Agent skill

Springboot Verification

by xu-xiang in xu-xiang/everything-claude-code-zh

Spring Boot 项目验证循环:包含构建、静态分析、带覆盖率的测试、安全扫描,以及发布或 PR 前的差异审查. An agent skill from xu-xiang/everything-claude-code-zh.

MITAuto-check passedBackend & APIs

Install Springboot Verification

skills CLI
$ npx skills add xu-xiang/everything-claude-code-zh --skill springboot-verification -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install xu-xiang/everything-claude-code-zh springboot-verification --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/xu-xiang/everything-claude-code-zh.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/springboot-verification .claude/skills/springboot-verification && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
springboot-verification
GitHub stars
2k
Token cost
~1.3k tokens
SKILL.md length
117 words
Files
1
Skills in repo
78
Repo updated
First seen
Licence
MIT

At a glance

Spring Boot 项目验证循环:包含构建、静态分析、带覆盖率的测试、安全扫描,以及发布或 PR 前的差异审查. An agent skill from xu-xiang/everything-claude-code-zh.

  • Tasks that involve Backend development
  • SKILL.md covers 触发时机, 第一阶段:构建 (Build), 第二阶段:静态分析 (Static Analysis) and 第三阶段:测试与覆盖率 (Tests + Coverage), plus 5 more sections
  • Calls mvn and git
  • Tasks that involve Integration testing

What it does

Springboot Verification is an agent skill from xu-xiang/everything-claude-code-zh. Spring Boot 项目验证循环:包含构建、静态分析、带覆盖率的测试、安全扫描,以及发布或 PR 前的差异审查。

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Backend development and Integration testing. It works with Spring Boot. The repository describes itself as: everything-claude-code 中文翻译项目:完整的 Claude Code 配置集合(agents, skills, hooks, commands, rules, MCPs)。源自 Anthropic 黑客松获胜者的实战配置,助力中文工程师高效理解与使用 Claude Code。 The licence is MIT.

When your agent uses it

  • Tasks that involve Backend development
  • Tasks that involve Integration testing

Example prompts

  • “/springboot-verification”

What it can do on your machine

Read from SKILL.md and the folder at commit dfbf946. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • mvn
    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Springboot Verification loads about 1.3k tokens when it runs. Until then it costs about 21 tokens; SKILL.md has 117 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~21
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from xu-xiang/everything-claude-code-zh at commit dfbf946, republished under its MIT licence (© xu-xiang). 117 words, ~1,317 tokens.

Download SKILL.mdSave it as .claude/skills/springboot-verification/SKILL.md (or your agent's skills folder).
name
springboot-verification
description
Spring Boot 项目验证循环:包含构建、静态分析、带覆盖率的测试、安全扫描,以及发布或 PR 前的差异审查。
origin
ECC

Spring Boot 验证循环 (Verification Loop)

在合并请求 (PR) 之前、重大变更之后以及部署前运行。

触发时机

  • 在为 Spring Boot 服务开启合并请求 (Pull Request) 之前
  • 在重大重构 (Refactoring) 或依赖 (Dependency) 升级之后
  • 预发布或生产环境部署 (Deployment) 前的验证
  • 运行完整的 构建 (Build) → 代码检查 (Lint) → 测试 (Test) → 安全扫描 (Security Scan) 流水线 (Pipeline)
  • 验证测试覆盖率 (Test Coverage) 是否达到阈值

第一阶段:构建 (Build)

bash
mvn -T 4 clean verify -DskipTests
# 或者
./gradlew clean assemble -x test

如果构建失败,请停止并修复。

第二阶段:静态分析 (Static Analysis)

Maven(常用插件):

bash
mvn -T 4 spotbugs:check pmd:check checkstyle:check

Gradle(如果已配置):

bash
./gradlew checkstyleMain pmdMain spotbugsMain

第三阶段:测试与覆盖率 (Tests + Coverage)

bash
mvn -T 4 test
mvn jacoco:report   # 验证 80% 以上的覆盖率
# 或者
./gradlew test jacocoTestReport

报告内容:

  • 测试总数、通过/失败数
  • 覆盖率 %(行/分支)
单元测试 (Unit Tests)

