Agent skill

112 Java Maven Plugins

by jabrena in jabrena/plinth

A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning…

Apache-2.0Auto-check passedSecurity

Install 112 Java Maven Plugins

skills CLI
$ npx skills add jabrena/plinth --skill 112-java-maven-plugins -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jabrena/plinth 112-java-maven-plugins --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jabrena/plinth.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/112-java-maven-plugins .claude/skills/112-java-maven-plugins && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
112-java-maven-plugins
GitHub stars
446
Token cost
~3.2k tokens
SKILL.md length
1,140 words
Files
20 (incl. references)
Skills in repo
124
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning…

  • Works in 8 steps: Scan existing plugins in , , and . → Scan existing properties in . → Scan existing profiles in . → …
  • You need to add
  • SKILL.md covers Constraints, When to use this skill, Workflow and Reference
  • Calls mvn

What it does

112 Java Maven Plugins is an agent skill from jabrena/plinth. Use when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning (OWASP), code formatting (Spotless), version management, container image build (Jib), build information tracking, and benchmarking (JMH) — through a consultative, modular step-by-step approach that only adds what you actually need. This should trigger for requests such as Add Maven plugins in pom.xml; Improve Maven plugins in pom.xml…

Its SKILL.md is about 3.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 20 other files, including reference files (for example `references/112-java-maven-plugins-flatten-maven-plugin.md`, `references/112-java-maven-plugins-git-commit-id-maven-plugin.md` and `references/112-java-maven-plugins-jib-maven-plugin.md`).

It sits in Security, covering Web application vulnerabilities, Linting and formatting and Containers. It works with Java. The repository describes itself as: Plinth is an AI-native engineering toolkit for modern Java enterprise SDLC, built around reusable Commands, Agents, Skills, and MCP Servers. The licence is Apache-2.0.

When your agent uses it

  • You need to add
  • Configure Maven plugins in your pom.xml — including quality tools (enforcer
  • Security scanning (OWASP)
  • Code formatting (Spotless)

Example prompts

  • “/112-java-maven-plugins”

Requirements

  • Docker

Workflow steps

8 steps, taken from the first numbered list in SKILL.md.

  1. Scan existing plugins in , , and .
  2. Scan existing properties in .
  3. Scan existing profiles in .
  4. Identify conflicts between existing configuration and possible additions.
  5. Preserve all existing plugins, properties, and profiles.
  6. Ask the user before enhancing any existing plugin, property, reporting entry, support file, or profile.
  7. Skip duplicate additions unless the user explicitly requests an enhancement.
  8. Check Maven Wrapper before plugin changes

What it can do on your machine

Read from SKILL.md and the folder at commit dca88dc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • mvn

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • sonarcloud.io

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

112 Java Maven Plugins loads about 3.2k tokens when it runs, and up to ~29k if it reads all its reference files. Until then it costs about 176 tokens; SKILL.md has 1,140 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~176
When it runs · the whole SKILL.md, loaded when a task matches
~3.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~29k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jabrena/plinth at commit dca88dc, republished under its Apache-2.0 licence (© jabrena). 1,140 words, ~3,184 tokens.

Download SKILL.mdSave it as .claude/skills/112-java-maven-plugins/SKILL.md (or your agent's skills folder). This skill also uses 19 other files; get the full folder from GitHub.
name
112-java-maven-plugins
description
Use when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning (OWASP), code formatting (Spotless), version management, container image build (Jib), build information tracking, and benchmarking (JMH) — through a consultative, modular step-by-step approach that only adds what you actually need. This should trigger for requests such as Add Maven plugins in pom.xml; Improve Maven plugins in pom.xml; Configure Maven quality plugins in pom.xml; Add Maven build lifecycle plugins for Java verification; Review Maven plugin versions and executions. Part of Plinth Toolkit
license
Apache-2.0
metadata.author
Juan Antonio Breña Moral
metadata.version
0.19.0

Maven Plugins: pom.xml Configuration Best Practices

Configure Maven plugins and profiles in pom.xml using a structured, question-driven process that preserves existing configuration. This is an interactive SKILL.

What is covered in this Skill?

