Agent skill

Spring Boot

by ericrisco in ericrisco/rsc-harness

A skill your agent uses when building, reviewing, testing, securing or configuring a Spring Boot 4 / Framework 7 backend — controllers, services, Spring Data JPA, application.yml…

MITAuto-check passedBackend & APIs

Install Spring Boot

skills CLI
$ npx skills add ericrisco/rsc-harness --skill spring-boot -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install ericrisco/rsc-harness spring-boot --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/spring-boot .claude/skills/spring-boot && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
spring-boot
GitHub stars
156
Token cost
~4k tokens
SKILL.md length
1,069 words
Files
7 (incl. scripts, references)
Skills in repo
229
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when building, reviewing, testing, securing or configuring a Spring Boot 4 / Framework 7 backend — controllers, services, Spring Data JPA, application.yml…

  • Configuring a Spring Boot 4 / Framework 7 backend — controllers
  • SKILL.md covers Boundaries, Project layout, Controllers and Service + transactions, plus 8 more sections
  • Runs Shell scripts from its folder; needs DB_PASSWORD
  • Spring Data JPA

What it does

Spring Boot is an agent skill from ericrisco/rsc-harness. Use when building, reviewing, testing, securing or configuring a Spring Boot 4 / Framework 7 backend — controllers, services, Spring Data JPA, application.yml, SecurityFilterChain, slice tests. NOT plain modern-Java language work like records or virtual threads (that is java); NOT engine-level SQL schema/index/EXPLAIN (that is postgresdb).

Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/jpa.md`).

It sits in Backend & APIs, covering Backend development. It works with Spring Boot, Java, SQL and Django. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.

When your agent uses it

  • Configuring a Spring Boot 4 / Framework 7 backend — controllers
  • Spring Data JPA
  • Application.yml
  • SecurityFilterChain

Example prompts

  • “/spring-boot”

Requirements

  • Python 3
  • A Bash shell

What it can do on your machine

Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (Shell), which the agent can run.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • DB_PASSWORD

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Spring Boot loads about 4k tokens when it runs, and up to ~6.8k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 1,069 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~89
When it runs · the whole SKILL.md, loaded when a task matches
~4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,069 words, ~4,013 tokens.

Download SKILL.mdSave it as .claude/skills/spring-boot/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
spring-boot
description
Use when building, reviewing, testing, securing or configuring a Spring Boot 4 / Framework 7 backend — controllers, services, Spring Data JPA, application.yml, SecurityFilterChain, slice tests. NOT plain modern-Java language work like records or virtual threads (that is `java`); NOT engine-level SQL schema/index/EXPLAIN (that is `postgresdb`).
tags
java, spring, jpa, security, backend
recommends
java, postgresdb, secure-coding, deployment
origin
risco

Spring Boot backends (Boot 4 / Framework 7)

A Spring Boot app is a thin web layer delegating to a transactional service layer over Spring Data JPA repositories — wired by constructor injection, configured by typed @ConfigurationProperties, locked down by a SecurityFilterChain bean. Controllers validate input and delegate; they never own business logic, transactions, or persistence. Hold that shape and most "where does this go?" questions answer themselves.

Pinned stack (verify against the project's pom.xml/build.gradle — do not assume): Spring Boot 4.0 (GA 2025-11-20), Spring Framework 7, Java 17 baseline / Java 25 LTS, Jakarta EE 11 (jakarta.*, never javax.*), Jackson 3, Spring Security 7, Spring Data JPA / Hibernate 7, JUnit 5 + Testcontainers, Maven 3.9 / Gradle.

If you are typing WebSecurityConfigurerAdapter, @MockBean, field @Autowired, authorizeRequests, or javax.persistence — stop. Those are the previous generation. The modern idioms below replace every one of them.

Boundaries

Project layout

Package by feature, not by layer — colocation keeps a change to one feature in one folder.

text
com.acme.shop
├── order/
│   ├── OrderController.java       // @RestController — web edge
│   ├── OrderService.java          // @Service — @Transactional unit of work
│   ├── OrderRepository.java       // extends JpaRepository<Order, Long>
│   ├── Order.java                 // @Entity (jakarta.persistence)
│   └── dto/CreateOrderRequest.java, OrderResponse.java   // records, never entities
├── config/AppProperties.java      // @ConfigurationProperties record
├── security/SecurityConfig.java   // SecurityFilterChain bean
└── ShopApplication.java           // @SpringBootApplication

