Flycms Dev
sunkaifei/FlyCms
FlyCms 项目(backend/ Spring Boot 4.1.1 + frontend/ vue-vben-admin v5)的架构地图与开发规范总纲。凡在本仓库做任何开发——写后端接口、新增/修改模块、管理页面、数据库变更、修 bug、重构——都要先加载本 skill 再动手,即使用户只说"改一下""加个功能";前端登录/菜单/权限专项另见…
A skill your agent uses when building, reviewing, testing, securing or configuring a Spring Boot 4 / Framework 7 backend — controllers, services, Spring Data JPA, application.yml…
$ npx skills add ericrisco/rsc-harness --skill spring-boot -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install ericrisco/rsc-harness spring-boot --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/spring-boot .claude/skills/spring-boot && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "spring-boot" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/spring-boot into .claude/skills/spring-boot/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spring-boot", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/ericrisco/rsc-harness/tree/main/skills/spring-bootType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add ericrisco/rsc-harness --skill spring-boot -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install ericrisco/rsc-harness spring-boot --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/spring-boot .agents/skills/spring-boot && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "spring-boot" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/spring-boot into .agents/skills/spring-boot/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spring-boot", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill spring-boot -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install ericrisco/rsc-harness spring-boot --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/spring-boot .cursor/skills/spring-boot && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "spring-boot" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/spring-boot into .cursor/skills/spring-boot/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spring-boot", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/ericrisco/rsc-harness.git --path skills/spring-boot--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add ericrisco/rsc-harness --skill spring-boot -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install ericrisco/rsc-harness spring-boot --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/spring-boot .gemini/skills/spring-boot && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "spring-boot" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/spring-boot into .gemini/skills/spring-boot/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spring-boot", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install ericrisco/rsc-harness spring-bootInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add ericrisco/rsc-harness --skill spring-boot -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/spring-boot .github/skills/spring-boot && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "spring-boot" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/spring-boot into .github/skills/spring-boot/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spring-boot", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add ericrisco/rsc-harness --skill spring-boot -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install ericrisco/rsc-harness spring-boot --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/ericrisco/rsc-harness.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/spring-boot .opencode/skills/spring-boot && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "spring-boot" agent skill from https://github.com/ericrisco/rsc-harness/tree/main/skills/spring-boot into .opencode/skills/spring-boot/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "spring-boot", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
spring-bootA skill your agent uses when building, reviewing, testing, securing or configuring a Spring Boot 4 / Framework 7 backend — controllers, services, Spring Data JPA, application.yml…
Spring Boot is an agent skill from ericrisco/rsc-harness. Use when building, reviewing, testing, securing or configuring a Spring Boot 4 / Framework 7 backend — controllers, services, Spring Data JPA, application.yml, SecurityFilterChain, slice tests. NOT plain modern-Java language work like records or virtual threads (that is java); NOT engine-level SQL schema/index/EXPLAIN (that is postgresdb).
Its SKILL.md is about 4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 9 other files, including scripts and reference files (for example `evals/README.md`, `evals/cases.yaml` and `references/jpa.md`).
It sits in Backend & APIs, covering Backend development. It works with Spring Boot, Java, SQL and Django. The repository describes itself as: Your agent invents things because it has no memory, and can't touch your database because it has no arms. rsc is the meta-harness that gives it both, plus the trade to know the… The licence is MIT.
Read from SKILL.md and the folder at commit 92fde8f. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Ships 1 file in scripts/ (Shell), which the agent can run.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names these keys or tokens, usually read from environment variables:
DB_PASSWORDFrom names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Spring Boot loads about 4k tokens when it runs, and up to ~6.8k if it reads all its reference files. Until then it costs about 89 tokens; SKILL.md has 1,069 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.
The full file from ericrisco/rsc-harness at commit 92fde8f, republished under its MIT licence (© ericrisco). 1,069 words, ~4,013 tokens.
