Agent skill

124 Java Secure Coding

by jabrena in jabrena/plinth

A skill your agent uses when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing…

Apache-2.0Auto-check passedSecurity

Install 124 Java Secure Coding

skills CLI
$ npx skills add jabrena/plinth --skill 124-java-secure-coding -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jabrena/plinth 124-java-secure-coding --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jabrena/plinth.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/124-java-secure-coding .claude/skills/124-java-secure-coding && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
124-java-secure-coding
GitHub stars
446
Token cost
~885 tokens
SKILL.md length
334 words
Files
2 (incl. references)
Skills in repo
124
Repo updated
First seen
Licence
Apache-2.0

At a glance

A skill your agent uses when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing…

  • You need to apply Java secure coding best practices — including validating untrusted inputs
  • SKILL.md covers Constraints, When to use this skill, Workflow and Reference
  • Calls mvn
  • Defending against injection attacks with parameterized queries

What it does

124 Java Secure Coding is an agent skill from jabrena/plinth. Use when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing attack surface via least privilege, applying strong cryptographic algorithms, handling exceptions securely without exposing sensitive data, managing secrets at runtime, avoiding unsafe deserialization, and encoding output to prevent XSS. This should trigger for requests such as Review Java code for secure coding; Find input validation…

Its SKILL.md is about 890 tokens, which your agent loads only when the skill is triggered. The skill folder holds 2 other files, including reference files (for example `references/124-java-secure-coding.md`).

It sits in Security, covering Secure coding, Cryptography and Threat modeling. It works with Java. The repository describes itself as: Plinth is an AI-native engineering toolkit for modern Java enterprise SDLC, built around reusable Commands, Agents, Skills, and MCP Servers. The licence is Apache-2.0.

When your agent uses it

  • You need to apply Java secure coding best practices — including validating untrusted inputs
  • Defending against injection attacks with parameterized queries
  • Minimizing attack surface via least privilege
  • Applying strong cryptographic algorithms

Example prompts

  • “/124-java-secure-coding”

What it can do on your machine

Read from SKILL.md and the folder at commit dca88dc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • mvn

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

124 Java Secure Coding loads about 885 tokens when it runs, and up to ~9.6k if it reads all its reference files. Until then it costs about 181 tokens; SKILL.md has 334 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~181
When it runs · the whole SKILL.md, loaded when a task matches
~885
With references · SKILL.md plus every file in references/, read only if the agent opens them
~9.6k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jabrena/plinth at commit dca88dc, republished under its Apache-2.0 licence (© jabrena). 334 words, ~885 tokens.

Download SKILL.mdSave it as .claude/skills/124-java-secure-coding/SKILL.md (or your agent's skills folder). This skill also uses 1 other file; get the full folder from GitHub.
name
124-java-secure-coding
description
Use when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing attack surface via least privilege, applying strong cryptographic algorithms, handling exceptions securely without exposing sensitive data, managing secrets at runtime, avoiding unsafe deserialization, and encoding output to prevent XSS. This should trigger for requests such as Review Java code for secure coding; Find input validation risks in Java code; Review Java code for injection vulnerabilities; Improve secure error handling in Java services; Harden Java code against common security flaws. Part of Plinth Toolkit
license
Apache-2.0
metadata.author
Juan Antonio Breña Moral
metadata.version
0.19.0

Java Secure coding guidelines

Identify and apply Java secure coding practices to reduce vulnerabilities, protect sensitive data, and harden application behaviour against common attack vectors.

What is covered in this Skill?

  • Input validation: type, length, format, and range checks
  • SQL/OS/LDAP injection defence via PreparedStatement and parameterized APIs
  • Attack surface minimisation: least-privilege permissions, removal of unused features
  • Strong cryptography: BCrypt/Argon2 for passwords, AES-GCM for encryption, digital signatures; avoid deprecated ciphers (MD5, SHA-1, DES)
  • Secure exception handling: log diagnostic details internally, expose only generic messages to clients
  • Secrets management: load credentials from environment variables or secret managers — never hardcoded
  • Safe deserialization: strict allow-lists, prefer explicit DTOs over native Java serialization
  • Output encoding to prevent XSS in rendered content

Scope: The reference is organized by examples (good/bad code patterns) for each core area. Apply recommendations based on applicable examples.