通过模拟依赖 (Mocked dependencies) 隔离测试服务逻辑:

java
@ExtendWith(MockitoExtension.class)
class UserServiceTest {

  @Mock private UserRepository userRepository;
  @InjectMocks private UserService userService;

  @Test
  void createUser_validInput_returnsUser() {
    var dto = new CreateUserDto("Alice", "alice@example.com");
    var expected = new User(1L, "Alice", "alice@example.com");
    when(userRepository.save(any(User.class))).thenReturn(expected);

    var result = userService.create(dto);

    assertThat(result.name()).isEqualTo("Alice");
    verify(userRepository).save(any(User.class));
  }

  @Test
  void createUser_duplicateEmail_throwsException() {
    var dto = new CreateUserDto("Alice", "existing@example.com");
    when(userRepository.existsByEmail(dto.email())).thenReturn(true);

    assertThatThrownBy(() -> userService.create(dto))
        .isInstanceOf(DuplicateEmailException.class);
  }
}
使用 Testcontainers 进行集成测试 (Integration Tests)

针对真实数据库而非 H2 进行测试:

java
@SpringBootTest
@Testcontainers
class UserRepositoryIntegrationTest {

  @Container
  static PostgreSQLContainer<?> postgres = new PostgreSQLContainer<>("postgres:16-alpine")
      .withDatabaseName("testdb");

  @DynamicPropertySource
  static void configureProperties(DynamicPropertyRegistry registry) {
    registry.add("spring.datasource.url", postgres::getJdbcUrl);
    registry.add("spring.datasource.username", postgres::getUsername);
    registry.add("spring.datasource.password", postgres::getPassword);
  }

  @Autowired private UserRepository userRepository;

  @Test
  void findByEmail_existingUser_returnsUser() {
    userRepository.save(new User("Alice", "alice@example.com"));

    var found = userRepository.findByEmail("alice@example.com");

    assertThat(found).isPresent();
    assertThat(found.get().getName()).isEqualTo("Alice");
  }
}
使用 MockMvc 进行 API 测试 (API Tests)

在完整的 Spring 上下文中测试控制层 (Controller layer):

java
@WebMvcTest(UserController.class)
class UserControllerTest {

  @Autowired private MockMvc mockMvc;
  @MockBean private UserService userService;

  @Test
  void createUser_validInput_returns201() throws Exception {
    var user = new UserDto(1L, "Alice", "alice@example.com");
    when(userService.create(any())).thenReturn(user);

    mockMvc.perform(post("/api/users")
            .contentType(MediaType.APPLICATION_JSON)
            .content("""
                {"name": "Alice", "email": "alice@example.com"}
                """))
        .andExpect(status().isCreated())
        .andExpect(jsonPath("$.name").value("Alice"));
  }

  @Test
  void createUser_invalidEmail_returns400() throws Exception {
    mockMvc.perform(post("/api/users")
            .contentType(MediaType.APPLICATION_JSON)
            .content("""
                {"name": "Alice", "email": "not-an-email"}
                """))
        .andExpect(status().isBadRequest());
  }
}

第四阶段:安全扫描 (Security Scan)

bash
# 依赖项 CVE 漏洞扫描
mvn org.owasp:dependency-check-maven:check
# 或者
./gradlew dependencyCheckAnalyze

# 源码中的密钥/敏感信息 (Secrets)
grep -rn "password\s*=\s*\"" src/ --include="*.java" --include="*.yml" --include="*.properties"
grep -rn "sk-\|api_key\|secret" src/ --include="*.java" --include="*.yml"

# 密钥/敏感信息 (Git 历史记录)
git secrets --scan  # 如果已配置
常见安全问题检查
# 检查 System.out.println (应使用 logger 代替)
grep -rn "System\.out\.print" src/main/ --include="*.java"

# 检查响应中是否包含原始异常信息
grep -rn "e\.getMessage()" src/main/ --include="*.java"

# 检查通配符 CORS 配置
grep -rn "allowedOrigins.*\*" src/main/ --include="*.java"

第五阶段:代码检查/格式化 (Lint/Format)(可选关卡)

bash
mvn spotless:apply   # 如果使用了 Spotless 插件
./gradlew spotlessApply

第六阶段:差异审查 (Diff Review)

bash
git diff --stat
git diff

检查清单:

