java-core — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited java-core (Plugin) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
A Claude Code plugin marketplace with 3 focused plugins for Java developers. All plugins support Java 8 through Java 21 and tailor advice to your target Java version.
| Plugin | Skills | Commands | Agents | Install when |
|---|---|---|---|---|
java-core | 14 | 2 | java-architect, java-build-resolver | Every Java project |
java-spring | 9 | 2 | java-spring-expert | Spring Boot projects |
java-quality | 3 | 1 | java-security-reviewer, java-performance-reviewer, java-test-engineer | Quality enforcement |
templates/CLAUDE.md.template to your Java project root as CLAUDE.md and fill in the placeholderstemplates/settings.json.template to .claude/settings.local.json to pre-approve build/test commands/plugin marketplace add ducpm2303/claude-java-plugins/plugin install java-core@java-plugins # every Java project
/plugin install java-spring@java-plugins # Spring Boot projects
/plugin install java-quality@java-plugins # security + performance + testing/plugin marketplace update java-pluginsSkills activate automatically based on context, or invoke them explicitly.
| Skill | What it does |
|---|---|
/java-core:java-review | Review Java code for bugs, naming issues, and version-appropriate idioms |
/java-core:java-refactor | Suggest and apply version-gated refactorings |
/java-core:java-explain | Explain Java code in plain language |
/java-core:java-fix | Diagnose compile errors or stack traces |
/java-core:java-docs | Generate Javadoc for classes and methods |
/java-core:java-health | Structural health score across Security, Tests, Performance, Quality (A–F) |
/java-core:java-concurrency-review | Review thread safety, race conditions, and Java 21 virtual thread compatibility |
/java-core:java-api-review | Review REST API design — HTTP methods, status codes, naming, versioning |
/java-core:java-migrate | Interactive migration guide: Java 8→11, 11→17, or 17→21 |
/java-core:java-commit | Generate a Conventional Commits message for staged Java changes |
/java-core:java-solid | Check all 5 SOLID principles with Java-specific patterns |
/java-core:java-design-pattern | Detect GoF patterns in code or recommend a pattern for a problem |
/java-core:java-adr | Create, list, and manage Architecture Decision Records |
/java-core:java-clean-arch | Review for Clean/Hexagonal Architecture violations or scaffold a full hexagonal layout with DDD patterns |
| Skill | What it does |
|---|---|
/java-spring:java-scaffold | Scaffold a brand-new Spring Boot project (2.7.x – 4.0.x) |
/java-spring:java-jpa | Deep JPA review — N+1 queries, fetch strategies, projections, Specifications |
/java-spring:java-logging | Review logging — SLF4J, MDC, structured logging, PII safety |
/java-spring:java-crud | Generate a complete CRUD feature in an existing project |
/java-spring:java-security | Review or generate Spring Security config — JWT, OAuth2, method security, CORS (Boot 2.x & 3.x) |
/java-spring:java-openapi | Generate or review OpenAPI/Swagger docs — @Tag, @Operation, @Schema, JWT auth scheme (springdoc v1/v2) |
/java-spring:java-spring-ai | Add AI features to Spring Boot — ChatClient, RAG, tool calling, memory (Spring AI 1.x / LangChain4J) |
/java-spring:java-resilience | Add Resilience4J patterns — circuit breaker, retry, rate limiter, bulkhead, timeout (Boot 2.x & 3.x) |
/java-spring:java-cache | Add or review Spring Cache — Caffeine (single-instance) or Redis (distributed), @Cacheable/@CacheEvict/@CachePut |
| Skill | What it does |
|---|---|
/java-quality:java-security-check | Quick OWASP scan — secrets, injection, weak crypto, Spring Security misconfigs |
/java-quality:java-perf-check | Quick performance scan — N+1, memory, threading, algorithmic hotspots |
/java-quality:java-test | Generate JUnit 5 + Mockito unit or Testcontainers integration tests |
Commands are explicitly triggered workflows — builds, analysis runs, and reports.
| Command | What it does |
|---|---|
/java-core:build | Run a clean Maven/Gradle build and report test results or compile errors |
/java-core:check | Run configured static analysis (Checkstyle, SpotBugs, PMD) and report findings |
| Command | What it does |
|---|---|
/java-spring:run | Start the Spring Boot app locally with pre-flight checks (env vars, DB) |
/java-spring:routes | Print a REST endpoint table scanned from all @RestController classes |
| Command | What it does |
|---|---|
/java-quality:audit | Full quality audit: security + performance + test coverage in one combined report |
Agents are specialist sub-agents Claude can delegate to:
| Agent | Plugin | Use for |
|---|---|---|
java-architect | java-core | Project structure, hexagonal/layered architecture, multi-module Maven, design patterns |
java-build-resolver | java-core | Fix Maven/Gradle/javac build errors with minimal changes |
java-spring-expert | java-spring | Spring Boot best practices, Spring Data JPA, Spring Security, REST API design |
java-security-reviewer | java-quality | Full OWASP Top 10 deep-dive, Spring Security misconfig, secrets audit |
java-performance-reviewer | java-quality | Deep JPA/memory/threading performance analysis with before/after fixes |
java-test-engineer | java-quality | Test strategy, coverage analysis, Testcontainers setup, PITest mutation testing |
Example usage:
Each plugin includes path-scoped rules that activate automatically when you open matching files — no manual invocation needed.
| Rule file | Activates for | Enforces |
|---|---|---|
java-core naming-conventions | **/*.java | Class/method/variable/package naming |
java-core project-structure | **/pom.xml, **/build.gradle* | Dependency scopes, version pinning, Java toolchain |
java-spring controller-conventions | **/*Controller.java | ResponseEntity returns, @Valid, HTTP status codes |
java-spring service-conventions | **/*Service.java | Constructor injection, @Transactional(readOnly), DTO mapping |
java-spring entity-conventions | **/*Entity.java, **/entity/*.java | Fetch types, auditing timestamps, soft delete, equality |
java-quality security-rules | **/*.java | No secrets in logs, no SQL concat, input validation |
java-quality test-conventions | **/*Test.java, **/*IT.java | AAA pattern, AssertJ, Testcontainers, naming |
java-core includes a .lsp.json configuring Eclipse JDT Language Server (jdtls) for real-time code intelligence:
Install jdtls:
brew install jdtls # macOS
# or download from https://github.com/eclipse-jdtls/eclipse.jdt.ls/releasesUse the same skills that run locally to automatically review every Java PR in CI.
templates/java-pr-review.yml to .github/workflows/java-pr-review.yml in your Java projectANTHROPIC_API_KEY to your repo secrets (Settings → Secrets → Actions).java or build files gets an automated reviewEvery PR automatically checks:
@ValidResults are posted as a single structured comment with severity-coded findings.
This repo runs .github/workflows/validate.yml on every push — it runs validate-plugins.sh and verifies version consistency across all plugin manifests.
See CONTRIBUTING.md for a full authoring guide covering skills, rules, commands, and agents.
Quick steps:
./scripts/validate-plugins.sh — must pass with zero errors.claude-plugin/marketplace.json~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.