.claude/skills/spring-boot/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.A Spring Boot app is a thin web layer delegating to a transactional service layer over
Spring Data JPA repositories — wired by constructor injection, configured by typed
@ConfigurationProperties, locked down by a SecurityFilterChain bean. Controllers
validate input and delegate; they never own business logic, transactions, or persistence.
Hold that shape and most "where does this go?" questions answer themselves.
Pinned stack (verify against the project's pom.xml/build.gradle — do not assume):
Spring Boot 4.0 (GA 2025-11-20), Spring Framework 7, Java 17 baseline / Java 25 LTS, Jakarta
EE 11 (jakarta.*, never javax.*), Jackson 3, Spring Security 7, Spring Data JPA /
Hibernate 7, JUnit 5 + Testcontainers, Maven 3.9 / Gradle.
If you are typing WebSecurityConfigurerAdapter, @MockBean, field @Autowired,
authorizeRequests, or javax.persistence — stop. Those are the previous generation.
The modern idioms below replace every one of them.
../java/SKILL.md.../fastapi/SKILL.md. NestJS/Node ->
../nestjs/SKILL.md. Django -> ../django/SKILL.md.EXPLAIN, partitioning, zero-downtime DDL ->
../postgresdb/SKILL.md (this skill drives the JPA layer above it).../secure-coding/SKILL.md.../deployment/SKILL.md
(keep only a build note here).Package by feature, not by layer — colocation keeps a change to one feature in one folder.
com.acme.shop
├── order/
│ ├── OrderController.java // @RestController — web edge
│ ├── OrderService.java // @Service — @Transactional unit of work
│ ├── OrderRepository.java // extends JpaRepository<Order, Long>
│ ├── Order.java // @Entity (jakarta.persistence)
│ └── dto/CreateOrderRequest.java, OrderResponse.java // records, never entities
├── config/AppProperties.java // @ConfigurationProperties record
├── security/SecurityConfig.java // SecurityFilterChain bean
└── ShopApplication.java // @SpringBootApplication@RestController + DTO records, @Valid on the body (Bean Validation, jakarta.validation)
so business code can assume valid data, ResponseEntity for 201/Location, a
@RestControllerAdvice for one error envelope. The controller parses, validates, delegates
and maps — any branch with business meaning belongs in the service, where it is transactional
and unit-testable without MVC. Boot 4 adds first-class versioning via a version attribute
on the mapping — one controller serves many versions, no path duplication.
@RestController
@RequestMapping("/api/users")
class UserController {
private final UserService users;
UserController(UserService users) { this.users = users; } // constructor injection
@PostMapping(version = "1") // Boot 4 API versioning
ResponseEntity<UserResponse> create(@Valid @RequestBody CreateUserRequest req) {
UserResponse body = users.create(req);
URI location = URI.create("/api/users/" + body.id());
return ResponseEntity.created(location).body(body); // 201 + Location
}
}
record CreateUserRequest(@NotBlank String name, @Email String email) {}
record UserResponse(Long id, String name, String email) {}@RestControllerAdvice
class ApiExceptionHandler {
@ExceptionHandler(MethodArgumentNotValidException.class)
ResponseEntity<ApiError> onInvalid(MethodArgumentNotValidException e) {
var details = e.getBindingResult().getFieldErrors().stream()
.map(f -> f.getField() + ": " + f.getDefaultMessage()).toList();
return ResponseEntity.badRequest().body(new ApiError("validation_failed", "Invalid request", details));
}
}
record ApiError(String code, String message, List<String> details) {}Bad -> Good — never return the entity; it leaks columns and lazy-loads in the serializer:
// Bad: leaks columns; lazy fields blow up in the serializer after the tx closes.
@GetMapping("/{id}") User get(@PathVariable Long id) { return repo.findById(id).orElseThrow(); }
// Good: map to a DTO inside the transactional service.
