Agent skill

Java Rules

by softspark in softspark/ai-toolkit

Java coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit.

Apache-2.0Auto-check passedBackend & APIs

Install Java Rules

skills CLI
$ npx skills add softspark/ai-toolkit --skill java-rules -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install softspark/ai-toolkit java-rules --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/app/skills/java-rules .claude/skills/java-rules && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
java-rules
GitHub stars
179
Token cost
~3.1k tokens
SKILL.md length
1,468 words
Files
1
Skills in repo
112
Repo updated
First seen
Licence
Apache-2.0

At a glance

Java coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit.

  • Tasks that involve Backend development
  • SKILL.md covers Naming, Modern Java (17+), Types and Classes, plus 21 more sections
  • Calls mvn
  • Tasks that involve ORMs and data access

What it does

Java Rules is an agent skill from softspark/ai-toolkit. Java coding rules: style, patterns, security, testing. Triggers: .java, pom.xml, build.gradle, Spring, Spring Boot, JPA, Hibernate, JUnit, Maven, Gradle.

Its SKILL.md is about 3.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Backend development, ORMs and data access and Unit testing. It works with Java, Gradle, Spring Boot and JUnit. The repository describes itself as: Professional-grade AI coding toolkit: 94 skills, 44 agents, multi-platform (Claude, Cursor, Windsurf, Copilot, Gemini, Cline, Roo Code, Aider, Augment, Antigravity, Codex CLI… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Backend development
  • Tasks that involve ORMs and data access
  • Tasks that involve Unit testing

Example prompts

  • “/java-rules”

Requirements

  • Pre-approved tools (allowed-tools): Read

What it can do on your machine

Read from SKILL.md and the folder at commit d64db2b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • mvn

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Java Rules loads about 3.1k tokens when it runs. Until then it costs about 41 tokens; SKILL.md has 1,468 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~41
When it runs · the whole SKILL.md, loaded when a task matches
~3.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from softspark/ai-toolkit at commit d64db2b, republished under its Apache-2.0 licence (© softspark). 1,468 words, ~3,141 tokens.

Download SKILL.mdSave it as .claude/skills/java-rules/SKILL.md (or your agent's skills folder).
name
java-rules
description
Java coding rules: style, patterns, security, testing. Triggers: .java, pom.xml, build.gradle, Spring, Spring Boot, JPA, Hibernate, JUnit, Maven, Gradle.
allowed-tools
Read
effort
medium
user-invocable
false

Java Rules

These rules come from app/rules/java/ in ai-toolkit. They cover the project's standards for coding style, frameworks, patterns, security, and testing in Java. Apply them when writing or reviewing Java code.

Java Coding Style

Naming

  • PascalCase: classes, interfaces, enums, records, annotations.
  • camelCase: methods, variables, parameters.
  • UPPER_SNAKE: constants (static final).
  • Package names: lowercase, dot-separated, reverse domain (com.company.project).
  • No Hungarian notation. No I prefix on interfaces.

Modern Java (17+)

  • Use record for immutable data carriers. No need for Lombok in most cases.
  • Use sealed classes/interfaces for restricted hierarchies.
  • Use pattern matching: if (obj instanceof String s) instead of cast.
  • Use switch expressions with arrow syntax and exhaustiveness.
  • Use text blocks (""") for multiline strings (SQL, JSON, HTML).

Types

  • Use var for local variables when the type is obvious from the right-hand side.
  • Use Optional<T> for return types that may be absent. Never for fields or params.
  • Prefer List.of(), Map.of(), Set.of() for immutable collections.
  • Use Stream for collection transformations. Avoid streams for simple iterations.

Classes

  • Prefer composition over inheritance. Use interfaces for abstraction.
  • Keep classes focused: single responsibility.
  • Use final on classes not designed for extension.
  • Use private constructors + static factory methods for controlled instantiation.
  • Records over POJOs for value types. Lombok only if records are insufficient.

Methods

  • Max 20-30 lines per method. Extract when longer.
  • Use @Override on every overridden method.
  • Return empty collections over null. Use Collections.emptyList() or List.of().
  • Avoid checked exceptions for programming errors. Use runtime exceptions.