Controllers

@RestController + DTO records, @Valid on the body (Bean Validation, jakarta.validation) so business code can assume valid data, ResponseEntity for 201/Location, a @RestControllerAdvice for one error envelope. The controller parses, validates, delegates and maps — any branch with business meaning belongs in the service, where it is transactional and unit-testable without MVC. Boot 4 adds first-class versioning via a version attribute on the mapping — one controller serves many versions, no path duplication.

java
@RestController
@RequestMapping("/api/users")
class UserController {
    private final UserService users;
    UserController(UserService users) { this.users = users; }   // constructor injection

    @PostMapping(version = "1")                                  // Boot 4 API versioning
    ResponseEntity<UserResponse> create(@Valid @RequestBody CreateUserRequest req) {
        UserResponse body = users.create(req);
        URI location = URI.create("/api/users/" + body.id());
        return ResponseEntity.created(location).body(body);     // 201 + Location
    }
}

record CreateUserRequest(@NotBlank String name, @Email String email) {}
record UserResponse(Long id, String name, String email) {}
java
@RestControllerAdvice
class ApiExceptionHandler {
    @ExceptionHandler(MethodArgumentNotValidException.class)
    ResponseEntity<ApiError> onInvalid(MethodArgumentNotValidException e) {
        var details = e.getBindingResult().getFieldErrors().stream()
            .map(f -> f.getField() + ": " + f.getDefaultMessage()).toList();
        return ResponseEntity.badRequest().body(new ApiError("validation_failed", "Invalid request", details));
    }
}
record ApiError(String code, String message, List<String> details) {}

Bad -> Good — never return the entity; it leaks columns and lazy-loads in the serializer:

java
// Bad: leaks columns; lazy fields blow up in the serializer after the tx closes.
@GetMapping("/{id}") User get(@PathVariable Long id) { return repo.findById(id).orElseThrow(); }
// Good: map to a DTO inside the transactional service.
@GetMapping("/{id}") UserResponse get(@PathVariable Long id) { return users.get(id); }

Service + transactions

Constructor-injected, final fields, @Transactional on the write path, readOnly = true on queries (lets Hibernate skip dirty checking). @Transactional belongs on service methods, never on a controller or repository: the transaction must wrap the unit of work, not the HTTP request or a single query.

java
@Service
class UserService {
    private final UserRepository repo;
    private final PasswordEncoder encoder;
    UserService(UserRepository repo, PasswordEncoder encoder) { this.repo = repo; this.encoder = encoder; }

    @Transactional
    UserResponse create(CreateUserRequest req) {
        var user = repo.save(new User(req.name(), req.email(), encoder.encode(req.rawPassword())));
        return new UserResponse(user.getId(), user.getName(), user.getEmail());
    }

    @Transactional(readOnly = true)
    UserResponse get(Long id) {
        return repo.findById(id).map(this::toResponse).orElseThrow(() -> new NotFoundException(id));
    }
}

Two traps that produce "my @Transactional isn't rolling back":

  • Self-invocation. Calling this.other() inside the same bean bypasses the proxy, so its @Transactional is ignored. Split into another bean or accept the outer transaction.
  • Checked exceptions don't roll back by default. Spring rolls back on RuntimeException only; use @Transactional(rollbackFor = ...) for checked ones.

Bad -> Good — field injection vs constructor:

java
// Bad: not testable with `new`, hides missing beans until runtime, allows final-less mutation.
@Autowired private UserRepository repo;
// Good:
private final UserRepository repo;
UserService(UserRepository repo) { this.repo = repo; }

JPA persistence

jakarta.persistence imports (never javax). Spring Data gives you derived queries for free and @Query for the rest; Pageable/Page for paging.

java
import jakarta.persistence.*;

@Entity @Table(name = "users")
class User {
    @Id @GeneratedValue(strategy = GenerationType.IDENTITY) private Long id;
    private String name;
    @Column(unique = true) private String email;
    @OneToMany(mappedBy = "user") private List<Order> orders = new ArrayList<>();
    // getters; protected no-arg ctor for Hibernate
}

interface UserRepository extends JpaRepository<User, Long> {
    Optional<User> findByEmail(String email);                       // derived query
    Page<User> findByNameContaining(String q, Pageable page);       // paginated

    @Query("select u from User u join fetch u.orders where u.id = :id")
    Optional<User> findWithOrders(@Param("id") Long id);            // fetch join kills N+1
}

N+1 symptom: iterating a lazy collection issues one query per parent. Fix with a join fetch, an @EntityGraph, or @BatchSize. LazyInitializationException means you touched a lazy field after the transaction (and its Hibernate session) closed — map to a DTO inside the @Transactional service, or fetch eagerly for that path. Relationship/cascade depth, projections, Specifications, optimistic locking and migration tooling are in references/jpa.md.

