Agent skill

Unit Test Security Authorization

by giuseppe-trisciuoglio in giuseppe-trisciuoglio/developer-kit

Provides patterns for unit testing Spring Security with @PreAuthorize, @Secured, @RolesAllowed.

MITAuto-check: notesBackend & APIs

Install Unit Test Security Authorization

skills CLI
$ npx skills add giuseppe-trisciuoglio/developer-kit --skill unit-test-security-authorization -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install giuseppe-trisciuoglio/developer-kit unit-test-security-authorization --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/giuseppe-trisciuoglio/developer-kit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/plugins/developer-kit-java/skills/unit-test-security-authorization .claude/skills/unit-test-security-authorization && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
unit-test-security-authorization
GitHub stars
357
Token cost
~1.7k tokens
SKILL.md length
441 words
Files
5 (incl. references)
Skills in repo
115
Repo updated
First seen
Licence
MIT

At a glance

Provides patterns for unit testing Spring Security with @PreAuthorize, @Secured, @RolesAllowed.

  • Works in 5 steps: Set Up Security Testing Dependencies → Enable Method Security in Test… → Test with @WithMockUser → …
  • Testing security configurations and access control logic
  • SKILL.md covers Overview, When to Use, Instructions and Quick Reference, plus 5 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Unit Test Security Authorization is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides patterns for unit testing Spring Security with @PreAuthorize, @Secured, @RolesAllowed. Validates role-based access control and authorization policies. Use when testing security configurations and access control logic.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files, including reference files (for example `references/advanced-authorization.md`, `references/basic-testing.md` and `references/complete-examples.md`).

It sits in Backend & APIs, covering Authorization and RBAC and Unit testing. The repository describes itself as: Modular plugin marketplace for Claude Code and agentic CLIs, with validated, spec-driven skills, agents, commands, and workflows for Java, TypeScript, Python, PHP, AWS, and AI. The licence is MIT.

When your agent uses it

  • Testing security configurations and access control logic
  • Tasks that involve Authorization and RBAC
  • Tasks that involve Unit testing

Example prompts

  • “Use the unit-test-security-authorization skill to provide patterns for unit testing Spring Security with @PreAuthorize, @Secured, @RolesAllowed”
  • “/unit-test-security-authorization”

Requirements

  • Pre-approved tools (allowed-tools): Read, Write, Bash, Glob, Grep

Workflow steps

5 steps, taken from the step headings in SKILL.md.

  1. Set Up Security Testing Dependencies
  2. Enable Method Security in Test Configuration
  3. Test with @WithMockUser
  4. Test Custom Permission Evaluators
  5. Validate Security is Active

What it can do on your machine

Read from SKILL.md and the folder at commit fe73fb3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Write
    • Bash
    • Glob
    • Grep

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are java and xml).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Unit Test Security Authorization loads about 1.7k tokens when it runs, and up to ~8.1k if it reads all its reference files. Until then it costs about 66 tokens; SKILL.md has 441 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~66
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~8.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Write, Bash, Glob, Grep

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from giuseppe-trisciuoglio/developer-kit at commit fe73fb3, republished under its MIT licence (© giuseppe-trisciuoglio). 441 words, ~1,681 tokens.

Download SKILL.mdSave it as .claude/skills/unit-test-security-authorization/SKILL.md (or your agent's skills folder). This skill also uses 4 other files; get the full folder from GitHub.
name
unit-test-security-authorization
description
Provides patterns for unit testing Spring Security with `@PreAuthorize`, `@Secured`, `@RolesAllowed`. Validates role-based access control and authorization policies. Use when testing security configurations and access control logic.
allowed-tools
Read, Write, Bash, Glob, Grep

Unit Testing Security and Authorization

Overview

This skill provides patterns for unit testing Spring Security authorization logic using @PreAuthorize, @Secured, @RolesAllowed, and custom permission evaluators. It covers testing role-based access control (RBAC), expression-based authorization, custom permission evaluators, and verifying access denied scenarios without full Spring Security context.