Maven plugins:

  • Maven Compiler
  • Maven Enforcer
  • Maven Surefire
  • Maven Failsafe
  • HTML test reports (Surefire Report, JXR)
  • Maven Spotless
  • Maven Flatten
  • Maven Versions
  • Maven Git Commit ID
  • Maven Jib

Maven profiles:

  • JaCoCo (code coverage)
  • PiTest (mutation testing)
  • Security (OWASP dependency check)
  • Static analysis (SpotBugs, PMD)
  • SonarQube/SonarCloud
  • JMH (Java Microbenchmark Harness)
  • Cyclomatic complexity

Constraints

Before applying plugin recommendations, ensure the project is in a valid state. Use a structured, question-driven process that preserves existing configuration and adds only what the user selects.

  • MANDATORY: Run ./mvnw validate or mvn validate before applying any plugin recommendations
  • SAFETY: If validation fails, stop and ask the user to fix issues—do not proceed until resolved
  • SCOPE: Begin with Step 1 (existing configuration analysis) before any changes. Never remove or replace existing plugins; only add new ones that do not conflict
  • BEFORE READING PLUGIN REFERENCES: Run the question flow embedded in this SKILL.md first. Ask questions one-by-one in strict order, collect all selected plugins/profiles and conditional values, then read only the implementation references selected by the user's answers

When to use this skill

  • Add Maven plugins in pom.xml
  • Improve Maven plugins in pom.xml
  • Configure Maven quality plugins in pom.xml
  • Add Maven build lifecycle plugins for Java verification
  • Review Maven plugin versions and executions

Workflow

  1. Validate project before plugin changes

Run ./mvnw validate or mvn validate and stop if validation fails.

  1. Analyze current plugin and profile configuration

Before making any changes to pom.xml:

  1. Scan existing plugins in <build><plugins>, <build><pluginManagement>, and <reporting><plugins>.

  2. Scan existing properties in <properties>.

  3. Scan existing profiles in <profiles>.

  4. Identify conflicts between existing configuration and possible additions.

  5. Preserve all existing plugins, properties, and profiles.

  6. Ask the user before enhancing any existing plugin, property, reporting entry, support file, or profile.

  7. Skip duplicate additions unless the user explicitly requests an enhancement.

  8. Check Maven Wrapper before plugin changes

Check for Maven Wrapper files in the project root:

  • mvnw and mvnw.cmd
  • .mvn/wrapper/maven-wrapper.properties

If Maven Wrapper is not present, stop and ask:

"I notice this project doesn't have Maven Wrapper configured. The Maven Wrapper ensures everyone uses the same Maven version, improving build consistency across different environments. Would you like me to install it? (y/n)"

Wait for the user's response before asking any other question. If the user says "y", install it:

bash
mvn wrapper:wrapper
  1. Ask Maven plugin assessment questions before reading references

Run this XML-included question flow before reading any plugin/profile implementation reference. Ask one question at a time, wait for the user's answer, and record selected plugins, profiles, and conditional values before continuing.

Question 1: What type of Java project is this?

Options:

  • Java Library (for publishing to Maven Central/Nexus)
  • Java CLI Application (command-line tool)
  • Java Microservice (Web service/REST API/Modular monolith)
  • Serverless (AWS Lambdas, Azure Functions)
  • Java POC (Proof of Concept)
  • Other (specify)

Question 2: Which Java version does your project target?

Options:

  • Java 17 (LTS - recommended for new projects)
  • Java 21 (LTS - latest LTS version)
  • Java 25 (LTS - latest LTS version)
  • Other (specify version)

Question 3: What build and quality aspects are important for your project?

Options:

  • Format source code (Spotless)
  • Maven Enforcer
  • Unit Testing (Surefire)
  • Unit Testing Reports (Surefire Reports)
  • Integration testing (Failsafe)
  • Code coverage reporting (JaCoCo)
  • Mutation testing (PiTest)
  • Security vulnerability scanning (OWASP)
  • Security static code analysis (SpotBugs, PMD)
  • Sonar
  • Dependency analysis (maven-dependency-plugin)
  • Version management
  • Container image build (Jib)
  • JMH (Java Microbenchmark Harness)
  • Maven Compiler
  • Cyclomatic Complexity

Note: When "Cyclomatic Complexity" is selected, Step 20 will create a PMD ruleset file and profile. The ruleset location depends on project structure: src/main/pmd/pmd-cyclomatic-complexity.xml (mono-module) or pmd/pmd-cyclomatic-complexity.xml (multi-module).


