Security Audit Scanner
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
A skill your agent uses when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing…
$ npx skills add jabrena/plinth --skill 124-java-secure-coding -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install jabrena/plinth 124-java-secure-coding --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/jabrena/plinth.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/124-java-secure-coding .claude/skills/124-java-secure-coding && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "124-java-secure-coding" agent skill from https://github.com/jabrena/plinth/tree/main/skills/124-java-secure-coding into .claude/skills/124-java-secure-coding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "124-java-secure-coding", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/jabrena/plinth/tree/main/skills/124-java-secure-codingType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add jabrena/plinth --skill 124-java-secure-coding -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install jabrena/plinth 124-java-secure-coding --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jabrena/plinth.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/124-java-secure-coding .agents/skills/124-java-secure-coding && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "124-java-secure-coding" agent skill from https://github.com/jabrena/plinth/tree/main/skills/124-java-secure-coding into .agents/skills/124-java-secure-coding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "124-java-secure-coding", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jabrena/plinth --skill 124-java-secure-coding -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install jabrena/plinth 124-java-secure-coding --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jabrena/plinth.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/124-java-secure-coding .cursor/skills/124-java-secure-coding && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "124-java-secure-coding" agent skill from https://github.com/jabrena/plinth/tree/main/skills/124-java-secure-coding into .cursor/skills/124-java-secure-coding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "124-java-secure-coding", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/jabrena/plinth.git --path skills/124-java-secure-coding--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add jabrena/plinth --skill 124-java-secure-coding -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install jabrena/plinth 124-java-secure-coding --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jabrena/plinth.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/124-java-secure-coding .gemini/skills/124-java-secure-coding && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "124-java-secure-coding" agent skill from https://github.com/jabrena/plinth/tree/main/skills/124-java-secure-coding into .gemini/skills/124-java-secure-coding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "124-java-secure-coding", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install jabrena/plinth 124-java-secure-codingInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add jabrena/plinth --skill 124-java-secure-coding -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/jabrena/plinth.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/124-java-secure-coding .github/skills/124-java-secure-coding && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "124-java-secure-coding" agent skill from https://github.com/jabrena/plinth/tree/main/skills/124-java-secure-coding into .github/skills/124-java-secure-coding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "124-java-secure-coding", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add jabrena/plinth --skill 124-java-secure-coding -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install jabrena/plinth 124-java-secure-coding --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/jabrena/plinth.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/124-java-secure-coding .opencode/skills/124-java-secure-coding && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "124-java-secure-coding" agent skill from https://github.com/jabrena/plinth/tree/main/skills/124-java-secure-coding into .opencode/skills/124-java-secure-coding/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "124-java-secure-coding", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
124-java-secure-codingA skill your agent uses when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing…
124 Java Secure Coding is an agent skill from jabrena/plinth. Use when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing attack surface via least privilege, applying strong cryptographic algorithms, handling exceptions securely without exposing sensitive data, managing secrets at runtime, avoiding unsafe deserialization, and encoding output to prevent XSS. This should trigger for requests such as Review Java code for secure coding; Find input validation…
Its SKILL.md is about 890 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/124-java-secure-coding.md`).
It sits in Security, covering Secure coding, Cryptography and Threat modeling. It works with Java. The repository describes itself as: Plinth is an AI-native engineering toolkit for modern Java enterprise SDLC, built around reusable Commands, Agents, Skills, and MCP Servers. The licence is Apache-2.0.
Read from SKILL.md and the folder at commit dca88dc. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
mvnFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
124 Java Secure Coding loads about 885 tokens when it runs, and up to ~9.6k if it reads all its reference files. Until then it costs about 181 tokens; SKILL.md has 334 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from jabrena/plinth at commit dca88dc, republished under its Apache-2.0 licence (© jabrena). 334 words, ~885 tokens.
.claude/skills/124-java-secure-coding/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.Identify and apply Java secure coding practices to reduce vulnerabilities, protect sensitive data, and harden application behaviour against common attack vectors.
What is covered in this Skill?
PreparedStatement and parameterized APIsScope: The reference is organized by examples (good/bad code patterns) for each core area. Apply recommendations based on applicable examples.
Before applying any secure coding changes, ensure the project compiles. If compilation fails, stop immediately — do not proceed until resolved. After applying improvements, run full verification.
