spring-boot-engineer

Pass

Audited by Gen Agent Trust Hub on Jun 20, 2026

Risk Level: SAFECOMMAND_EXECUTION
Full Analysis
  • [SAFE]: The skill provides industry-standard development patterns for Spring Boot 3.x and Spring Security 6. It correctly implements security controls such as JWT authentication, password hashing with BCrypt (strength 12), and CORS configuration.
  • [COMMAND_EXECUTION]: The instructions reference standard project-local build tool wrappers (./mvnw test, ./gradlew test) for verifying code functionality. These operations are within the expected scope of a development assistant and use the project's own build scripts.
  • [SAFE]: The skill actively promotes secure credential management by instructing the agent to externalize secrets using environment variables or Spring Cloud Config, specifically forbidding hardcoded secrets in property files.
  • [SAFE]: The MyBatis-Plus reference document includes the BlockAttackInnerInterceptor, which is a security feature designed to prevent accidental or malicious full-table updates and deletes.
Audit Metadata
Risk Level
SAFE
Analyzed
Jun 20, 2026, 07:53 PM
Security Audit — agent-trust-hub — spring-boot-engineer