Question 3.1 (conditional): What is your target container image for Jib?

Note: This question is only asked if "Container image build (Jib)" was selected in question 3.

  • Example format: gcr.io/my-project/my-app, docker.io/username/myimage, or myimage for local Docker
  • The image name will be used in the Jib plugin <to><image> configuration

Question 4: What is your target coverage threshold?

Options:

  • 70% (moderate)
  • 80% (recommended)
  • 90% (high)
  • Custom percentage (specify)
Show full SKILL.md (455 more words)Show less

Note: This question is only asked if "Code coverage reporting (JaCoCo)" was selected in question 3.


Question 5: Do you want to configure Sonar/SonarCloud integration?** (y/n)

Note: This question is only asked if "Static code analysis (SpotBugs, Sonar)" was selected in question 3.

If yes, please provide the following information:


Question 5.1: What is your Sonar organization identifier?

  • For SonarCloud: This is typically your GitHub username or organization name
  • For SonarQube: This is your organization key as configured in SonarQube
  • Example: my-github-user or my-company-org

Question 5.2: What is your Sonar project key?

  • For SonarCloud: Usually in format GITHUB_USER_REPOSITORY_NAME (e.g., john-doe_my-java-project)
  • For SonarQube: Custom project key as defined in your SonarQube instance
  • Must be unique within your Sonar organization
  • Example: john-doe_awesome-java-lib

Question 5.3: What is your Sonar project display name?

  • Human-readable name for your project as it appears in Sonar dashboard
  • Can contain spaces and special characters
  • Example: Awesome Java Library or My Microservice API

Question 5.4: Which Sonar service are you using? (conditional)

Note: This question is only asked if Sonar configuration was enabled in question 5.

Options:

  • SonarCloud (https://sonarcloud.io) - recommended for open source projects
  • SonarQube Server (specify your server URL)

If SonarQube Server: Please provide your SonarQube server URL (e.g., https://sonar.mycompany.com)


After all applicable questions are answered, confirm the selections and map them to references:

  • If Maven Compiler is selected, read references/112-java-maven-plugins-maven-compiler-plugin.md.
  • If Maven Enforcer is selected, read references/112-java-maven-plugins-maven-enforcer-plugin.md.
  • If Unit Testing (Surefire) is selected, read references/112-java-maven-plugins-maven-surefire-plugin.md.
  • If Integration testing (Failsafe) is selected, read references/112-java-maven-plugins-maven-failsafe-plugin.md.
  • If Unit Testing Reports (Surefire Reports) is selected, read references/112-java-maven-plugins-maven-surefire-report-plugin.md and references/112-java-maven-plugins-maven-jxr-plugin.md.
  • If Format source code (Spotless) is selected, read references/112-java-maven-plugins-spotless-maven-plugin.md.
  • If Version management is selected, read references/112-java-maven-plugins-versions-maven-plugin.md.
  • If build information tracking is selected, read references/112-java-maven-plugins-git-commit-id-maven-plugin.md.
  • If the project is a Java Library, read references/112-java-maven-plugins-flatten-maven-plugin.md.
  • If Container image build (Jib) is selected, read references/112-java-maven-plugins-jib-maven-plugin.md.
  • If Dependency analysis is selected, read references/112-java-maven-plugins-maven-dependency-plugin.md.
  • If Code coverage reporting (JaCoCo) is selected, read references/112-java-maven-plugins-profile-jacoco.md.
  • If Mutation testing (PiTest) is selected, read references/112-java-maven-plugins-profile-pitest.md.
  • If Security vulnerability scanning (OWASP) is selected, read references/112-java-maven-plugins-profile-security.md.
  • If Security static code analysis (SpotBugs, PMD) is selected, read references/112-java-maven-plugins-profile-static-analysis.md.
  • If Sonar is selected, read references/112-java-maven-plugins-profile-sonar.md.
  • If JMH is selected, read references/112-java-maven-plugins-profile-jmh.md.
  • If Cyclomatic Complexity is selected, read references/112-java-maven-plugins-profile-cyclomatic-complexity.md.
  • Do not read or apply unselected plugin/profile references.
  1. Read selected references and add only selected configuration

Add selected plugins and profiles without removing existing ones, preserving project structure and compatibility. Add only the Maven properties, plugin configuration, profile configuration, reporting plugins, and support files required by the selected references.

