spring-security-auth-review
Installation
SKILL.md
Spring Security Auth Review
When to use
Invoke before shipping any Spring Boot service that handles authenticated requests, or whenever Spring Security, JWT/OAuth2, sessions, refresh tokens, CORS, CSRF, actuator exposure, or service-to-service auth changes materially.
Do not use for general application security review, non-Spring services, frontend-only auth UX, cryptographic protocol design, or domain authorization policy design above the framework layer.
Inputs
Required:
- Spring Boot service source tree.
- Spring Security configuration, including
SecurityFilterChainorSecurityWebFilterChain. - Auth model: JWT, OAuth2 resource server, session, BFF, refresh token, or service-to-service.
Optional: