling
java
// Before
.exceptionHandling()
    .authenticationEntryPoint((request, response, ex) -> {
        response.sendError(HttpServletResponse.SC_UNAUTHORIZED);
    })
.and()

// After
.exceptionHandling(ex -> ex
    .authenticationEntryPoint((request, response, authException) -> {
        response.sendError(HttpServletResponse.SC_UNAUTHORIZED,
            authException.getMessage());
    })
)
6. Headers Configuration
java
// Before
.headers().frameOptions().disable()

// After
.headers(headers -> headers
    .frameOptions(frame -> frame.disable())
)
7. UserDetailsService Configuration
java
// The UserDetailsService bean is auto-detected
// No need to explicitly configure in AuthenticationManagerBuilder

@Service
public class CustomUserDetailsService implements UserDetailsService {

    @Override
    public UserDetails loadUserByUsername(String username) {
        // Implementation
    }
}

Complete Migration Example

Before (Spring Boot 2.x)
java
@Configuration
@EnableWebSecurity
@EnableGlobalMethodSecurity(prePostEnabled = true)
public class SecurityConfig extends WebSecurityConfigurerAdapter {

    @Autowired
    private UserDetailsService userDetailsService;

    @Bean
    public PasswordEncoder passwordEncoder() {
        return new BCryptPasswordEncoder();
    }

    @Override
    protected void configure(AuthenticationManagerBuilder auth) throws Exception {
        auth.userDetailsService(userDetailsService)
            .passwordEncoder(passwordEncoder());
    }

    @Override
    @Bean
    public AuthenticationManager authenticationManagerBean() throws Exception {
        return super.authenticationManagerBean();
    }

    @Override
    protected void configure(HttpSecurity http) throws Exception {
        http
            .csrf().disable()
            .sessionManagement()
                .sessionCreationPolicy(SessionCreationPolicy.STATELESS)
            .and()
            .exceptionHandling()
                .authenticationEntryPoint((request, response, ex) -> {
                    response.sendError(HttpServletResponse.SC_UNAUTHORIZED, ex.getMessage());
                })
            .and()
            .authorizeRequests()
                .antMatchers(HttpMethod.POST, "/api/users").permitAll()
                .antMatchers("/api/auth/**").permitAll()
                .antMatchers("/h2-console/**").permitAll()
                .antMatchers("/actuator/health").permitAll()
                .anyRequest().authenticated()
            .and()
            .headers().frameOptions().disable();
    }
}
After (Spring Boot 3.x)
java
@Configuration
@EnableWebSecurity
@EnableMethodSecurity(prePostEnabled = true)
public class SecurityConfig {

    @Bean
    public PasswordEncoder passwordEncoder() {
        return new BCryptPasswordEncoder();
    }

    @Bean
    public AuthenticationManager authenticationManager(
            AuthenticationConfiguration authConfig) throws Exception {
        return authConfig.getAuthenticationManager();
    }

    @Bean
    public SecurityFilterChain securityFilterChain(HttpSecurity http) throws Exception {
        http
            .csrf(csrf -> csrf.disable())
            .sessionManagement(session ->
                session.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
            .exceptionHandling(ex -> ex
                .authenticationEntryPoint((request, response, authException) -> {
                    response.sendError(HttpServletResponse.SC_UNAUTHORIZED,
                        authException.getMessage());
                })
            )
            .authorizeHttpRequests(auth -> auth
                .requestMatchers(HttpMethod.POST, "/api/users").permitAll()
                .requestMatchers("/api/auth/**").permitAll()
                .requestMatchers("/h2-console/**").permitAll()
                .requestMatchers("/actuator/health").permitAll()
                .anyRequest().authenticated()
            )
            .headers(headers -> headers
                .frameOptions(frame -> frame.disable())
            );

        return http.build();
    }
}

Servlet Namespace Change

Don't forget the servlet import change:

java
// Before
import javax.servlet.http.HttpServletResponse;

// After
import jakarta.servlet.http.HttpServletResponse;

Testing Security

Update security test annotations if needed:

java
@SpringBootTest
@AutoConfigureMockMvc
class SecurityTests {

    @Test
    @WithMockUser(roles = "ADMIN")
    void adminEndpoint_withAdminUser_shouldSucceed() {
        // Test implementation
    }
}

Migration Commands Summary

Step 1: Remove WebSecurityConfigurerAdapter
bash
# Find classes extending WebSecurityConfigurerAdapter
grep -r "extends WebSecurityConfigurerAdapter" --include="*.java" .

