Agent skill

Code Quality

by piomin in piomin/claude-ai-spring-boot

Comprehensive code review for Java - clean code principles, API contracts, null safety, exception handling, and performance.

Apache-2.0Auto-check passedDevelopment

Install Code Quality

skills CLI
$ npx skills add piomin/claude-ai-spring-boot --skill code-quality -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install piomin/claude-ai-spring-boot code-quality --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/piomin/claude-ai-spring-boot.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/code-quality .claude/skills/code-quality && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-quality
GitHub stars
1.3k
Token cost
~2.2k tokens
SKILL.md length
358 words
Files
1
Skills in repo
2
Repo updated
First seen
Licence
Apache-2.0

At a glance

Comprehensive code review for Java - clean code principles, API contracts, null safety, exception handling, and performance.

  • Works in 3 steps: Quick scan - Understand intent, identify… → Checklist pass - Apply relevant… → Summary - List findings by severity…
  • User says review code
  • SKILL.md covers When to Use, Review Strategy, Clean Code Principles and API Contract Review, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Code Quality is an agent skill from piomin/claude-ai-spring-boot. Comprehensive code review for Java - clean code principles, API contracts, null safety, exception handling, and performance. Use when user says "review code", "refactor", "check API", or before merging changes.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Code quality, Code review and API design. It works with Java, PostgreSQL, Docker and JUnit. The repository describes itself as: Claude Code template for Spring Boot and other staff (included in the tags). The licence is Apache-2.0.

When your agent uses it

  • User says review code
  • Before merging changes

Example prompts

  • “review code”
  • “refactor”
  • “check API”
  • “/code-quality”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Quick scan - Understand intent, identify scope
  2. Checklist pass - Apply relevant categories below
  3. Summary - List findings by severity (Critical → Minor → Good)

What it can do on your machine

Read from SKILL.md and the folder at commit d87e7a3. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md (its code samples are java and markdown).

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Quality loads about 2.2k tokens when it runs. Until then it costs about 56 tokens; SKILL.md has 358 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~56
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from piomin/claude-ai-spring-boot at commit d87e7a3, republished under its Apache-2.0 licence (© piomin). 358 words, ~2,177 tokens.

Download SKILL.mdSave it as .claude/skills/code-quality/SKILL.md (or your agent's skills folder).
name
code-quality
description
Comprehensive code review for Java - clean code principles, API contracts, null safety, exception handling, and performance. Use when user says "review code", "refactor", "check API", or before merging changes.

Code Quality Review Skill

Systematic code review combining clean code principles, API design, and Java best practices.

When to Use

  • "review this code" / "code review" / "check this PR"
  • "refactor" / "clean this code" / "improve readability"
  • "review API" / "check endpoints" / "REST review"
  • Before merging PR or releasing API changes

Review Strategy

  1. Quick scan - Understand intent, identify scope
  2. Checklist pass - Apply relevant categories below
  3. Summary - List findings by severity (Critical → Minor → Good)

Clean Code Principles

DRY - Don't Repeat Yourself

Violation:

java
// ❌ Duplicated validation logic
public void createUser(UserRequest req) {
    if (req.getEmail() == null || !req.getEmail().contains("@")) {
        throw new ValidationException("Invalid email");
    }
}

public void updateUser(UserRequest req) {
    if (req.getEmail() == null || !req.getEmail().contains("@")) {
        throw new ValidationException("Invalid email");
    }
}

Fix:

java
// ✅ Single source of truth
public class EmailValidator {
    public void validate(String email) {
        if (email == null || !email.contains("@")) {
            throw new ValidationException("Invalid email");
        }
    }
}
KISS - Keep It Simple

Violation:

java
// ❌ Over-engineered
public interface UserFactory {
    User createUser();
}
public class ConcreteUserFactory implements UserFactory {
    public User createUser() { return new User(); }
}

Fix:

java
// ✅ Simple
public User createUser() { return new User(); }
YAGNI - You Aren't Gonna Need It

