spring-boot-engineer
Pass
Audited by Gen Agent Trust Hub on Sep 2, 2026
Risk Level: SAFENO_CODECOMMAND_EXECUTION
Full Analysis
- [NO_CODE]: The skill consists entirely of Markdown instructions and Java code templates. It does not include any executable script files or external dependencies that are run by the agent platform itself.
- [COMMAND_EXECUTION]: The core workflow instructs the agent to execute standard Java build tool commands like './mvnw test' or './gradlew test' to verify implementation. These are standard operations for a software development assistant and target the user's local build environment as requested by the task.
- [CREDENTIALS_UNSAFE]: The skill demonstrates high security awareness by explicitly forbidding the hardcoding of secrets or credentials in configuration files and requiring the use of environment variables or secure configuration servers like Spring Cloud Config.
- [INDIRECT_PROMPT_INJECTION]: The skill defines a specialized role for generating code from requirements. While this task involves processing user-provided natural language, the skill incorporates explicit rules for validation and layered architecture, which helps maintain operational boundaries.
Audit Metadata