Configuration & profiles

yaml
# application.yml — no secrets committed here; import them at boot.
spring:
  config:
    import: "optional:configtree:/run/secrets/"   # mount real secrets at runtime
  datasource:
    url: ${DB_URL}
    username: ${DB_USER}
    password: ${DB_PASSWORD}
app:
  invite-ttl: 24h
  max-orders-per-day: 50
---
spring:
  config:
    activate:
      on-profile: dev
app:
  max-orders-per-day: 5
java
@ConfigurationProperties(prefix = "app")
record AppProperties(Duration inviteTtl, int maxOrdersPerDay) {}   // typed, validated at startup
// register once: @EnableConfigurationProperties(AppProperties.class) on a @Configuration

Bad -> Good — scattered @Value("${app.max-orders-per-day}") strings vs one injected AppProperties record. One typed binding beats string keys sprinkled across the codebase and fails fast on a missing/mistyped key instead of NPE-ing later.

Security

A single SecurityFilterChain bean with the lambda DSL, stateless for token APIs, JWT via the resource server.

java
@Configuration
@EnableMethodSecurity                                            // enables @PreAuthorize
class SecurityConfig {
    @Bean
    SecurityFilterChain api(HttpSecurity http) throws Exception {
        http
          .csrf(csrf -> csrf.disable())                          // OK: stateless token API, no cookies
          .sessionManagement(s -> s.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
          .authorizeHttpRequests(auth -> auth
              .requestMatchers(HttpMethod.POST, "/api/users").permitAll()
              .requestMatchers("/api/admin/**").hasRole("ADMIN")
              .anyRequest().authenticated())
          .oauth2ResourceServer(o -> o.jwt(Customizer.withDefaults()));
        return http.build();
    }

    @Bean PasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(); }
}

Order requestMatchers from most specific to least — the first match wins, so a broad permitAll placed early opens routes you meant to lock. Full JWT/OAuth2 client, method security, CORS, and CSRF posture (token vs cookie apps) live in references/security.md. For the language-agnostic authz/secret principles behind these rules, see ../secure-coding/SKILL.md.

Testing

Pick the narrowest slice that exercises what you changed — @SpringBootTest only when you genuinely need the full context:

SliceLoadsUse forCollaborators
@WebMvcTestweb layer + Security + MockMvcone controller's HTTP contract@MockitoBean the service
@DataJpaTestJPA + in-memory/TC DB, rolls back per testrepository queries, mappingsreal repo, test DB
@SpringBootTestfull contextend-to-end / integrationreal beans, Testcontainers

@MockBean/@SpyBean are removed — use @MockitoBean/@MockitoSpyBean from org.springframework.test.context.bean.override.mockito.

java
@WebMvcTest(UserController.class)
class UserControllerTest {
    @Autowired MockMvc mvc;
    @MockitoBean UserService users;                              // not @MockBean

    @Test void rejectsBlankName() throws Exception {
        mvc.perform(post("/api/users").contentType(MediaType.APPLICATION_JSON)
                .content("{\"name\":\"\",\"email\":\"a@b.co\"}"))
           .andExpect(status().isBadRequest());
    }
}

Integration DB via Testcontainers + @ServiceConnection (auto-wires connection details, no @DynamicPropertySource):

java
@TestConfiguration(proxyBeanMethods = false)
class ContainersConfig {
    @Bean @ServiceConnection
    PostgreSQLContainer<?> postgres() { return new PostgreSQLContainer<>("postgres:17"); }
}

Slice deep dive, container reuse, MockMvcTester/WebTestClient, and the CI gate are in references/testing.md.

Show full SKILL.md (398 more words)Show less

HTTP clients & resilience

Outbound calls: declare an @HttpExchange interface and register it — no manual RestTemplate/HttpServiceProxyFactory boilerplate.

java
@HttpExchange("/v1")
interface BillingClient {
    @GetExchange("/invoices/{id}") Invoice invoice(@PathVariable String id);
}
// register: @ImportHttpServices(group = "billing", types = BillingClient.class) on a @Configuration

RestClient is the modern synchronous client for ad-hoc calls. For built-in resilience, @Retryable and @ConcurrencyLimit are core in Framework 7 — no extra Spring Retry dependency for the basics.