Formatting

  • Use project formatter (Google Java Format or IDE-configured).
  • Use @SuppressWarnings sparingly and with specific warning names.
  • Use final for parameters and local variables where practical.

Nullability

  • Annotate with @Nullable / @NonNull from JSpecify or JetBrains.
  • Use Objects.requireNonNull() at public API boundaries.
  • Never return null from collections or arrays. Return empty.
  • Use Optional for genuinely optional return values.

Documentation

  • Javadoc on all public classes and methods.
  • Use @param, @return, @throws tags for public API methods.
  • Skip Javadoc for obvious getters, toString(), and equals().

Java Frameworks

Spring Boot

  • Use Spring Boot 3+ with Java 17+ minimum.
  • Use @RestController for REST APIs. Return ResponseEntity for status control.
  • Use @Valid + Jakarta Bean Validation for request validation.
  • Use profiles (@Profile) for environment-specific configuration.
  • Use application.yml over application.properties for readability.
  • Externalize config: env vars > config files > hardcoded defaults.

Spring Data JPA

  • Use repository interfaces extending JpaRepository.
  • Use @Query with JPQL for custom queries. Use native queries only when needed.
  • Use @EntityGraph to prevent N+1 queries in associations.
  • Use Specification for dynamic query building.
  • Always use @Transactional at the service layer, not repository.

Spring Security

  • Use SecurityFilterChain bean configuration (not WebSecurityConfigurerAdapter).
  • Use @PreAuthorize / @Secured for method-level authorization.
  • Use BCrypt for password encoding: new BCryptPasswordEncoder().
  • Configure CORS, CSRF, and session management explicitly.
  • Use OAuth2 Resource Server for JWT validation in APIs.

Hibernate / JPA

  • Use FetchType.LAZY by default on all associations.
  • Use @BatchSize or @Fetch(FetchMode.SUBSELECT) to avoid N+1.
  • Use @Version for optimistic locking on entities.
  • Use DTOs (records) for read queries. Do not expose entities in APIs.
  • Use Flyway or Liquibase for schema migrations.

Quarkus / Micronaut

  • Use for microservices and serverless where startup time matters.
  • Use compile-time DI (Micronaut) or build-time optimization (Quarkus).
  • Use reactive patterns with Mutiny (Quarkus) or Reactor (Micronaut).
  • Use native image builds with GraalVM for production deployments.

Build Tools

  • Use Gradle (Kotlin DSL) for new projects. Maven for enterprise legacy.
  • Use dependency management to unify versions across modules.
  • Use Bill of Materials (BOM) imports for consistent Spring versions.
  • Use Spotless or Checkstyle for enforced code formatting.

Logging

  • Use SLF4J facade with Logback or Log4j2 backend.
  • Use structured logging with MDC for correlation IDs.
  • Use parameterized logging: log.info("User {} created", userId).
  • Never log sensitive data (passwords, tokens, PII).

Java Patterns

Error Handling

  • Use unchecked exceptions for programming errors (IllegalArgumentException).
  • Use checked exceptions only for recoverable conditions the caller must handle.
  • Create domain exception hierarchy: AppException -> NotFoundException, etc.
  • Never catch Exception or Throwable broadly. Catch specific types.
  • Use try-with-resources for all AutoCloseable resources.

Immutability

  • Use record for immutable value objects (Java 16+).
  • Use List.copyOf(), Map.copyOf() to create unmodifiable copies.
  • Make fields private final. No setters unless mutation is required.
  • Return defensive copies of mutable collections from getters.
  • Use builder pattern for constructing immutable objects with many fields.

Optional

  • Use Optional<T> as return type for methods that may not return a value.
  • Chain: optional.map(...).orElseThrow(...). Avoid isPresent() + get().
  • Never use Optional for fields, method parameters, or collection elements.
  • Use Optional.empty() over null. Use Optional.ofNullable() at boundaries.