Violation:

java
// ❌ Premature abstraction
public class ConfigurableUserServiceFactoryProvider { }

Fix:

java
// ✅ Implement when actually needed
public class UserService { }

API Contract Review

HTTP Verb Semantics
VerbUse ForIdempotentSafe
GETRetrieve resourceYesYes
POSTCreate new resourceNoNo
PUTReplace entire resourceYesNo
PATCHPartial updateNo*No
DELETERemove resourceYesNo

Common Mistakes:

java
// ❌ POST for retrieval
@PostMapping("/users/search")
public List<User> search(@RequestBody SearchCriteria criteria) { }

// ✅ GET with query params
@GetMapping("/users")
public List<User> search(@RequestParam String name) { }

// ❌ GET for state change
@GetMapping("/users/{id}/activate")
public void activate(@PathVariable Long id) { }

// ✅ POST/PATCH for state change
@PostMapping("/users/{id}/activate")
public ResponseEntity<Void> activate(@PathVariable Long id) { }
API Versioning
java
// ✅ URL path versioning (recommended)
@RestController
@RequestMapping("/api/v1/users")
public class UserControllerV1 { }

// ❌ No versioning
@RequestMapping("/users")  // Breaking changes affect all clients
Response Status Codes
CodeUse CaseExample
200 OKSuccessful GET/PUT/PATCHFound resource
201 CreatedSuccessful POSTNew resource created
204 No ContentSuccessful DELETEResource deleted
400 Bad RequestValidation failureInvalid input
404 Not FoundResource doesn't existUser not found
409 ConflictState conflictDuplicate email
500 Server ErrorUnexpected errorDatabase down
DTO vs Entity Exposure
java
// ❌ Exposing JPA entity
@GetMapping("/{id}")
public User getUser(@PathVariable Long id) {
    return userRepository.findById(id).get();  // Exposes internals, N+1 risk
}

// ✅ Use DTO
@GetMapping("/{id}")
public UserResponse getUser(@PathVariable Long id) {
    return userService.findById(id);  // Returns DTO
}

Java Code Review Checklist

Null Safety

Check for:

java
// ❌ NPE risk
String name = user.getName().toUpperCase();

// ✅ Safe with Optional
String name = Optional.ofNullable(user.getName())
    .map(String::toUpperCase)
    .orElse("");

// ✅ Safe with early return
if (user.getName() == null) return "";
return user.getName().toUpperCase();

Flags:

  • Chained calls without null checks
  • Optional.get() without isPresent()
  • Returning null instead of Optional or empty collection
  • Missing @Nullable/@NonNull on public APIs
Show full SKILL.md (131 more words)Show less
Exception Handling

Check for:

java
// ❌ Swallowing exceptions
try {
    process();
} catch (Exception e) { }  // Silent failure

// ❌ Losing stack trace
catch (IOException e) {
    throw new RuntimeException(e.getMessage());  // Lost context
}

// ✅ Proper handling
catch (IOException e) {
    log.error("Failed to process file: {}", filename, e);
    throw new ProcessingException("File processing failed", e);
}

Flags:

  • Empty catch blocks
  • Catching Exception or Throwable (too broad)
  • Not logging exceptions
  • Creating new exception without original cause
Resource Management

Check for:

java
// ❌ Resource leak
FileInputStream fis = new FileInputStream(file);
String content = read(fis);
fis.close();  // Won't execute if read() throws

// ✅ Try-with-resources
try (FileInputStream fis = new FileInputStream(file)) {
    return read(fis);
}  // Auto-closed
Transaction Boundaries

Check for:

java
// ❌ Missing transaction
public void createUser(UserRequest request) {
    User user = new User();
    userRepository.save(user);
    roleRepository.save(new Role(user));  // Two separate transactions
}

// ✅ Proper transaction
@Transactional
public void createUser(UserRequest request) {
    User user = new User();
    userRepository.save(user);
    roleRepository.save(new Role(user));  // Single atomic transaction
}
Naming Conventions