When to Use

Use this skill when:

  • Testing @PreAuthorize and @Secured method-level security
  • Testing role-based access control (RBAC)
  • Testing custom permission evaluators
  • Verifying access denied scenarios
  • Testing authorization with authenticated principals
  • Want fast authorization tests without full Spring Security context

Instructions

Follow these steps to test Spring Security authorization:

1. Set Up Security Testing Dependencies

Add spring-security-test to your test dependencies:

xml
<dependency>
  <groupId>org.springframework.security</groupId>
  <artifactId>spring-security-test</artifactId>
  <scope>test</scope>
</dependency>
2. Enable Method Security in Test Configuration
java
@Configuration
@EnableMethodSecurity
class TestSecurityConfig { }
3. Test with @WithMockUser
java
@Test
@WithMockUser(roles = "ADMIN")
void shouldAllowAdminAccess() {
  assertThatCode(() -> service.deleteUser(1L))
    .doesNotThrowAnyException();
}

@Test
@WithMockUser(roles = "USER")
void shouldDenyUserAccess() {
  assertThatThrownBy(() -> service.deleteUser(1L))
    .isInstanceOf(AccessDeniedException.class);
}
4. Test Custom Permission Evaluators
java
@Test
void shouldGrantPermissionToOwner() {
  Authentication auth = new UsernamePasswordAuthenticationToken(
    "alice", null, List.of(new SimpleGrantedAuthority("ROLE_USER"))
  );
  Document doc = new Document(1L, "Test", new User("alice"));

  boolean result = evaluator.hasPermission(auth, doc, "WRITE");
  assertThat(result).isTrue();
}
5. Validate Security is Active

If tests pass unexpectedly, add this assertion to verify security is enforced:

java
@Test
void shouldRejectUnauthorizedWhenSecurityEnabled() {
  assertThatThrownBy(() -> service.deleteUser(1L))
    .isInstanceOf(AccessDeniedException.class);
}

Quick Reference

AnnotationDescriptionExample
@PreAuthorizePre-invocation authorization@PreAuthorize("hasRole('ADMIN')")
@PostAuthorizePost-invocation authorization@PostAuthorize("returnObject.owner == authentication.name")
@SecuredSimple role-based security@Secured("ROLE_ADMIN")
@RolesAllowedJSR-250 standard@RolesAllowed({"ADMIN", "MANAGER"})
@WithMockUserTest annotation@WithMockUser(roles = "ADMIN")

Examples

Basic @PreAuthorize Test
java
@Service
public class UserService {
  @PreAuthorize("hasRole('ADMIN')")
  public void deleteUser(Long userId) {
    // delete logic
  }
}

// Test
@Test
@WithMockUser(roles = "ADMIN")
void shouldAllowAdminToDeleteUser() {
  assertThatCode(() -> service.deleteUser(1L))
    .doesNotThrowAnyException();
}

@Test
@WithMockUser(roles = "USER")
void shouldDenyUserFromDeletingUser() {
  assertThatThrownBy(() -> service.deleteUser(1L))
    .isInstanceOf(AccessDeniedException.class);
}
Expression-Based Security Test
java
@PreAuthorize("#userId == authentication.principal.id")
public UserProfile getUserProfile(Long userId) {
  // get profile
}

// For custom principal properties, use @WithUserDetails with a custom UserDetailsService
@Test
@WithUserDetails("alice")
void shouldAllowUserToAccessOwnProfile() {
  assertThatCode(() -> service.getUserProfile(1L))
    .doesNotThrowAnyException();
}

Validation tip: If a security test passes unexpectedly, verify that @EnableMethodSecurity is active on the test configuration — a missing annotation causes all @PreAuthorize checks to be bypassed silently.

See references/basic-testing.md for more basic patterns and references/advanced-authorization.md for complex expressions and custom evaluators.