@GetMapping("/{id}") UserResponse get(@PathVariable Long id) { return users.get(id); }Constructor-injected, final fields, @Transactional on the write path, readOnly = true
on queries (lets Hibernate skip dirty checking). @Transactional belongs on service methods,
never on a controller or repository: the transaction must wrap the unit of work, not the HTTP
request or a single query.
@Service
class UserService {
private final UserRepository repo;
private final PasswordEncoder encoder;
UserService(UserRepository repo, PasswordEncoder encoder) { this.repo = repo; this.encoder = encoder; }
@Transactional
UserResponse create(CreateUserRequest req) {
var user = repo.save(new User(req.name(), req.email(), encoder.encode(req.rawPassword())));
return new UserResponse(user.getId(), user.getName(), user.getEmail());
}
@Transactional(readOnly = true)
UserResponse get(Long id) {
return repo.findById(id).map(this::toResponse).orElseThrow(() -> new NotFoundException(id));
}
}Two traps that produce "my @Transactional isn't rolling back":
this.other() inside the same bean bypasses the proxy, so its
@Transactional is ignored. Split into another bean or accept the outer transaction.RuntimeException
only; use @Transactional(rollbackFor = ...) for checked ones.Bad -> Good — field injection vs constructor:
// Bad: not testable with `new`, hides missing beans until runtime, allows final-less mutation.
@Autowired private UserRepository repo;
// Good:
private final UserRepository repo;
UserService(UserRepository repo) { this.repo = repo; }jakarta.persistence imports (never javax). Spring Data gives you derived queries for free
and @Query for the rest; Pageable/Page for paging.
import jakarta.persistence.*;
@Entity @Table(name = "users")
class User {
@Id @GeneratedValue(strategy = GenerationType.IDENTITY) private Long id;
private String name;
@Column(unique = true) private String email;
@OneToMany(mappedBy = "user") private List<Order> orders = new ArrayList<>();
// getters; protected no-arg ctor for Hibernate
}
interface UserRepository extends JpaRepository<User, Long> {
Optional<User> findByEmail(String email); // derived query
Page<User> findByNameContaining(String q, Pageable page); // paginated
@Query("select u from User u join fetch u.orders where u.id = :id")
Optional<User> findWithOrders(@Param("id") Long id); // fetch join kills N+1
}N+1 symptom: iterating a lazy collection issues one query per parent. Fix with a
join fetch, an @EntityGraph, or @BatchSize. LazyInitializationException means you
touched a lazy field after the transaction (and its Hibernate session) closed — map to a DTO
inside the @Transactional service, or fetch eagerly for that path. Relationship/cascade
depth, projections, Specifications, optimistic locking and migration tooling are in
references/jpa.md.
# application.yml — no secrets committed here; import them at boot.
spring:
config:
import: "optional:configtree:/run/secrets/" # mount real secrets at runtime
datasource:
url: ${DB_URL}
username: ${DB_USER}
password: ${DB_PASSWORD}
app:
invite-ttl: 24h
max-orders-per-day: 50
---
spring:
config:
activate:
on-profile: dev
app:
max-orders-per-day: 5@ConfigurationProperties(prefix = "app")
record AppProperties(Duration inviteTtl, int maxOrdersPerDay) {} // typed, validated at startup
// register once: @EnableConfigurationProperties(AppProperties.class) on a @ConfigurationBad -> Good — scattered @Value("${app.max-orders-per-day}") strings vs one injected
AppProperties record. One typed binding beats string keys sprinkled across the codebase and
fails fast on a missing/mistyped key instead of NPE-ing later.
A single SecurityFilterChain bean with the lambda DSL, stateless for token APIs, JWT via the
resource server.
