Agent skill

Maven POM Refactor Check

by christian-schlichtherle in christian-schlichtherle/truelicense

Verifies that a pom.xml change did not silently alter Maven build behavior by diffing the effective POMs before and after.

Apache-2.0Auto-check passedDevelopment

Install Maven POM Refactor Check

skills CLI
$ npx skills add christian-schlichtherle/truelicense --skill verify-pom-refactor -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install christian-schlichtherle/truelicense verify-pom-refactor --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/christian-schlichtherle/truelicense.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/verify-pom-refactor .claude/skills/verify-pom-refactor && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
verify-pom-refactor
GitHub stars
399
Token cost
~883 tokens
SKILL.md length
408 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

Verifies that a pom.xml change did not silently alter Maven build behavior by diffing the effective POMs before and after.

  • Restructuring a pom.xml or inlining a parent POM
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md
  • Moving a plugin or dependency between sections of a POM
  • Pruning a pluginManagement or dependencyManagement entry

What it does

Maven's model merging can change what executes with no visible symptom, so for any structural POM change the agent diffs the effective POM, produced with the Maven help plugin, instead of reading the source diff. It captures the effective POM of every module in the plain and release profiles before and after, strips the timestamped line that the help plugin adds and diffs the results.

Reading hints: a pure reordering is not a behavior change unless two plugins share a phase, which a sorted diff confirms, and profiles inherited from a parent do not appear in module effective POMs, so the build section has to be diffed separately because that is what actually runs. For a prune, where the effective POM is supposed to change, the check is inverted and asserts that resolved plugin versions did not move. The agent then confirms against built artifacts rather than the log, using an offline Maven build and a check described in the project's CLAUDE.md. The examples come from that project's own regression history.

When your agent uses it

  • Restructuring a pom.xml or inlining a parent POM
  • Moving a plugin or dependency between sections of a POM
  • Pruning a pluginManagement or dependencyManagement entry

Example prompts

  • “I moved the compiler plugin into pluginManagement, so verify the effective POMs still match.”
  • “Check that inlining the parent POM did not change which plugins run in the release profile.”
  • “I pruned unused dependencyManagement entries, so show that no resolved plugin version moved.”

Requirements

  • Maven, using the project's `./mvnw` wrapper
  • The Maven help plugin's `effective-pom` goal

What it can do on your machine

Read from SKILL.md and the folder at commit 697ff98. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are bash).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Maven POM Refactor Check loads about 883 tokens when it runs. Until then it costs about 79 tokens; SKILL.md has 408 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~79
When it runs · the whole SKILL.md, loaded when a task matches
~883

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from christian-schlichtherle/truelicense at commit 697ff98, republished under its Apache-2.0 licence (© christian-schlichtherle). 408 words, ~883 tokens.

Download SKILL.mdSave it as .claude/skills/verify-pom-refactor/SKILL.md (or your agent's skills folder).
name
verify-pom-refactor
description
Verify that a change to any pom.xml did not silently alter build behaviour. Use whenever a POM is restructured, a plugin or dependency is moved between sections, or a pluginManagement/dependencyManagement entry is pruned — Maven's model merging can change what executes with no visible symptom.

Verifying a POM refactor

Maven's model merging is implicit enough that a POM change can alter behaviour with no visible symptom — that is the common thread through the 4.0.1 obfuscation regression, the silent zero-test Failsafe run, and the parent POM inlining. For any structural POM change, diff the effective POM rather than reading the source diff:

bash
for m in . api build-tasks core jax-rs jsf maven-plugin obfuscate spi swing tests ui v1 v2-core v2-json v2-xml v4; do
  n=$(echo "$m" | sed 's|^\.$|ROOT|')
  for p in plain release; do
    [ "$p" = release ] && PF="-P sonatype-oss-release" || PF=""
    ./mvnw -o -q help:effective-pom -pl "$m" $PF -Doutput="$DIR/$n.$p.xml"
  done
done

Strip the Generated by Maven Help Plugin on line (it carries a timestamp), capture before and after, and diff. Two things make the result readable:

  • A pure reordering is not a behaviour change unless two plugins share a phase. Check with diff <(sort before) <(sort after): if that is empty, only the order moved.
  • Inherited-but-inactive profiles are invisible. help:effective-pom lists a project's own profiles and injects the active ones into <build>; profiles inherited from an ancestor are not listed at all, which is why module effective POMs have no <profiles> section. So a profile moving between POMs shows up as a large <profiles> addition on the declaring project and nothing anywhere else. Diff the <build> section separately — that is what actually executes.

The inlining commit was signed off on exactly this: all 32 module effective POMs content-identical, one adjacent transposition (truelicense-maven-plugin ↔ maven-antrun-plugin, phases process-classes vs prepare-package) in the release-profile ones, and the root's <build> unchanged. Profile declaration order in the root POM is arranged to reproduce the old parent-then-child injection order for that reason, and for no other.

Then confirm against artifacts, not the log — ./mvnw -o clean install -P sonatype-oss-release -Dgpg.skip=true -Dmaven.javadoc.skip=true, followed by the grep -rlaE '_clinit@|_string#' check under Build-time verification in CLAUDE.md.

Show full SKILL.md (147 more words)Show less

Pruning

For a prune, where the effective POM is supposed to change, invert the check: assert that the things which must not move, didn't. Two comparisons cover it, and both caught nothing only because the prune was scoped from evidence rather than from reading:

  • Resolved version of every plugin that executes a goal. Extract the <artifactId>/<version> pairs from the <build><plugins> section of all 34 effective POMs and diff the sorted set. Removing a pluginManagement entry for a plugin that turns out to be bound somewhere silently downgrades it to a lifecycle default.
  • Full GAV and scope of every resolved dependency. ./mvnw -o dependency:list over the reactor, before and after, diffed. Removing a dependencyManagement entry can shift a transitive version even when no module declares that artifact directly. On the prune commit the only delta was ScalaCheck and its test-interface leaving the test classpath, which was the intent.