# The class must be refactored - cannot be automated with sed
Step 2: Replace Method Security Annotation
bash
# Replace @EnableGlobalMethodSecurity with @EnableMethodSecurity
find . -name "*.java" -type f -exec sed -i 's/@EnableGlobalMethodSecurity/@EnableMethodSecurity/g' {} +

# Update import
find . -name "*.java" -type f -exec sed -i 's/import org.springframework.security.config.annotation.method.configuration.EnableGlobalMethodSecurity/import org.springframework.security.config.annotation.method.configuration.EnableMethodSecurity/g' {} +
Step 3: Replace antMatchers with requestMatchers
bash
# Replace antMatchers
find . -name "*.java" -type f -exec sed -i 's/\.antMatchers(/.requestMatchers(/g' {} +

# Replace mvcMatchers
find . -name "*.java" -type f -exec sed -i 's/\.mvcMatchers(/.requestMatchers(/g' {} +

# Replace regexMatchers
find . -name "*.java" -type f -exec sed -i 's/\.regexMatchers(/.requestMatchers(/g' {} +
Step 4: Replace authorizeRequests with authorizeHttpRequests
bash
find . -name "*.java" -type f -exec sed -i 's/\.authorizeRequests(/.authorizeHttpRequests(/g' {} +

Verification Commands

Verify No Deprecated Patterns Remain
bash
# Should return NO results
grep -r "WebSecurityConfigurerAdapter" --include="*.java" .
grep -r "@EnableGlobalMethodSecurity" --include="*.java" .
grep -r "\.antMatchers(" --include="*.java" .
grep -r "\.authorizeRequests(" --include="*.java" .
Verify New Patterns Are Present
bash
# Should return results
grep -r "@EnableMethodSecurity" --include="*.java" .
grep -r "SecurityFilterChain" --include="*.java" .
grep -r "\.requestMatchers(" --include="*.java" .
grep -r "\.authorizeHttpRequests(" --include="*.java" .

Common Migration Pitfalls

  1. @Configuration is now required separately - Before Spring Security 6, @Configuration was part of @EnableWebSecurity. Now you must add it explicitly.

  2. Lambda DSL is mandatory - The old chained method style (http.csrf().disable().and()...) is deprecated and must be converted to lambda style.

  3. AuthenticationManager injection changed - Use AuthenticationConfiguration.getAuthenticationManager() instead of overriding authenticationManagerBean().

  4. UserDetailsService auto-detection - Spring Security 6 automatically detects UserDetailsService beans; no need for explicit configuration.

  5. Method security default changes - @EnableMethodSecurity enables @PreAuthorize and @PostAuthorize by default (unlike the old annotation).

Sources

© benchflow-ai, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6 of benchflow-ai/skillsbench.

Open the folder on GitHubat commit 9a1f4dd

Compare with similar skills

Spring Security 6 next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Spring Security 6 compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Spring Security 6 this skillbenchflow-ai/skillsbench1.8k—~3.2kAutomated safety check: PassApache-2.0
Spring Bootpiomin/claude-ai-spring-boot1.3k—~2kAutomated safety check: PassApache-2.0
Dr Jskilljdubois/dr-jskill342—~4.6kAutomated safety check: NotesApache-2.0
WxJava Integration Guidebinarywang/WxJava33k—~123Automated safety check: PassApache-2.0
Grails Developer Guideapache/grails-core2.9k—~4.9kAutomated safety check: PassApache-2.0
Flycms Devsunkaifei/FlyCms656—~827Automated safety check: PassMIT

Similar skills

  • Spring Boot

    piomin/claude-ai-spring-boot

    Spring Boot 3.x development - REST APIs, JPA, Security, Testing, and Cloud-native patterns.

    1.3k GitHub stars~2k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed
  • Dr Jskill

    jdubois/dr-jskill

    Creates Java + Spring Boot projects: Web applications, full-stack apps with Vue.js or Angular or React or vanilla JS, PostgreSQL, REST APIs, and Docker.

    342 GitHub stars~4.6k tokensUpdated 8 days ago
    Backend & APIsAuto-check: notes
  • WxJava Integration Guide

    binarywang/WxJava

    Plans a WxJava setup for Java, Spring Boot or Solon projects that call WeChat services, from module and BOM choice to config and a minimal working call.

    33k GitHub stars~123 tokensUpdated 12 days ago
    Backend & APIsAuto-check passed
  • Grails Developer Guide

    apache/grails-core

    Guides building Grails web applications and REST APIs with GORM, controllers, services, views, plugins and Spock and Geb testing.