@Configuration
@EnableMethodSecurity // enables @PreAuthorize
class SecurityConfig {
@Bean
SecurityFilterChain api(HttpSecurity http) throws Exception {
http
.csrf(csrf -> csrf.disable()) // OK: stateless token API, no cookies
.sessionManagement(s -> s.sessionCreationPolicy(SessionCreationPolicy.STATELESS))
.authorizeHttpRequests(auth -> auth
.requestMatchers(HttpMethod.POST, "/api/users").permitAll()
.requestMatchers("/api/admin/**").hasRole("ADMIN")
.anyRequest().authenticated())
.oauth2ResourceServer(o -> o.jwt(Customizer.withDefaults()));
return http.build();
}
@Bean PasswordEncoder passwordEncoder() { return new BCryptPasswordEncoder(); }
}Order requestMatchers from most specific to least — the first match wins, so a broad
permitAll placed early opens routes you meant to lock. Full JWT/OAuth2 client, method
security, CORS, and CSRF posture (token vs cookie apps) live in
references/security.md. For the language-agnostic authz/secret
principles behind these rules, see ../secure-coding/SKILL.md.
Pick the narrowest slice that exercises what you changed — @SpringBootTest only when you
genuinely need the full context:
| Slice | Loads | Use for | Collaborators |
|---|---|---|---|
@WebMvcTest | web layer + Security + MockMvc | one controller's HTTP contract | @MockitoBean the service |
@DataJpaTest | JPA + in-memory/TC DB, rolls back per test | repository queries, mappings | real repo, test DB |
@SpringBootTest | full context | end-to-end / integration | real beans, Testcontainers |
@MockBean/@SpyBean are removed — use @MockitoBean/@MockitoSpyBean from
org.springframework.test.context.bean.override.mockito.
@WebMvcTest(UserController.class)
class UserControllerTest {
@Autowired MockMvc mvc;
@MockitoBean UserService users; // not @MockBean
@Test void rejectsBlankName() throws Exception {
mvc.perform(post("/api/users").contentType(MediaType.APPLICATION_JSON)
.content("{\"name\":\"\",\"email\":\"a@b.co\"}"))
.andExpect(status().isBadRequest());
}
}Integration DB via Testcontainers + @ServiceConnection (auto-wires connection details, no
@DynamicPropertySource):
@TestConfiguration(proxyBeanMethods = false)
class ContainersConfig {
@Bean @ServiceConnection
PostgreSQLContainer<?> postgres() { return new PostgreSQLContainer<>("postgres:17"); }
}Slice deep dive, container reuse, MockMvcTester/WebTestClient, and the CI gate are in
references/testing.md.
Outbound calls: declare an @HttpExchange interface and register it — no manual
RestTemplate/HttpServiceProxyFactory boilerplate.
@HttpExchange("/v1")
interface BillingClient {
@GetExchange("/invoices/{id}") Invoice invoice(@PathVariable String id);
}
// register: @ImportHttpServices(group = "billing", types = BillingClient.class) on a @ConfigurationRestClient is the modern synchronous client for ad-hoc calls. For built-in resilience,
@Retryable and @ConcurrencyLimit are core in Framework 7 — no extra Spring Retry
dependency for the basics.
| Anti-pattern | Why it's wrong | Do instead |
|---|---|---|
Extend WebSecurityConfigurerAdapter | Removed in Security 6/7 | SecurityFilterChain bean + lambda DSL |
@Autowired on a field | Untestable, hides missing beans till runtime | constructor injection, final fields |
@Transactional on a @RestController | Tx must wrap the unit of work, not the request | put it on the service method |
| Business branching in the controller | Not transactional, needs MVC to test | move the decision into the @Service |
Return the @Entity from a controller | Leaks columns, lazy-loads in serializer (LIE) | map to a DTO record inside the tx |
| Request body reaching the service unvalidated | Business code can no longer assume valid data | @Valid + jakarta.validation at the edge |
Scattered @Value("${...}") config keys | String keys, no validation, fails late | one typed @ConfigurationProperties record |
Use @MockBean / @SpyBean | Replaced in Boot 4 | @MockitoBean / @MockitoSpyBean |
import javax.persistence / javax.validation | Jakarta EE 11 baseline | jakarta.* |
authorizeRequests / antMatchers | Gone in Security 6/7 | authorizeHttpRequests + requestMatchers |
csrf().disable() with no rationale | Silently opens cookie-session apps | disable only for stateless token APIs; comment why |
@SpringBootTest for one controller | Slow, loads everything | @WebMvcTest + @MockitoBean |
One 800-line @Service | Untestable, tangled transactions | split per use case / aggregate |
catch (Exception e) and echo e.getMessage() | Leaks internals, swallows bugs | @RestControllerAdvice + typed error envelope |
| Serialize a lazy collection after the tx closes | LazyInitializationException / N+1 | fetch join or @EntityGraph, map in-tx |
scripts/verify.sh greps a project for the legacy idioms above (read-only, best effort).