  1. Summarize applied plugin setup

Report added plugins/profiles, rationale, and recommended follow-up commands or checks.

Reference

For detailed guidance, examples, and constraints, see:

© jabrena, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 19 other files (references) in skills/112-java-maven-plugins of jabrena/plinth.

  • SKILL.md
  • references/112-java-maven-plugins-flatten-maven-plugin.md
  • references/112-java-maven-plugins-git-commit-id-maven-plugin.md
  • references/112-java-maven-plugins-jib-maven-plugin.md
  • references/112-java-maven-plugins-maven-compiler-plugin.md
  • references/112-java-maven-plugins-maven-dependency-plugin.md
  • references/112-java-maven-plugins-maven-enforcer-plugin.md
  • references/112-java-maven-plugins-maven-failsafe-plugin.md
  • references/112-java-maven-plugins-maven-jxr-plugin.md
  • references/112-java-maven-plugins-maven-surefire-plugin.md
  • references/112-java-maven-plugins-maven-surefire-report-plugin.md
  • references/112-java-maven-plugins-profile-cyclomatic-complexity.md
  • references/112-java-maven-plugins-profile-jacoco.md
  • references/112-java-maven-plugins-profile-jmh.md
  • references/112-java-maven-plugins-profile-pitest.md
  • references/112-java-maven-plugins-profile-security.md
  • references/112-java-maven-plugins-profile-sonar.md
  • references/112-java-maven-plugins-profile-static-analysis.md
  • references/112-java-maven-plugins-spotless-maven-plugin.md
  • references/112-java-maven-plugins-versions-maven-plugin.md

Open the folder on GitHubat commit dca88dc

Compare with similar skills

112 Java Maven Plugins next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

112 Java Maven Plugins compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
112 Java Maven Plugins this skilljabrena/plinth446—~3.2kAutomated safety check: PassApache-2.0
Code Audit3stoneBrother/code-audit8931 repos~2.7kAutomated safety check: PassNone
Mavenskjolber/3d-bin-container-packing568—~886Automated safety check: PassApache-2.0
Upgrade Java Depsnvuillam/npm-groovy-lint248—~1.9kAutomated safety check: NotesMIT
Code Securitysemgrep/skills322—~1.2kAutomated safety check: PassCustom licence
Taint Instrumentation AssistantArabelaTso/Skills-4-SE253—~2.9kAutomated safety check: PassApache-2.0

Similar skills

  • Code Audit

    3stoneBrother/code-audit

    Professional code security audit skill covering 55+ vulnerability types.

    893 GitHub starsUsed in 1 repo~2.7k tokens
    SecurityAuto-check passed
  • Maven

    skjolber/3d-bin-container-packing

    Maven build expertise for this multi-module Java project. An agent skill from skjolber/3d-bin-container-packing.

    568 GitHub stars~886 tokensUpdated today
    SecurityAuto-check passed
  • Upgrade Java Deps

    nvuillam/npm-groovy-lint

    Upgrade CodeNarc and the bundled Java dependencies (jackson, logback, slf4j, janino, GMetrics, Groovy libs) that ship inside lib/java/, rebuild the deterministic CodeNarcServer.jar, and verify…

    248 GitHub stars~1.9k tokensUpdated 4 days ago
    SecurityAuto-check: notes
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    322 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Taint Instrumentation Assistant

    ArabelaTso/Skills-4-SE

    Instruments code to track the flow of untrusted or sensitive data at runtime, enabling detection of injection vulnerabilities, data leaks, and privilege violations.