© christian-schlichtherle, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/verify-pom-refactor of christian-schlichtherle/truelicense.

Open the folder on GitHubat commit 697ff98

Compare with similar skills

Maven POM Refactor Check next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Maven POM Refactor Check compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Maven POM Refactor Check this skillchristian-schlichtherle/truelicense399—~883Automated safety check: PassApache-2.0
Dep Validateblokadaorg/blokada3.3k—~5.7kAutomated safety check: NotesMPL-2.0
Ponytail Minimal-Code Modediegosouzapw/OmniRoute75k—~1.9kAutomated safety check: PassMIT
Build Fixcodewithmukesh/dotnet-claude-kit756—~1.8kAutomated safety check: PassMIT
Nemo Rl Auto ResearchNVIDIA/skills3.6k—~2.3kAutomated safety check: PassApache-2.0
Guidelinesakash-network/node1.1k20 repos~577Automated safety check: PassMIT

Similar skills

  • Dep Validate

    blokadaorg/blokada

    A skill your agent uses to validate risky dependency bumps end to end as a local or cloud-launched agent.

    3.3k GitHub stars~5.7k tokensUpdated 2 days ago
    DevelopmentAuto-check: notes
  • Ponytail Minimal-Code Mode

    diegosouzapw/OmniRoute

    Pushes the agent toward the smallest working solution on coding tasks by climbing a ladder from skipping the work to reuse, standard library, native features and one-liners.

    75k GitHub stars~1.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Build Fix

    codewithmukesh/dotnet-claude-kit

    Autonomous iteration loops for .NET: drive a broken build or failing test suite to green with bounded iterations, progress detection, and fail-safe guards that prevent infinite retries and wasted…

    756 GitHub stars~1.8k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Official

    Autonomous NeMo-RL research agent workflow for directed hypothesis testing and open-ended discovery.

    3.6k GitHub stars~2.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Guidelines

    akash-network/node

    Behavioral guidelines to reduce common LLM coding mistakes. An agent skill from akash-network/node.

    1.1k GitHub starsUsed in 20 repos~577 tokens
    DevelopmentAuto-check passed
  • Migrate Core Code to Submodules

    tinyhumansai/openhuman

    Plans and carries out moving non-host-specific code and its tests from the OpenHuman core into vendored tiny submodule libraries, then releases the submodule and re-pins the host.

    42k GitHub stars~2.6k tokensUpdated today
    DevelopmentAuto-check passed

More from christian-schlichtherle/truelicense

  • TrueLicense Maven Central Release

    christian-schlichtherle/truelicense

    Documents how TrueLicense is published to Maven Central from a version tag, the plugin constraints behind it and how to rehearse a release locally.

    399 GitHub stars~846 tokensUpdated 2 mo ago
    Auto-check passed

Categories

Questions about Maven POM Refactor Check

What does Maven POM Refactor Check do?

Verifies that a pom.xml change did not silently alter Maven build behavior by diffing the effective POMs before and after. Maven's model merging can change what executes with no visible symptom, so for any structural POM change the agent diffs the effective POM, produced with the Maven help plugin, instead of reading the source diff. It captures the effective POM of every module in the plain and release profiles before and after, strips the timestamped line that the help plugin adds and diffs the results.

When should I use Maven POM Refactor Check?

Maven POM Refactor Check fits situations like: restructuring a pom.xml or inlining a parent POM; moving a plugin or dependency between sections of a POM; pruning a pluginManagement or dependencyManagement entry.

How do I install Maven POM Refactor Check in Claude Code?

Run `npx skills add christian-schlichtherle/truelicense --skill verify-pom-refactor -a claude-code`. Or copy the skill folder (.claude/skills/verify-pom-refactor in christian-schlichtherle/truelicense) into .claude/skills/verify-pom-refactor in your project. Claude Code loads it when a task matches its description.

How do I install Maven POM Refactor Check in Codex?

Run `npx skills add christian-schlichtherle/truelicense --skill verify-pom-refactor -a codex`. Or copy the skill folder (.claude/skills/verify-pom-refactor in christian-schlichtherle/truelicense) into .agents/skills/verify-pom-refactor in your project. Codex loads it when a task matches its description.

Can I use Maven POM Refactor Check in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add christian-schlichtherle/truelicense --skill verify-pom-refactor -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/verify-pom-refactor, .gemini/skills/verify-pom-refactor, .github/skills/verify-pom-refactor and .opencode/skills/verify-pom-refactor in your project.

What does Maven POM Refactor Check need to run?

SKILL.md names no scripts, command-line tools or credentials: Maven POM Refactor Check is instructions for the agent only. Our summary lists: Maven, using the project's `./mvnw` wrapper; The Maven help plugin's `effective-pom` goal.

Does Maven POM Refactor Check access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Maven POM Refactor Check safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Maven POM Refactor Check use?

Maven POM Refactor Check is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Maven POM Refactor Check use?

About 883 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Maven POM Refactor Check?

Skills that share tags, products or a category with Maven POM Refactor Check: Dep Validate (blokadaorg/blokada, 3.3k stars), Ponytail Minimal-Code Mode (diegosouzapw/OmniRoute, 75k stars), Build Fix (codewithmukesh/dotnet-claude-kit, 756 stars) and Nemo Rl Auto Research (NVIDIA/skills, 3.6k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Maven POM Refactor Check?

christian-schlichtherle (a GitHub user) maintains it in christian-schlichtherle/truelicense, which has 399 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on August 10, 2026.

Source: christian-schlichtherle/truelicense on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.