Anti-patterns

Anti-patternWhy it's wrongDo instead
Extend WebSecurityConfigurerAdapterRemoved in Security 6/7SecurityFilterChain bean + lambda DSL
@Autowired on a fieldUntestable, hides missing beans till runtimeconstructor injection, final fields
@Transactional on a @RestControllerTx must wrap the unit of work, not the requestput it on the service method
Business branching in the controllerNot transactional, needs MVC to testmove the decision into the @Service
Return the @Entity from a controllerLeaks columns, lazy-loads in serializer (LIE)map to a DTO record inside the tx
Request body reaching the service unvalidatedBusiness code can no longer assume valid data@Valid + jakarta.validation at the edge
Scattered @Value("${...}") config keysString keys, no validation, fails lateone typed @ConfigurationProperties record
Use @MockBean / @SpyBeanReplaced in Boot 4@MockitoBean / @MockitoSpyBean
import javax.persistence / javax.validationJakarta EE 11 baselinejakarta.*
authorizeRequests / antMatchersGone in Security 6/7authorizeHttpRequests + requestMatchers
csrf().disable() with no rationaleSilently opens cookie-session appsdisable only for stateless token APIs; comment why
@SpringBootTest for one controllerSlow, loads everything@WebMvcTest + @MockitoBean
One 800-line @ServiceUntestable, tangled transactionssplit per use case / aggregate
catch (Exception e) and echo e.getMessage()Leaks internals, swallows bugs@RestControllerAdvice + typed error envelope
Serialize a lazy collection after the tx closesLazyInitializationException / N+1fetch join or @EntityGraph, map in-tx

scripts/verify.sh greps a project for the legacy idioms above (read-only, best effort).

Quick reference

TaskIdiom
Inject a dependencyconstructor arg, final field
Expose an endpoint@RestController + @GetMapping/@PostMapping(version=)
Validate input@Valid @RequestBody + jakarta.validation annotations
Get by idrepo.findById(id).orElseThrow(...) in a readOnly tx
PaginatePage<T> findBy...(..., Pageable page)
Custom query@Query("select ... join fetch ...")
Transaction boundary@Transactional on the service method
Hash a passwordPasswordEncoder bean (BCryptPasswordEncoder)
Lock down routesSecurityFilterChain + authorizeHttpRequests/requestMatchers
JWT APIoauth2ResourceServer(o -> o.jwt(...)), stateless session
Mock a collaborator in a test@MockitoBean
Integration DBTestcontainers @Bean + @ServiceConnection

Project grounding

If the repo has a 02-DOCS/ wiki, record stack decisions (Boot version, security posture, test strategy, migration tool) in 02-DOCS/wiki/stack/spring-boot.md and link it from the CLAUDE.md Knowledge map. This is recorded, not gated — if there is no 02-DOCS/, skip silently; you may suggest the project harness if the user wants persistent docs.

© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (scripts, references) in skills/spring-boot of ericrisco/rsc-harness.

  • SKILL.md
  • evals/README.md
  • evals/cases.yaml
  • references/jpa.md
  • references/security.md
  • references/testing.md
  • scripts/verify.sh

Open the folder on GitHubat commit 92fde8f

Compare with similar skills

Spring Boot next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Spring Boot compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Spring Boot this skillericrisco/rsc-harness156—~4kAutomated safety check: PassMIT
Flycms Devsunkaifei/FlyCms656—~827Automated safety check: PassMIT
Arch Wikiahmedemad3/arch-wiki249—~5.1kAutomated safety check: PassNone
Tech Selection ResearchaAAaqwq/AGI-Super-Team105—~1.6kAutomated safety check: NotesMIT
Backend Analysis Skilljiushiwon/wg-skills110—~1kAutomated safety check: PassApache-2.0
Otel Javaollygarden/opentelemetry-agent-skills106—~1.4kAutomated safety check: PassApache-2.0

Similar skills

  • Flycms Dev

    sunkaifei/FlyCms

    FlyCms 项目(backend/ Spring Boot 4.1.1 + frontend/ vue-vben-admin v5)的架构地图与开发规范总纲。凡在本仓库做任何开发——写后端接口、新增/修改模块、管理页面、数据库变更、修 bug、重构——都要先加载本 skill 再动手,即使用户只说"改一下""加个功能";前端登录/菜单/权限专项另见…

    656 GitHub stars~827 tokensUpdated 5 days ago
    Backend & APIsAuto-check passed
  • Arch Wiki

    ahmedemad3/arch-wiki

    Scans any project codebase for new/changed modules, endpoints, middleware, infrastructure, Docker topologies, SQL queries, or permissions and updates docs/architecture/architecture.json.