Good:

java
// ✅ Clear intent
public List<User> findActiveUsersByRole(String role) { }
public boolean isEmailValid(String email) { }
public void activateUser(Long userId) { }

Bad:

java
// ❌ Unclear
public List<User> get(String s) { }
public boolean check(String str) { }
public void doStuff(Long id) { }
Performance

Check for:

java
// ❌ N+1 query problem
List<User> users = userRepository.findAll();
for (User user : users) {
    List<Order> orders = orderRepository.findByUserId(user.getId());  // N queries
}

// ✅ Join fetch
@Query("SELECT u FROM User u LEFT JOIN FETCH u.orders")
List<User> findAllWithOrders();

// ❌ Loading all data
List<User> allUsers = userRepository.findAll();  // Could be millions

// ✅ Pagination
Page<User> users = userRepository.findAll(PageRequest.of(0, 20));

Review Output Format

markdown
## Code Review: [Component/Feature Name]

### Critical Issues
- **Null safety violation** (UserService.java:42) - `user.getName().toUpperCase()` can NPE. Use Optional or null check.
- **Resource leak** (FileHandler.java:15) - FileInputStream not closed. Use try-with-resources.

### Important Improvements
- **API design** - POST used for idempotent update (UserController.java:28). Use PUT instead.
- **Transaction missing** - Multi-step operation needs @Transactional (OrderService.java:56).
- **N+1 query** - Loop fetches orders individually (line 89). Use JOIN FETCH.

### Code Smells
- **Long method** - extractUserData() is 80 lines. Consider extracting sub-methods.
- **Magic number** - Use named constant instead of `86400` (line 123).
- **Inconsistent naming** - Mix of camelCase and snake_case in variables.

### Good Practices Observed
- ✅ Constructor injection used throughout
- ✅ DTOs properly separate from entities
- ✅ Comprehensive validation on all endpoints
- ✅ Good test coverage (87%)

Quick Reference Flags

CategoryRed Flags
Null SafetyChained calls, Optional.get(), returning null
ExceptionsEmpty catch, broad catch, lost stack trace
ResourcesManual close(), missing try-with-resources
API DesignWrong HTTP verb, no versioning, entity exposure
TransactionsMulti-step writes without @Transactional
PerformanceN+1 queries, loading all data, missing indexes
Clean CodeCode duplication, magic numbers, unclear names

Severity Levels

  • Critical - Security, data loss, crash risk → Must fix before merge
  • Important - Performance, maintainability, correctness → Should fix
  • Code Smell - Style, complexity, minor issues → Nice to have
  • Good - Positive feedback to reinforce good practices

© piomin, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .claude/skills/code-quality of piomin/claude-ai-spring-boot.

Open the folder on GitHubat commit d87e7a3

Compare with similar skills

Code Quality next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Quality compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Quality this skillpiomin/claude-ai-spring-boot1.3k—~2.2kAutomated safety check: PassApache-2.0
Cross-Language Coding Standardszereight/gitlab-mcp2k1 repos~1.4kAutomated safety check: PassMIT
Code PatternsAedelon/claude-code-blueprint120—~1.2kAutomated safety check: PassCustom licence
Code Review Skillawesome-skills/code-review-skill2.1k—~2.8kAutomated safety check: NotesMIT
Git Commitsdatabasus/databasus8.8k—~294Automated safety check: PassApache-2.0
Software Design Philosophyluoling8192/software-design-philosophy-skill344—~3.4kAutomated safety check: PassMIT

Similar skills

  • Shared reference for naming, function size, complexity and error handling rules that reviewer agents apply across TypeScript, Python, Go, Rust, Java, C# and Swift.

    2k GitHub starsUsed in 1 repo~1.4k tokens
    DevelopmentAuto-check passed
  • Code Patterns

    Aedelon/claude-code-blueprint

    Reference patterns for REST APIs, pytest/vitest testing, Docker multi-stage builds, GitHub Actions CI/CD, PostgreSQL, TypeScript generics, Python async, and React Server Components.