Streams

  • Use streams for transformations: filter, map, collect.
  • Avoid side effects in stream operations. Keep them pure.
  • Use Collectors.toUnmodifiableList() for immutable results.
  • Prefer for loop for simple iterations that do not transform data.
  • Use Stream.of() or IntStream.range() for generating sequences.

Dependency Injection

  • Use constructor injection exclusively. No field or setter injection.
  • Accept interfaces in constructors, not implementations.
  • Use @Component, @Service, @Repository for Spring-managed beans.
  • Keep the number of constructor dependencies under 5. Split if more.

Concurrency

  • Use ExecutorService and CompletableFuture for async operations.
  • Use virtual threads (Java 21+) for I/O-bound concurrent work.
  • Use ConcurrentHashMap, AtomicInteger for thread-safe operations.
  • Avoid synchronized blocks when possible -- use higher-level concurrency.
  • Use ReentrantReadWriteLock for read-heavy shared state.

Design Patterns

  • Use Strategy pattern (via interfaces) over switch/if-else chains.
  • Use Factory methods for flexible object creation.
  • Use Decorator pattern for composable behavior augmentation.
  • Avoid Singleton pattern -- use DI container for lifecycle management.
Show full SKILL.md (600 more words)Show less

Anti-Patterns

  • Returning null from methods -- use Optional or empty collections.
  • Mutable DTOs with getters/setters -- use records.
  • God classes with 20+ dependencies -- split by responsibility.
  • String typing for domain values -- use types, enums, or value objects.

Java Security

Input Validation

  • Validate all input with Jakarta Bean Validation (@NotNull, @Size, @Email).
  • Use @Valid on controller parameters to trigger validation automatically.
  • Create custom validators for domain-specific rules.
  • Never trust client-provided IDs. Verify resource ownership server-side.

SQL Injection

  • Use JPA/Hibernate parameterized queries. Never concatenate input into JPQL/SQL.
  • Use CriteriaBuilder or Specifications for dynamic queries.
  • For native queries, use named parameters: @Query(value = "... WHERE id = :id", nativeQuery = true).
  • Use PreparedStatement if using JDBC directly. Never Statement with concatenation.

Authentication

  • Use Spring Security with BCrypt (BCryptPasswordEncoder) for password hashing.
  • Use JWT with short expiration (15 min) + refresh tokens for APIs.
  • Implement account lockout after N failed attempts.
  • Use @AuthenticationPrincipal to access the current user in controllers.

Authorization

  • Use @PreAuthorize("hasRole('ADMIN')") for role-based access control.
  • Use method security for fine-grained authorization.
  • Check resource ownership in service layer, not just role membership.
  • Default deny: require explicit authorization for every endpoint.

XSS and CSRF

  • Spring auto-escapes Thymeleaf output. Do not use th:utext with user data.
  • Enable CSRF protection for session-based auth. Disable only for stateless JWT APIs.
  • Set Content-Type headers explicitly on responses.
  • Use CSP headers to restrict script sources.

Serialization

  • Do not deserialize untrusted data with ObjectInputStream (RCE risk).
  • Use Jackson with @JsonIgnoreProperties(ignoreUnknown = true).
  • Disable default typing in Jackson: never use enableDefaultTyping().
  • Validate deserialized objects with Bean Validation after parsing.

Dependencies

  • Run OWASP Dependency-Check in CI: mvn verify -P owasp-check.
  • Update Spring Boot regularly -- security patches are frequent.
  • Use dependencyManagement to control transitive dependency versions.
  • Audit mvn dependency:tree for unexpected transitive dependencies.

Secrets

  • Use Spring Cloud Config or Vault for secrets management.
  • Use @Value("${secret}") with env var placeholders, not hardcoded values.
  • Never log request headers containing Authorization or session tokens.
  • Use separate config profiles for dev/staging/prod with different secrets.

Logging Security

  • Use parameterized logging to prevent log injection.
  • Sanitize user input before logging: remove newlines and control characters.
  • Never log stack traces to API responses. Return generic error messages.