Best Practices

  1. Use @WithMockUser for setting authenticated user context
  2. Test both allow and deny cases for each security rule
  3. Test with different roles to verify role-based decisions
  4. Test expression-based security comprehensively
  5. Mock external dependencies (permission evaluators, etc.)
  6. Test anonymous access separately from authenticated access
  7. Use @EnableGlobalMethodSecurity in configuration for method-level security
Show full SKILL.md (164 more words)Show less

Common Pitfalls

  • Forgetting to enable method security in test configuration
  • Not testing both allow and deny scenarios
  • Testing framework code instead of authorization logic
  • Not handling null authentication in tests
  • Mixing authentication and authorization tests unnecessarily

Constraints and Warnings

  • Method security requires proxy: @PreAuthorize works via proxies; direct method calls bypass security
  • @EnableGlobalMethodSecurity: Must be enabled for @PreAuthorize, @Secured to work
  • Role prefix: Spring adds "ROLE_" prefix automatically; use hasRole('ADMIN') not hasRole('ROLE_ADMIN')
  • Authentication context: Security context is thread-local; be careful with async tests
  • @WithMockUser limitations: Creates a simple Authentication; complex auth scenarios need custom setup
  • SpEL expressions: Complex SpEL in @PreAuthorize can be difficult to debug; test thoroughly
  • Performance impact: Method security adds overhead; consider security at layer boundaries

References

Setup and Configuration
Testing Patterns
Advanced Topics
Complete Examples

© giuseppe-trisciuoglio, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 4 other files (references) in plugins/developer-kit-java/skills/unit-test-security-authorization of giuseppe-trisciuoglio/developer-kit.

  • SKILL.md
  • references/advanced-authorization.md
  • references/basic-testing.md
  • references/complete-examples.md
  • references/setup.md

Open the folder on GitHubat commit fe73fb3

Compare with similar skills

Unit Test Security Authorization next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Unit Test Security Authorization compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Unit Test Security Authorization this skillgiuseppe-trisciuoglio/developer-kit357—~1.7kAutomated safety check: NotesMIT
Frontmcp Testingagentfront/frontmcp146—~10kAutomated safety check: NotesApache-2.0
Durable Objectshodgef/apiker1274 repos~1.5kAutomated safety check: PassMIT
Backend Dev Guidelineslitefuse/litefuse1011 repos~5.8kAutomated safety check: PassCustom licence
Debug DashboardBlackBeltTechnology/pi-agent-dashboard315—~1.6kAutomated safety check: PassMIT
Run And Verifyaropan/clist439—~461Automated safety check: PassApache-2.0

Similar skills

  • Frontmcp Testing

    agentfront/frontmcp

    A skill your agent uses for anything about testing FrontMCP servers: writing or running unit, integration, and E2E tests and reaching the 95%+ coverage bar.

    146 GitHub stars~10k tokensUpdated today
    Testing & QAAuto-check: notes
  • Durable Objects

    hodgef/apiker

    Create and review Cloudflare Durable Objects. An agent skill from hodgef/apiker.

    127 GitHub starsUsed in 4 repos~1.5k tokens
    Backend & APIsAuto-check passed
  • Backend Dev Guidelines

    litefuse/litefuse

    Comprehensive backend development guide for Litefuse's Next.js 14/tRPC/Express/TypeScript monorepo.

    101 GitHub starsUsed in 1 repo~5.8k tokens
    Backend & APIsAuto-check passed
  • Debug Dashboard

    BlackBeltTechnology/pi-agent-dashboard

    Diagnose problems in the running pi-agent-dashboard system: server.log, /api/health, bridge WebSocket connectivity, vitest triage, known-issue FAQ entries.

    315 GitHub stars~1.6k tokensUpdated today
    Backend & APIsAuto-check passed
  • Run And Verify

    aropan/clist

    Choose and run focused checks after changing CLIST Python code: Django tests, standalone pytest tests, offline parser fixtures, Ruff, or a relevant management-command check.

    439 GitHub stars~461 tokensUpdated 6 days ago
    Backend & APIsAuto-check passed
  • Tinystruct Patterns

    templetongroup/radiant

    Expert guidance for developing with the tinystruct Java framework.

    113 GitHub stars~3k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed

More from giuseppe-trisciuoglio/developer-kit

All 115 skills in this repo
  • Nestjs Drizzle Crud Generator

    giuseppe-trisciuoglio/developer-kit

    Generates complete CRUD modules for NestJS applications with Drizzle ORM.

    357 GitHub stars~1.3k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Actuator

    giuseppe-trisciuoglio/developer-kit

    Provides patterns to configure Spring Boot Actuator for production-grade monitoring, health probes, secured management endpoints, and Micrometer metrics across JVM services.