Constraints

Before applying any secure coding changes, ensure the project compiles. If compilation fails, stop immediately — do not proceed until resolved. After applying improvements, run full verification.

  • MANDATORY: Run ./mvnw compile or mvn compile before applying any changes
  • SAFETY: If compilation fails, stop immediately — do not proceed until the project is in a valid state
  • VERIFY: Run ./mvnw clean verify or mvn clean verify after applying improvements
  • BEFORE APPLYING: Read the reference for detailed good/bad examples, constraints, and safeguards for each secure coding pattern

When to use this skill

  • Review Java code for secure coding
  • Find input validation risks in Java code
  • Review Java code for injection vulnerabilities
  • Improve secure error handling in Java services
  • Harden Java code against common security flaws

Workflow

  1. Compile project before secure-coding changes

Run ./mvnw compile or mvn compile and stop immediately if compilation fails.

  1. Read secure-coding reference and assess risks

Read references/124-java-secure-coding.md and identify applicable vulnerabilities and hardening opportunities.

  1. Apply secure-coding improvements

Implement selected protections for input validation, crypto, secrets, deserialization, and output encoding.

  1. Verify with full build

Run ./mvnw clean verify or mvn clean verify after applying improvements.

Reference

For detailed guidance, examples, and constraints, see references/124-java-secure-coding.md.

© jabrena, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 1 other file (references) in skills/124-java-secure-coding of jabrena/plinth.

  • SKILL.md
  • references/124-java-secure-coding.md

Open the folder on GitHubat commit dca88dc

Compare with similar skills

124 Java Secure Coding next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

124 Java Secure Coding compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
124 Java Secure Coding this skilljabrena/plinth446—~885Automated safety check: PassApache-2.0
Security Audit Scannerruvnet/ruflo74k2 repos~823Automated safety check: PassMIT
Security and Hardeningaddyosmani/agent-skills103k1 repos~4.4kAutomated safety check: NotesMIT
Code Securitysemgrep/skills322—~1.2kAutomated safety check: PassCustom licence
Constant-Time Analysistrailofbits/skills7.4k—~3.3kAutomated safety check: NotesCC-BY-SA-4.0
Security Auditjellydn/my-ai-tools123—~2.9kAutomated safety check: NotesMIT

Similar skills

  • Runs claude-flow CLI security scans for input validation, path traversal, SQL injection, XSS, hardcoded secrets and known CVEs, and writes an audit report.

    74k GitHub starsUsed in 2 repos~823 tokens
    SecurityAuto-check passed
  • Security and Hardening

    addyosmani/agent-skills

    Applies a threat-model-first approach to web code that handles untrusted input, authentication, data storage, dependencies or personal data.

    103k GitHub starsUsed in 1 repo~4.4k tokens
    SecurityAuto-check: notes
  • Code Security

    semgrep/skills

    Official

    Security guidelines for writing secure code. An agent skill from semgrep/skills.

    322 GitHub stars~1.2k tokensUpdated 2 mo ago
    SecurityAuto-check passed
  • Constant-Time Analysis

    trailofbits/skills

    Official

    Compiles cryptographic code and inspects the assembly or bytecode for variable-time instructions, then triages which flagged operations actually touch secrets.

    7.4k GitHub stars~3.3k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security Audit

    jellydn/my-ai-tools

    A skill your agent uses when reviewing code for security vulnerabilities, hardening an application, or deriving security requirements from OWASP/ASVS guidance.