Java Testing

Framework

  • Use JUnit 5 (Jupiter) for all new tests. No JUnit 4.
  • Use AssertJ for fluent, readable assertions.
  • Use Mockito for mocking dependencies.
  • Use Testcontainers for integration tests with databases/services.

File Naming

  • Test classes: FooTest.java in src/test/java/ mirroring source package.
  • Integration tests: FooIT.java or use @Tag("integration").
  • Test utilities: src/test/java/.../support/ or TestUtils.java.

Structure

  • Use @Nested classes to group related tests within a test class.
  • Use @DisplayName for human-readable test descriptions.
  • Use @BeforeEach for setup, @AfterEach for cleanup.
  • Use @ParameterizedTest with @ValueSource, @CsvSource, @MethodSource.

Assertions (AssertJ)

  • Use assertThat(actual).isEqualTo(expected) over JUnit assertions.
  • Use assertThatThrownBy(() -> ...).isInstanceOf(FooException.class).
  • Use assertThat(list).hasSize(3).extracting("name").contains("Ada").
  • Chain assertions for readable, self-documenting tests.

Mocking (Mockito)

  • Use @Mock + @ExtendWith(MockitoExtension.class) for injection.
  • Use when().thenReturn() for stubbing. verify() for interaction checking.
  • Use @InjectMocks to auto-inject mocks into the class under test.
  • Prefer constructor injection in production code for testability.
  • Use ArgumentCaptor to inspect complex arguments.

Integration Testing

  • Use Testcontainers for PostgreSQL, Redis, Kafka, etc.
  • Use @SpringBootTest sparingly -- it starts the full context. Prefer slices.
  • Use @WebMvcTest for controller tests, @DataJpaTest for repository tests.
  • Use @TestConfiguration for test-specific bean overrides.

Test Data

  • Use test builders or factory methods for creating test objects.
  • Use @Sql annotation to load test data from SQL files.
  • Keep test data minimal. Only set fields relevant to the behavior under test.
  • Use random UUIDs for IDs in tests to avoid collision.

Performance

  • Run tests in parallel: configure junit.jupiter.execution.parallel.enabled=true.
  • Use @SpringBootTest only when integration context is needed.
  • Mock external dependencies in unit tests for speed.
  • Keep the full test suite under 5 minutes.

© softspark, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in app/skills/java-rules of softspark/ai-toolkit.

Open the folder on GitHubat commit d64db2b

Compare with similar skills

Java Rules next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Java Rules compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Java Rules this skillsoftspark/ai-toolkit179—~3.1kAutomated safety check: PassApache-2.0
Java ArchitectJeffallan/claude-skills12k—~1.5kAutomated safety check: PassMIT
Groovy 5 Developer Guideapache/grails-core2.9k—~3kAutomated safety check: PassApache-2.0
Dotnet Backend Patternswshobson/agents40k7 repos~6.6kAutomated safety check: PassMIT
Spring Bootpiomin/claude-ai-spring-boot1.3k—~2kAutomated safety check: PassApache-2.0
Grails Developer Guideapache/grails-core2.9k—~4.9kAutomated safety check: PassApache-2.0

Similar skills

  • Java Architect

    Jeffallan/claude-skills

    Builds Spring Boot 3.x services on Java 21 with domain-driven design, WebFlux, JPA tuning and Spring Security using OAuth2 and JWT, verified by Maven or Gradle builds.

    12k GitHub stars~1.5k tokensUpdated 4 days ago
    Backend & APIsAuto-check passed
  • Groovy 5 Developer Guide

    apache/grails-core

    Guidance for Groovy 5 work in Grails projects: syntax, closures, traits, DSLs, metaprogramming, Spock tests, static compilation and Java 21 integration.

    2.9k GitHub stars~3k tokensUpdated today
    DevelopmentAuto-check passed
  • Master C/.NET backend development patterns for building robust APIs, MCP servers, and enterprise applications.

    40k GitHub starsUsed in 7 repos~6.6k tokens
    Backend & APIsAuto-check passed
  • Spring Boot

    piomin/claude-ai-spring-boot

    Spring Boot 3.x development - REST APIs, JPA, Security, Testing, and Cloud-native patterns.