    357 GitHub stars~2.2k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Crud Patterns

    giuseppe-trisciuoglio/developer-kit

    Provides and generates complete CRUD workflows for Spring Boot 3 services.

    357 GitHub stars~2.5k tokensUpdated 1 mo ago
    Auto-check: notes
  • Spring Boot Security JWT

    giuseppe-trisciuoglio/developer-kit

    Provides JWT authentication and authorization patterns for Spring Boot 3.5.x covering token generation with JJWT, Bearer/cookie authentication, database/OAuth2 integration, and RBAC/permission-based…

    357 GitHub stars~3.9k tokensUpdated 1 mo ago
    Auto-check: notes
  • AWS CLI Beast

    giuseppe-trisciuoglio/developer-kit

    Provides advanced AWS CLI patterns for managing EC2, Lambda, S3, DynamoDB, RDS, VPC, IAM, and CloudWatch.

    357 GitHub stars~1.7k tokensUpdated 1 mo ago
    Auto-check: notes
  • PR Review Comments

    giuseppe-trisciuoglio/developer-kit

    Posts review findings from a JSON file as inline comments on a GitHub Pull Request, attaching each comment to its file and line.

    357 GitHub stars~1k tokensUpdated 1 mo ago
    Auto-check: notes

Questions about Unit Test Security Authorization

What does Unit Test Security Authorization do?

Provides patterns for unit testing Spring Security with @PreAuthorize, @Secured, @RolesAllowed. Unit Test Security Authorization is an agent skill from giuseppe-trisciuoglio/developer-kit. Provides patterns for unit testing Spring Security with @PreAuthorize, @Secured, @RolesAllowed.

When should I use Unit Test Security Authorization?

Unit Test Security Authorization fits situations like: testing security configurations and access control logic; tasks that involve Authorization and RBAC; tasks that involve Unit testing.

How do I install Unit Test Security Authorization in Claude Code?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill unit-test-security-authorization -a claude-code`. Or copy the skill folder (plugins/developer-kit-java/skills/unit-test-security-authorization in giuseppe-trisciuoglio/developer-kit) into .claude/skills/unit-test-security-authorization in your project. Claude Code loads it when a task matches its description.

How do I install Unit Test Security Authorization in Codex?

Run `npx skills add giuseppe-trisciuoglio/developer-kit --skill unit-test-security-authorization -a codex`. Or copy the skill folder (plugins/developer-kit-java/skills/unit-test-security-authorization in giuseppe-trisciuoglio/developer-kit) into .agents/skills/unit-test-security-authorization in your project. Codex loads it when a task matches its description.

Can I use Unit Test Security Authorization in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add giuseppe-trisciuoglio/developer-kit --skill unit-test-security-authorization -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/unit-test-security-authorization, .gemini/skills/unit-test-security-authorization, .github/skills/unit-test-security-authorization and .opencode/skills/unit-test-security-authorization in your project.

What does Unit Test Security Authorization need to run?

SKILL.md names no scripts, command-line tools or credentials: Unit Test Security Authorization is instructions for the agent only. Its frontmatter pre-approves these tools: Read, Write, Bash, Glob, Grep.

Does Unit Test Security Authorization access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Unit Test Security Authorization safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Unit Test Security Authorization use?

Unit Test Security Authorization is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Unit Test Security Authorization use?

About 1.7k tokens (SKILL.md is roughly 6.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 6.5k tokens, read only when the agent opens those files.

What are the alternatives to Unit Test Security Authorization?

Skills that share tags, products or a category with Unit Test Security Authorization: Frontmcp Testing (agentfront/frontmcp, 146 stars), Durable Objects (hodgef/apiker, 127 stars), Backend Dev Guidelines (litefuse/litefuse, 101 stars) and Debug Dashboard (BlackBeltTechnology/pi-agent-dashboard, 315 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Unit Test Security Authorization?

giuseppe-trisciuoglio (a GitHub user) maintains it in giuseppe-trisciuoglio/developer-kit, which has 357 GitHub stars. The repository holds 115 skills in this directory. The repository was last updated on September 10, 2026.

Source: giuseppe-trisciuoglio/developer-kit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.