| Task | Idiom |
|---|---|
| Inject a dependency | constructor arg, final field |
| Expose an endpoint | @RestController + @GetMapping/@PostMapping(version=) |
| Validate input | @Valid @RequestBody + jakarta.validation annotations |
| Get by id | repo.findById(id).orElseThrow(...) in a readOnly tx |
| Paginate | Page<T> findBy...(..., Pageable page) |
| Custom query | @Query("select ... join fetch ...") |
| Transaction boundary | @Transactional on the service method |
| Hash a password | PasswordEncoder bean (BCryptPasswordEncoder) |
| Lock down routes | SecurityFilterChain + authorizeHttpRequests/requestMatchers |
| JWT API | oauth2ResourceServer(o -> o.jwt(...)), stateless session |
| Mock a collaborator in a test | @MockitoBean |
| Integration DB | Testcontainers @Bean + @ServiceConnection |
If the repo has a 02-DOCS/ wiki, record stack decisions (Boot version, security posture,
test strategy, migration tool) in 02-DOCS/wiki/stack/spring-boot.md and link it from the
CLAUDE.md Knowledge map. This is recorded, not gated — if there is no 02-DOCS/, skip
silently; you may suggest the project harness if the user wants persistent docs.
© ericrisco, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (scripts, references) in skills/spring-boot of ericrisco/rsc-harness.
Open the folder on GitHubat commit 92fde8f
Spring Boot next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Spring Boot this skillericrisco/rsc-harness | 156 | — | ~4k | Automated safety check: Pass | MIT | |
| Flycms Devsunkaifei/FlyCms | 656 | — | ~827 | Automated safety check: Pass | MIT | |
| Arch Wikiahmedemad3/arch-wiki | 249 | — | ~5.1k | Automated safety check: Pass | None | |
| Tech Selection ResearchaAAaqwq/AGI-Super-Team | 105 | — | ~1.6k | Automated safety check: Notes | MIT | |
| Backend Analysis Skilljiushiwon/wg-skills | 110 | — | ~1k | Automated safety check: Pass | Apache-2.0 | |
| Otel Javaollygarden/opentelemetry-agent-skills | 106 | — | ~1.4k | Automated safety check: Pass | Apache-2.0 |
sunkaifei/FlyCms
FlyCms 项目(backend/ Spring Boot 4.1.1 + frontend/ vue-vben-admin v5)的架构地图与开发规范总纲。凡在本仓库做任何开发——写后端接口、新增/修改模块、管理页面、数据库变更、修 bug、重构——都要先加载本 skill 再动手,即使用户只说"改一下""加个功能";前端登录/菜单/权限专项另见…
ahmedemad3/arch-wiki
Scans any project codebase for new/changed modules, endpoints, middleware, infrastructure, Docker topologies, SQL queries, or permissions and updates docs/architecture/architecture.json.