    2.9k GitHub stars~4.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Flycms Dev

    sunkaifei/FlyCms

    FlyCms 项目(backend/ Spring Boot 4.1.1 + frontend/ vue-vben-admin v5)的架构地图与开发规范总纲。凡在本仓库做任何开发——写后端接口、新增/修改模块、管理页面、数据库变更、修 bug、重构——都要先加载本 skill 再动手,即使用户只说"改一下""加个功能";前端登录/菜单/权限专项另见…

    656 GitHub stars~827 tokensUpdated 6 days ago
    Backend & APIsAuto-check passed
  • Intelliconnect Service Style

    ruanrongman/IntelliConnect

    Create or update IntelliConnect Spring Boot service/serviceimpl code in this repository style.

    147 GitHub stars~2.4k tokensUpdated yesterday
    Backend & APIsAuto-check passed

More from benchflow-ai/skillsbench

All 178 skills in this repo
  • Lean4 Memories

    benchflow-ai/skillsbench

    This skill should be used when working on Lean 4 formalization projects to maintain persistent memory of successful proof patterns, failed approaches, project conventions, and user preferences…

    1.8k GitHub stars~3.2k tokensUpdated 2 mo ago
    Auto-check passed
  • Senior Data Engineer

    benchflow-ai/skillsbench

    World-class data engineering skill for building scalable data pipelines, ETL/ELT systems, real-time streaming, and data infrastructure.

    1.8k GitHub stars~5.9k tokensUpdated 2 mo ago
    Auto-check passed
  • Ac Branch Pi Model

    benchflow-ai/skillsbench

    AC branch pi-model power flow equations (P/Q and |S|) with transformer tap ratio and phase shift, matching acopf-math-model.md and MATPOWER branch fields.

    1.8k GitHub stars~1.1k tokensUpdated 2 mo ago
    Auto-check passed
  • Civ6lib

    benchflow-ai/skillsbench

    Civilization 6 district mechanics library. An agent skill from benchflow-ai/skillsbench.

    1.8k GitHub stars~1.7k tokensUpdated 2 mo ago
    Auto-check passed
  • D3 Visualization

    benchflow-ai/skillsbench

    Build deterministic, verifiable data visualizations with D3.js (v6).

    1.8k GitHub stars~1.5k tokensUpdated 2 mo ago
    Auto-check passed
  • Dc Power Flow

    benchflow-ai/skillsbench

    DC power flow analysis for power systems. An agent skill from benchflow-ai/skillsbench.

    1.8k GitHub stars~717 tokensUpdated 2 mo ago
    Auto-check passed

Works with

Categories

Questions about Spring Security 6

What does Spring Security 6 do?

Migrate Spring Security 5 to Spring Security 6 configuration. Spring Security 6 is an agent skill from benchflow-ai/skillsbench. Migrate Spring Security 5 to Spring Security 6 configuration.

When should I use Spring Security 6?

Spring Security 6 fits situations like: removing WebSecurityConfigurerAdapter; replacing @EnableGlobalMethodSecurity with @EnableMethodSecurity; converting antMatchers to requestMatchers; updating to lambda DSL configuration style.

How do I install Spring Security 6 in Claude Code?

Run `npx skills add benchflow-ai/skillsbench --skill spring-security-6 -a claude-code`. Or copy the skill folder (tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6 in benchflow-ai/skillsbench) into .claude/skills/spring-security-6 in your project. Claude Code loads it when a task matches its description.

How do I install Spring Security 6 in Codex?

Run `npx skills add benchflow-ai/skillsbench --skill spring-security-6 -a codex`. Or copy the skill folder (tasks/spring-boot-jakarta-migration/environment/skills/spring-security-6 in benchflow-ai/skillsbench) into .agents/skills/spring-security-6 in your project. Codex loads it when a task matches its description.

Can I use Spring Security 6 in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add benchflow-ai/skillsbench --skill spring-security-6 -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spring-security-6, .gemini/skills/spring-security-6, .github/skills/spring-security-6 and .opencode/skills/spring-security-6 in your project.

What does Spring Security 6 need to run?

SKILL.md names no scripts, command-line tools or credentials: Spring Security 6 is instructions for the agent only.

Does Spring Security 6 access the network?

SKILL.md names 2 domains. As links in the text: baeldung.com and docs.spring.io. This is read from the text; nothing was executed.

Is Spring Security 6 safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Spring Security 6 use?

Spring Security 6 is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Spring Security 6 use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Spring Security 6?

Skills that share tags, products or a category with Spring Security 6: Spring Boot (piomin/claude-ai-spring-boot, 1.3k stars), Dr Jskill (jdubois/dr-jskill, 342 stars), WxJava Integration Guide (binarywang/WxJava, 33k stars) and Grails Developer Guide (apache/grails-core, 2.9k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Spring Security 6?

benchflow-ai (a GitHub organization) maintains it in benchflow-ai/skillsbench, which has 1,832 GitHub stars. The repository holds 178 skills in this directory. The repository was last updated on July 23, 2026.

Source: benchflow-ai/skillsbench on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.