    1.3k GitHub stars~2k tokensUpdated 5 mo ago
    Backend & APIsAuto-check passed
  • Grails Developer Guide

    apache/grails-core

    Guides building Grails web applications and REST APIs with GORM, controllers, services, views, plugins and Spock and Geb testing.

    2.9k GitHub stars~4.9k tokensUpdated today
    Backend & APIsAuto-check passed
  • Mastering Python Skill

    SpillwaveSolutions/agent-brain

    Modern Python coaching covering language foundations through advanced production patterns.

    120 GitHub stars~1.4k tokensUpdated 18 days ago
    DevelopmentAuto-check: notes

More from softspark/ai-toolkit

All 112 skills in this repo
  • Prepare Test Env

    softspark/ai-toolkit

    Prepare or verify a project QA environment with source identity, readiness, browser access, evidence paths and owned cleanup.

    179 GitHub stars~1.8k tokensUpdated today
    Auto-check: notes
  • A11y Validate

    softspark/ai-toolkit

    Accessibility validator: WCAG 2.1 AA, EN 301 549, EAA. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~3.8k tokensUpdated today
    Auto-check: notes
  • Analyze

    softspark/ai-toolkit

    Analyzes code quality, complexity, patterns across codebase.

    179 GitHub stars~1k tokensUpdated today
    Auto-check passed
  • Autonomous Dev

    softspark/ai-toolkit

    Drives a brief, specification, issue or existing PR through implementation, review, tests and QA to a ready PR.

    179 GitHub stars~2.6k tokensUpdated today
    Auto-check: notes
  • Brand Voice

    softspark/ai-toolkit

    Direct technical voice for docs, README, user-facing text. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~2.1k tokensUpdated today
    Auto-check passed
  • CI

    softspark/ai-toolkit

    Detect/generate/debug CI pipeline config (GitHub Actions, GitLab CI).

    179 GitHub stars~1.1k tokensUpdated today
    Auto-check: notes

Questions about Java Rules

What does Java Rules do?

Java coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit. Java Rules is an agent skill from softspark/ai-toolkit. Java coding rules: style, patterns, security, testing.

When should I use Java Rules?

Java Rules fits situations like: tasks that involve Backend development; tasks that involve ORMs and data access; tasks that involve Unit testing.

How do I install Java Rules in Claude Code?

Run `npx skills add softspark/ai-toolkit --skill java-rules -a claude-code`. Or copy the skill folder (app/skills/java-rules in softspark/ai-toolkit) into .claude/skills/java-rules in your project. Claude Code loads it when a task matches its description.

How do I install Java Rules in Codex?

Run `npx skills add softspark/ai-toolkit --skill java-rules -a codex`. Or copy the skill folder (app/skills/java-rules in softspark/ai-toolkit) into .agents/skills/java-rules in your project. Codex loads it when a task matches its description.

Can I use Java Rules in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add softspark/ai-toolkit --skill java-rules -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/java-rules, .gemini/skills/java-rules, .github/skills/java-rules and .opencode/skills/java-rules in your project.

What does Java Rules need to run?

Going by SKILL.md and its folder, Java Rules needs the command-line tools its instructions call (mvn). Its frontmatter pre-approves these tools: Read.

Does Java Rules access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Java Rules safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Java Rules use?

Java Rules is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Java Rules use?

About 3.1k tokens (SKILL.md is roughly 13k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Java Rules?

Skills that share tags, products or a category with Java Rules: Java Architect (Jeffallan/claude-skills, 12k stars), Groovy 5 Developer Guide (apache/grails-core, 2.9k stars), Dotnet Backend Patterns (wshobson/agents, 40k stars) and Spring Boot (piomin/claude-ai-spring-boot, 1.3k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Java Rules?

softspark (a GitHub user) maintains it in softspark/ai-toolkit, which has 179 GitHub stars. The repository holds 112 skills in this directory. The repository was last updated on October 7, 2026.

Source: softspark/ai-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.