./mvnw compile or mvn compile before applying any changes./mvnw clean verify or mvn clean verify after applying improvementsRun ./mvnw compile or mvn compile and stop immediately if compilation fails.
Read references/124-java-secure-coding.md and identify applicable vulnerabilities and hardening opportunities.
Implement selected protections for input validation, crypto, secrets, deserialization, and output encoding.
Run ./mvnw clean verify or mvn clean verify after applying improvements.
For detailed guidance, examples, and constraints, see references/124-java-secure-coding.md.
© jabrena, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 1 other file (references) in skills/124-java-secure-coding of jabrena/plinth.
Open the folder on GitHubat commit dca88dc
124 Java Secure Coding next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| 124 Java Secure Coding this skilljabrena/plinth | 446 | — | ~885 | Automated safety check: Pass | Apache-2.0 | |
| Security Audit Scannerruvnet/ruflo | 74k | 2 repos | ~823 | Automated safety check: Pass | MIT | |
| Security and Hardeningaddyosmani/agent-skills | 103k | 1 repos | ~4.4k | Automated safety check: Notes | MIT | |
| Code Securitysemgrep/skills | 322 | — | ~1.2k | Automated safety check: Pass | Custom licence | |
| Constant-Time Analysistrailofbits/skills | 7.4k | — | ~3.3k | Automated safety check: Notes | CC-BY-SA-4.0 | |
| Security Auditjellydn/my-ai-tools | 123 | — | ~2.9k | Automated safety check: Notes | MIT |
ruvnet/ruflo
Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.
addyosmani/agent-skills
Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.
semgrep/skills
Security guidelines for writing secure code. An agent skill from semgrep/skills.
trailofbits/skills
Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.
jellydn/my-ai-tools
A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.
github/awesome-copilot
AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…
jabrena/plinth
A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI…
jabrena/plinth
A skill your agent uses when you need to generate Java project diagrams — including UML sequence diagrams, UML class diagrams, C4 model diagrams, UML state machine diagrams, UML Deployment Diagrams…
jabrena/plinth
A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning…
jabrena/plinth
A skill your agent uses when you need to set up JMeter performance testing for a Java project — including creating the run-jmeter.sh script from the exact template, configuring load tests with…
jabrena/plinth
A skill your agent uses when you need to set up Java application profiling to detect and measure performance issues — including trusted preinstalled async-profiler v4.x setup, problem-driven…
jabrena/plinth
A skill your agent uses when you need to generate a checklist document with embedded commands inventory, following the embedded template exactly and producing INVENTORY-COMMANDS-JAVA.md in the…
Works with
Categories
A skill your agent uses when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing…. 124 Java Secure Coding is an agent skill from jabrena/plinth. Use when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing attack surface via least privilege, applying strong cryptographic algorithms, handling exceptions securely without exposing sensitive data, managing secrets at runtime, avoiding unsafe deserialization, and encoding output to prevent XSS.
124 Java Secure Coding fits situations like: you need to apply Java secure coding best practices — including validating untrusted inputs; defending against injection attacks with parameterized queries; minimizing attack surface via least privilege; applying strong cryptographic algorithms.
Run `npx skills add jabrena/plinth --skill 124-java-secure-coding -a claude-code`. Or copy the skill folder (skills/124-java-secure-coding in jabrena/plinth) into .claude/skills/124-java-secure-coding in your project. Claude Code loads it when a task matches its description.
Run `npx skills add jabrena/plinth --skill 124-java-secure-coding -a codex`. Or copy the skill folder (skills/124-java-secure-coding in jabrena/plinth) into .agents/skills/124-java-secure-coding in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jabrena/plinth --skill 124-java-secure-coding -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/124-java-secure-coding, .gemini/skills/124-java-secure-coding, .github/skills/124-java-secure-coding and .opencode/skills/124-java-secure-coding in your project.
Going by SKILL.md and its folder, 124 Java Secure Coding needs the command-line tools its instructions call (mvn).
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
124 Java Secure Coding is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 885 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with 124 Java Secure Coding: Security Audit Scanner (ruvnet/ruflo, 74k stars), Security and Hardening (addyosmani/agent-skills, 103k stars), Code Security (semgrep/skills, 322 stars) and Constant-Time Analysis (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
jabrena (a GitHub user) maintains it in jabrena/plinth, which has 446 GitHub stars. The repository holds 124 skills in this directory. The repository was last updated on October 7, 2026.
Source: jabrena/plinth on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.