aAAaqwq/AGI-Super-Team
A skill your agent uses when the user wants to research, compare, or evaluate a technology, framework, platform, or engineering tool for product R&D decision-making, such as "调研 FastAPI", "技术选型"…
jiushiwon/wg-skills
后端项目静态分析技能。不运行项目,直接扫描源码,为 Java(Spring Boot/Spring Cloud)、Go(Gin/Echo)、Python(FastAPI/Django/Flask)、Node.js(Express/NestJS) 项目产出 4 份报告:① 接口报告(全部 API 清单:方法/路径/入参/出参/鉴权)② 技术报告(语言/框架版本、中间件如…
ollygarden/opentelemetry-agent-skills
OpenTelemetry in Java — Javaagent zero-code instrumentation, Spring Boot Starter, manual autoconfigure SDK, declarative YAML configuration, BOM dependency management, sensitive-data capture and…
awesome-skills/code-review-skill
Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…
ericrisco/rsc-harness
A skill your agent uses when designing or analyzing a controlled experiment — falsifiable hypothesis, sample size from an MDE, reading significance/CI/power, CUPED, or rescuing tests that won't go…
ericrisco/rsc-harness
A skill your agent uses when making a web UI conform to WCAG 2.2 Level AA — axe-core or Lighthouse a11y violations, keyboard operability, focus management, ARIA roles/names/live regions, contrast…
ericrisco/rsc-harness
A skill your agent uses when running or fixing paid acquisition on Google or Meta — campaign structure (Performance Max, Demand Gen, Search, Advantage+), platform-fit creative, budget/scaling rules…
ericrisco/rsc-harness
A skill your agent uses when measuring whether an LLM or agent system actually got better and gating merges on it: golden sets, fixing an inflated LLM-as-judge, scoring RAG (faithfulness, contextual…
ericrisco/rsc-harness
A skill your agent uses when a creative goal must become a finished media file: pick and order generative-media models per modality — AI voiceover, image-to-video clips, score — then glue them with…
ericrisco/rsc-harness
A skill your agent uses when instrumenting product or web analytics — GA4/PostHog SDK wiring, event taxonomy, funnels, double-counted events, consent gating, PII scrubbing.
Categories
A skill your agent uses when building, reviewing, testing, securing or configuring a Spring Boot 4 / Framework 7 backend — controllers, services, Spring Data JPA, application.yml…. Spring Boot is an agent skill from ericrisco/rsc-harness.yml, SecurityFilterChain, slice tests.
Spring Boot fits situations like: configuring a Spring Boot 4 / Framework 7 backend — controllers; spring Data JPA; application.yml; securityFilterChain.
Run `npx skills add ericrisco/rsc-harness --skill spring-boot -a claude-code`. Or copy the skill folder (skills/spring-boot in ericrisco/rsc-harness) into .claude/skills/spring-boot in your project. Claude Code loads it when a task matches its description.
Run `npx skills add ericrisco/rsc-harness --skill spring-boot -a codex`. Or copy the skill folder (skills/spring-boot in ericrisco/rsc-harness) into .agents/skills/spring-boot in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add ericrisco/rsc-harness --skill spring-boot -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/spring-boot, .gemini/skills/spring-boot, .github/skills/spring-boot and .opencode/skills/spring-boot in your project.
Going by SKILL.md and its folder, Spring Boot needs a shell for the scripts in its folder and credentials named DB_PASSWORD. Our summary lists: Python 3; A Bash shell.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.
Spring Boot is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 4k tokens (SKILL.md is roughly 16k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Spring Boot: Flycms Dev (sunkaifei/FlyCms, 656 stars), Arch Wiki (ahmedemad3/arch-wiki, 249 stars), Tech Selection Research (aAAaqwq/AGI-Super-Team, 105 stars) and Backend Analysis Skill (jiushiwon/wg-skills, 110 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
ericrisco (a GitHub user) maintains it in ericrisco/rsc-harness, which has 156 GitHub stars. The repository holds 229 skills in this directory. The repository was last updated on October 6, 2026.
Source: ericrisco/rsc-harness on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.