    249 GitHub stars~5.1k tokensUpdated 18 days ago
    Backend & APIsAuto-check passed
  • Tech Selection Research

    aAAaqwq/AGI-Super-Team

    A skill your agent uses when the user wants to research, compare, or evaluate a technology, framework, platform, or engineering tool for product R&D decision-making, such as "调研 FastAPI", "技术选型"…

    105 GitHub stars~1.6k tokensUpdated 10 days ago
    Backend & APIsAuto-check: notes
  • Backend Analysis Skill

    jiushiwon/wg-skills

    后端项目静态分析技能。不运行项目,直接扫描源码,为 Java(Spring Boot/Spring Cloud)、Go(Gin/Echo)、Python(FastAPI/Django/Flask)、Node.js(Express/NestJS) 项目产出 4 份报告:① 接口报告(全部 API 清单:方法/路径/入参/出参/鉴权)② 技术报告(语言/框架版本、中间件如…

    110 GitHub stars~1k tokensUpdated 3 days ago
    Backend & APIsAuto-check passed
  • Otel Java

    ollygarden/opentelemetry-agent-skills

    OpenTelemetry in Java — Javaagent zero-code instrumentation, Spring Boot Starter, manual autoconfigure SDK, declarative YAML configuration, BOM dependency management, sensitive-data capture and…

    106 GitHub stars~1.4k tokensUpdated 4 days ago
    DevOps & CloudAuto-check passed
  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 29 days ago
    DevelopmentAuto-check: notes

More from ericrisco/rsc-harness

All 229 skills in this repo
  • Ab Testing

    ericrisco/rsc-harness

    A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…

    156 GitHub stars~2.4k tokensUpdated today
    Auto-check passed
  • Accessibility

    ericrisco/rsc-harness

    A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…

    156 GitHub stars~3.4k tokensUpdated today
    Auto-check passed
  • Ads

    ericrisco/rsc-harness

    A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…

    156 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Agent Eval

    ericrisco/rsc-harness

    A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…

    156 GitHub stars~3.2k tokensUpdated today
    Auto-check passed
  • AI Media

    ericrisco/rsc-harness

    A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…

    156 GitHub stars~3.3k tokensUpdated today
    Auto-check passed
  • Analytics

    ericrisco/rsc-harness

    A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.

    156 GitHub stars~2.8k tokensUpdated today
    Auto-check passed

Categories

Questions about Spring Boot

What does Spring Boot do?

A skill your agent uses when building, reviewing, testing, securing or configuring a Spring Boot 4 / Framework 7 backend — controllers, services, Spring Data JPA, application.yml…. Spring Boot is an agent skill from ericrisco/rsc-harness.yml, SecurityFilterChain, slice tests.

When should I use Spring Boot?

Spring Boot fits situations like: configuring a Spring Boot 4 / Framework 7 backend — controllers; spring Data JPA; application.yml; securityFilterChain.

How do I install Spring Boot in Claude Code?

Run `npx skills add ericrisco/rsc-harness --skill spring-boot -a claude-code`. Or copy the skill folder (skills/spring-boot in ericrisco/rsc-harness) into .claude/skills/spring-boot in your project. Claude Code loads it when a task matches its description.

How do I install Spring Boot in Codex?

Run `npx skills add ericrisco/rsc-harness --skill spring-boot -a codex`. Or copy the skill folder (skills/spring-boot in ericrisco/rsc-harness) into .agents/skills/spring-boot in your project. Codex loads it when a task matches its description.

Can I use Spring Boot in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill spring-boot -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spring-boot, .gemini/skills/spring-boot, .github/skills/spring-boot and .opencode/skills/spring-boot in your project.

What does Spring Boot need to run?

Going by SKILL.md and its folder, Spring Boot needs a shell for the scripts in its folder and credentials named DB_PASSWORD. Our summary lists: Python 3; A Bash shell.

Does Spring Boot access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Spring Boot safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Spring Boot use?

Spring Boot is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Spring Boot use?

About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.8k tokens, read only when the agent opens those files.

What are the alternatives to Spring Boot?

Skills that share tags, products or a category with Spring Boot: Flycms Dev (sunkaifei/FlyCms, 656 stars), Arch Wiki (ahmedemad3/arch-wiki, 249 stars), Tech Selection Research (aAAaqwq/AGI-Super-Team, 105 stars) and Backend Analysis Skill (jiushiwon/wg-skills, 110 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Spring Boot?

ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.

Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.