    120 GitHub stars~1.2k tokensUpdated 7 mo ago
    DevOps & CloudAuto-check passed
  • Code Review Skill

    awesome-skills/code-review-skill

    Provides comprehensive code review guidance for React 19, Vue 3, Angular 17+, Svelte 5, Rust, TypeScript, Java, Java 8, PHP, Ruby, Rails, Python, Django, FastAPI, Go, C/.NET, Kotlin, Swift, Dart…

    2.1k GitHub stars~2.8k tokensUpdated 28 days ago
    DevelopmentAuto-check: notes
  • Git Commits

    databasus/databasus

    Write Databasus commit messages and branch names using the repository's release-compatible format.

    8.8k GitHub stars~294 tokensUpdated 14 days ago
    DevelopmentAuto-check passed
  • Software Design Philosophy

    luoling8192/software-design-philosophy-skill

    Software design philosophy guide based on John Ousterhout's "A Philosophy of Software Design." Use this skill during: code reviews, architecture discussions, API design, module decomposition…

    344 GitHub stars~3.4k tokensUpdated 2 mo ago
    DevelopmentAuto-check passed
  • Audit Sibling Divergence

    ben-manes/caffeine

    Compares code paths that should behave the same, such as sync and async cache methods, and requires a concrete scenario where the two observably disagree.

    18k GitHub stars~4.3k tokensUpdated yesterday
    DevelopmentAuto-check: notes

More from piomin/claude-ai-spring-boot

  • Spring Boot

    piomin/claude-ai-spring-boot

    Spring Boot 3.x development - REST APIs, JPA, Security, Testing, and Cloud-native patterns.

    1.3k GitHub stars~2k tokensUpdated 5 mo ago
    Auto-check passed

Categories

Questions about Code Quality

What does Code Quality do?

Comprehensive code review for Java - clean code principles, API contracts, null safety, exception handling, and performance. Code Quality is an agent skill from piomin/claude-ai-spring-boot. Comprehensive code review for Java - clean code principles, API contracts, null safety, exception handling, and performance.

When should I use Code Quality?

Code Quality fits situations like: user says review code; before merging changes.

How do I install Code Quality in Claude Code?

Run `npx skills add piomin/claude-ai-spring-boot --skill code-quality -a claude-code`. Or copy the skill folder (.claude/skills/code-quality in piomin/claude-ai-spring-boot) into .claude/skills/code-quality in your project. Claude Code loads it when a task matches its description.

How do I install Code Quality in Codex?

Run `npx skills add piomin/claude-ai-spring-boot --skill code-quality -a codex`. Or copy the skill folder (.claude/skills/code-quality in piomin/claude-ai-spring-boot) into .agents/skills/code-quality in your project. Codex loads it when a task matches its description.

Can I use Code Quality in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add piomin/claude-ai-spring-boot --skill code-quality -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-quality, .gemini/skills/code-quality, .github/skills/code-quality and .opencode/skills/code-quality in your project.

What does Code Quality need to run?

SKILL.md names no scripts, command-line tools or credentials: Code Quality is instructions for the agent only.

Does Code Quality access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Code Quality safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Code Quality use?

Code Quality is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Code Quality use?

About 2.2k tokens (SKILL.md is roughly 8.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Quality?

Skills that share tags, products or a category with Code Quality: Cross-Language Coding Standards (zereight/gitlab-mcp, 2k stars), Code Patterns (Aedelon/claude-code-blueprint, 120 stars), Code Review Skill (awesome-skills/code-review-skill, 2.1k stars) and Git Commits (databasus/databasus, 8.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Quality?

piomin (a GitHub user) maintains it in piomin/claude-ai-spring-boot, which has 1,302 GitHub stars. The repository holds 2 skills in this directory. The repository was last updated on April 29, 2026.

Source: piomin/claude-ai-spring-boot on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.