    253 GitHub stars~2.9k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Sca Trivy

    AgentSecOps/SecOpsAgentKit

    Software Composition Analysis (SCA) and container vulnerability scanning using Aqua Trivy for identifying CVE vulnerabilities in dependencies, container images, IaC misconfigurations, and license…

    220 GitHub starsUsed in 2 repos~3.7k tokens
    SecurityAuto-check passed

More from jabrena/plinth

All 124 skills in this repo
  • A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI…

    446 GitHub stars~874 tokensUpdated today
    Auto-check passed
  • A skill your agent uses when you need to generate Java project diagrams — including UML sequence diagrams, UML class diagrams, C4 model diagrams, UML state machine diagrams, UML Deployment Diagrams…

    446 GitHub stars~3.1k tokensUpdated today
    Auto-check passed
  • A skill your agent uses when you need to set up JMeter performance testing for a Java project — including creating the run-jmeter.sh script from the exact template, configuring load tests with…

    446 GitHub stars~842 tokensUpdated today
    Auto-check passed
  • A skill your agent uses when you need to set up Java application profiling to detect and measure performance issues — including trusted preinstalled async-profiler v4.x setup, problem-driven…

    446 GitHub stars~903 tokensUpdated today
    Auto-check passed
  • A skill your agent uses when you need to generate a checklist document with embedded commands inventory, following the embedded template exactly and producing INVENTORY-COMMANDS-JAVA.md in the…

    446 GitHub stars~697 tokensUpdated today
    Auto-check passed
  • 002 Agents Inventory

    jabrena/plinth

    A skill your agent uses when you need to generate a checklist document with embedded agents inventory, following the embedded template exactly and producing INVENTORY-AGENTS-JAVA.md in the project…

    446 GitHub stars~675 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about 112 Java Maven Plugins

What does 112 Java Maven Plugins do?

A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning…. 112 Java Maven Plugins is an agent skill from jabrena/plinth.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning (OWASP), code formatting (Spotless), version management, container image build (Jib), build information tracking, and benchmarking (JMH) — through a consultative, modular step-by-step approach that only adds what you actually need.

When should I use 112 Java Maven Plugins?

112 Java Maven Plugins fits situations like: you need to add; configure Maven plugins in your pom.xml — including quality tools (enforcer; security scanning (OWASP); code formatting (Spotless).

How do I install 112 Java Maven Plugins in Claude Code?

Run `npx skills add jabrena/plinth --skill 112-java-maven-plugins -a claude-code`. Or copy the skill folder (skills/112-java-maven-plugins in jabrena/plinth) into .claude/skills/112-java-maven-plugins in your project. Claude Code loads it when a task matches its description.

How do I install 112 Java Maven Plugins in Codex?

Run `npx skills add jabrena/plinth --skill 112-java-maven-plugins -a codex`. Or copy the skill folder (skills/112-java-maven-plugins in jabrena/plinth) into .agents/skills/112-java-maven-plugins in your project. Codex loads it when a task matches its description.

Can I use 112 Java Maven Plugins in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jabrena/plinth --skill 112-java-maven-plugins -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/112-java-maven-plugins, .gemini/skills/112-java-maven-plugins, .github/skills/112-java-maven-plugins and .opencode/skills/112-java-maven-plugins in your project.

What does 112 Java Maven Plugins need to run?

Going by SKILL.md and its folder, 112 Java Maven Plugins needs the command-line tools its instructions call (mvn). Our summary lists: Docker.

Does 112 Java Maven Plugins access the network?

SKILL.md names 1 domain. As links in the text: sonarcloud.io. This is read from the text; nothing was executed.

Is 112 Java Maven Plugins safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does 112 Java Maven Plugins use?

112 Java Maven Plugins is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does 112 Java Maven Plugins use?

About 3.2k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 26k tokens, read only when the agent opens those files.

What are the alternatives to 112 Java Maven Plugins?

Skills that share tags, products or a category with 112 Java Maven Plugins: Code Audit (3stoneBrother/code-audit, 893 stars), Maven (skjolber/3d-bin-container-packing, 568 stars), Upgrade Java Deps (nvuillam/npm-groovy-lint, 248 stars) and Code Security (semgrep/skills, 322 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains 112 Java Maven Plugins?

jabrena (a GitHub user) maintains it in jabrena/plinth, which has 446 GitHub stars. The repository holds 124 skills in this directory. The repository was last updated on October 7, 2026.

Source: jabrena/plinth on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.