  • 未遗留调试日志(System.out,无守卫的 log.debug)
  • 错误信息和 HTTP 状态码具有明确意义
  • 在需要的地方包含事务 (Transactions) 和校验 (Validation)
  • 配置变更已记录文档

输出模板

验证报告 (VERIFICATION REPORT)
===================
构建 (Build):     [通过/失败]
静态分析 (Static): [通过/失败] (spotbugs/pmd/checkstyle)
测试 (Tests):     [通过/失败] (X/Y 通过, Z% 覆盖率)
安全 (Security):  [通过/失败] (CVE 漏洞发现: N)
差异 (Diff):      [X 个文件已变更]

总体状态 (Overall): [准备就绪 / 尚未就绪]

待修复问题:
1. ...
2. ...

持续模式 (Continuous Mode)

  • 在发生重大变更时,或在长会话期间每 30–60 分钟重新运行各阶段。
  • 保持短循环:运行 mvn -T 4 test + spotbugs 以获取快速反馈。

请记住:快速反馈优于后期“惊喜”。保持关卡严格——在生产系统中,将警告视为缺陷。

© xu-xiang, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in skills/springboot-verification of xu-xiang/everything-claude-code-zh.

Open the folder on GitHubat commit dfbf946

Compare with similar skills

Springboot Verification next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Springboot Verification compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Springboot Verification this skillxu-xiang/everything-claude-code-zh2k—~1.3kAutomated safety check: PassMIT
323 Frameworks Spring Boot Testing Acceptance Testsjabrena/plinth447—~1.2kAutomated safety check: PassApache-2.0
Spring Boot Test Patternsgiuseppe-trisciuoglio/developer-kit356—~2.3kAutomated safety check: NotesMIT
Spring Boot TestingHoangNguyen0403/agent-skills-standard571—~819Automated safety check: PassMIT
Springboot Verificationaffaan-m/ECC276k5 repos~1.5kAutomated safety check: PassMIT
Springboot TDDaffaan-m/ECC276k3 repos~813Automated safety check: PassMIT

Similar skills

  • A skill your agent uses when you need to implement acceptance tests from maintainer-authored or maintainer-sanitized Gherkin scenario facts for Spring Boot applications — including selecting…

    447 GitHub stars~1.2k tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Spring Boot Test Patterns

    giuseppe-trisciuoglio/developer-kit

    Provides comprehensive testing patterns for Spring Boot applications covering unit, integration, slice, and container-based testing with JUnit 5, Mockito, Testcontainers, and performance optimization.

    356 GitHub stars~2.3k tokensUpdated 28 days ago
    Backend & APIsAuto-check: notes
  • Spring Boot Testing

    HoangNguyen0403/agent-skills-standard

    Write unit, integration, and slice tests for Spring Boot 3 applications.

    571 GitHub stars~819 tokensUpdated today
    Backend & APIsAuto-check passed
  • Run the full Spring Boot verification loop — Maven or Gradle build, SpotBugs, PMD, and Checkstyle static analysis, unit and Testcontainers integration tests with JaCoCo coverage, OWASP dependency…

    276k GitHub starsUsed in 5 repos~1.5k tokens
    Testing & QAAuto-check passed
  • Springboot TDD

    affaan-m/ECC

    使用JUnit 5、Mockito、MockMvc、Testcontainers和JaCoCo进行Spring Boot的测试驱动开发。适用于添加功能、修复错误或重构时。

    276k GitHub starsUsed in 3 repos~813 tokens
    Testing & QAAuto-check passed
  • Springboot TDD

    affaan-m/ECC

    Desarrollo guiado por pruebas para Spring Boot usando JUnit 5, Mockito, MockMvc, Testcontainers y JaCoCo.

