spring-security-configurator-auditor
Installation
SKILL.md
Spring Security Configurator Auditor
Source mapping: Tier 2 high-value skill derived from Kotlin_Spring_Developer_Pipeline.md (SK-13).
Mission
Produce a security model that is explicit, minimal, and testable. Optimize for least privilege and correct failure semantics, not for shortest config.
Read First
- Current
SecurityFilterChainor chains. - Endpoint inventory, including actuator, docs, and internal admin routes.
- Authentication model: session, JWT, OAuth2 resource server, API keys, mTLS, or mixed.
- Authorization model: roles, scopes, claims, method security, tenant boundaries.
- CORS, CSRF, and security-related tests.