    123 GitHub stars~2.9k tokensUpdated yesterday
    SecurityAuto-check: notes
  • Security Review

    github/awesome-copilot

    Official

    AI-powered codebase security scanner that reasons about code like a security researcher — tracing data flows, understanding component interactions, and catching vulnerabilities that pattern-matching…

    40k GitHub starsUsed in 1 repo~2.3k tokens
    SecurityAuto-check: notes

More from jabrena/plinth

All 124 skills in this repo
  • A skill your agent uses when you need to add or review fuzz testing for Java APIs with CATS — including contract-driven negative testing, malformed payload validation, boundary input exploration, CI…

    446 GitHub stars~874 tokensUpdated yesterday
    Auto-check passed
  • A skill your agent uses when you need to generate Java project diagrams — including UML sequence diagrams, UML class diagrams, C4 model diagrams, UML state machine diagrams, UML Deployment Diagrams…

    446 GitHub stars~3.1k tokensUpdated yesterday
    Auto-check passed
  • A skill your agent uses when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning…

    446 GitHub stars~3.2k tokensUpdated yesterday
    Auto-check passed
  • A skill your agent uses when you need to set up JMeter performance testing for a Java project — including creating the run-jmeter.sh script from the exact template, configuring load tests with…

    446 GitHub stars~842 tokensUpdated yesterday
    Auto-check passed
  • A skill your agent uses when you need to set up Java application profiling to detect and measure performance issues — including trusted preinstalled async-profiler v4.x setup, problem-driven…

    446 GitHub stars~903 tokensUpdated yesterday
    Auto-check passed
  • A skill your agent uses when you need to generate a checklist document with embedded commands inventory, following the embedded template exactly and producing INVENTORY-COMMANDS-JAVA.md in the…

    446 GitHub stars~697 tokensUpdated yesterday
    Auto-check passed

Works with

Categories

Questions about 124 Java Secure Coding

What does 124 Java Secure Coding do?

A skill your agent uses when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing…. 124 Java Secure Coding is an agent skill from jabrena/plinth. Use when you need to apply Java secure coding best practices — including validating untrusted inputs, defending against injection attacks with parameterized queries, minimizing attack surface via least privilege, applying strong cryptographic algorithms, handling exceptions securely without exposing sensitive data, managing secrets at runtime, avoiding unsafe deserialization, and encoding output to prevent XSS.

When should I use 124 Java Secure Coding?

124 Java Secure Coding fits situations like: you need to apply Java secure coding best practices — including validating untrusted inputs; defending against injection attacks with parameterized queries; minimizing attack surface via least privilege; applying strong cryptographic algorithms.

How do I install 124 Java Secure Coding in Claude Code?

Run `npx skills add jabrena/plinth --skill 124-java-secure-coding -a claude-code`. Or copy the skill folder (skills/124-java-secure-coding in jabrena/plinth) into .claude/skills/124-java-secure-coding in your project. Claude Code loads it when a task matches its description.

How do I install 124 Java Secure Coding in Codex?

Run `npx skills add jabrena/plinth --skill 124-java-secure-coding -a codex`. Or copy the skill folder (skills/124-java-secure-coding in jabrena/plinth) into .agents/skills/124-java-secure-coding in your project. Codex loads it when a task matches its description.

Can I use 124 Java Secure Coding in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jabrena/plinth --skill 124-java-secure-coding -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/124-java-secure-coding, .gemini/skills/124-java-secure-coding, .github/skills/124-java-secure-coding and .opencode/skills/124-java-secure-coding in your project.

What does 124 Java Secure Coding need to run?

Going by SKILL.md and its folder, 124 Java Secure Coding needs the command-line tools its instructions call (mvn).

Does 124 Java Secure Coding access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is 124 Java Secure Coding safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does 124 Java Secure Coding use?

124 Java Secure Coding is published under the Apache-2.0 licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does 124 Java Secure Coding use?

About 885 tokens (SKILL.md is roughly 3.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 8.8k tokens, read only when the agent opens those files.

What are the alternatives to 124 Java Secure Coding?

Skills that share tags, products or a category with 124 Java Secure Coding: Security Audit Scanner (ruvnet/ruflo, 74k stars), Security and Hardening (addyosmani/agent-skills, 103k stars), Code Security (semgrep/skills, 322 stars) and Constant-Time Analysis (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains 124 Java Secure Coding?

jabrena (a GitHub user) maintains it in jabrena/plinth, which has 446 GitHub stars. The repository holds 124 skills in this directory. The repository was last updated on October 7, 2026.

Source: jabrena/plinth on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.