    276k GitHub stars~996 tokensUpdated 4 days ago
    Testing & QAAuto-check passed

More from xu-xiang/everything-claude-code-zh

All 78 skills in this repo
  • Configure Ecc

    xu-xiang/everything-claude-code-zh

    Everything Claude Code 的交互式安装程序 — 引导用户选择并安装技能和规则到用户级或项目级目录,验证路径,并可选择优化已安装文件。

    2k GitHub starsUsed in 1 repo~2.1k tokens
    Auto-check passed
  • Continuous Learning V2

    xu-xiang/everything-claude-code-zh

    基于本能(Instinct)的学习系统,通过钩子(hooks)观察会话,创建带有置信度评分的原子本能,并将其演化为技能(Skills)、命令(Commands)或智能体(Agents)。v2.1 版本增加了项目作用域(project-scoped)的本能,以防止跨项目污染。

    2k GitHub stars~2.1k tokensUpdated 7 mo ago
    Auto-check passed
  • API Design

    xu-xiang/everything-claude-code-zh

    生产级 API 的 REST API 设计模式,包括资源命名、状态码、分页、过滤、错误响应、版本控制和速率限制. An agent skill from xu-xiang/everything-claude-code-zh.

    2k GitHub stars~2.7k tokensUpdated 7 mo ago
    Auto-check passed
  • Backend Patterns

    xu-xiang/everything-claude-code-zh

    后端架构模式、API 设计、数据库优化以及适用于 Node.js、Express 和 Next.js API 路由的服务端最佳实践。

    2k GitHub stars~3.2k tokensUpdated 7 mo ago
    Auto-check passed
  • Backend Patterns

    xu-xiang/everything-claude-code-zh

    后端架构模式、API 设计、数据库优化以及 Node.js、Express 和 Next.js API 路由的服务端最佳实践。

    2k GitHub stars~3.1k tokensUpdated 7 mo ago
    Auto-check passed
  • Backend Patterns

    xu-xiang/everything-claude-code-zh

    后端架构模式、API 设计、数据库优化以及针对 Node.js、Express 和 Next.js API 路由的服务端最佳实践。

    2k GitHub stars~3.2k tokensUpdated 7 mo ago
    Auto-check passed

Works with

Questions about Springboot Verification

What does Springboot Verification do?

Spring Boot 项目验证循环:包含构建、静态分析、带覆盖率的测试、安全扫描,以及发布或 PR 前的差异审查. An agent skill from xu-xiang/everything-claude-code-zh. Springboot Verification is an agent skill from xu-xiang/everything-claude-code-zh.

When should I use Springboot Verification?

Springboot Verification fits situations like: tasks that involve Backend development; tasks that involve Integration testing.

How do I install Springboot Verification in Claude Code?

Run `npx skills add xu-xiang/everything-claude-code-zh --skill springboot-verification -a claude-code`. Or copy the skill folder (skills/springboot-verification in xu-xiang/everything-claude-code-zh) into .claude/skills/springboot-verification in your project. Claude Code loads it when a task matches its description.

How do I install Springboot Verification in Codex?

Run `npx skills add xu-xiang/everything-claude-code-zh --skill springboot-verification -a codex`. Or copy the skill folder (skills/springboot-verification in xu-xiang/everything-claude-code-zh) into .agents/skills/springboot-verification in your project. Codex loads it when a task matches its description.

Can I use Springboot Verification in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add xu-xiang/everything-claude-code-zh --skill springboot-verification -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/springboot-verification, .gemini/skills/springboot-verification, .github/skills/springboot-verification and .opencode/skills/springboot-verification in your project.

What does Springboot Verification need to run?

Going by SKILL.md and its folder, Springboot Verification needs the command-line tools its instructions call (mvn and git).

Does Springboot Verification access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Springboot Verification safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Springboot Verification use?

Springboot Verification is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Springboot Verification use?

About 1.3k tokens (SKILL.md is roughly 5.3k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Springboot Verification?

Skills that share tags, products or a category with Springboot Verification: 323 Frameworks Spring Boot Testing Acceptance Tests (jabrena/plinth, 447 stars), Spring Boot Test Patterns (giuseppe-trisciuoglio/developer-kit, 356 stars), Spring Boot Testing (HoangNguyen0403/agent-skills-standard, 571 stars) and Springboot Verification (affaan-m/ECC, 276k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Springboot Verification?

xu-xiang (a GitHub user) maintains it in xu-xiang/everything-claude-code-zh, which has 1,976 GitHub stars. The repository holds 78 skills in this directory. The repository was last updated on March 5, 2026.

Source: xu-xiang/everything-claude-code-zh on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.