Skip to content
Back to skills

Spring Boot Best Practices

ASecurity

Use a small set of enforceable production defaults: - Prefer constructor injection, with final dependencies; Lombok `@RequiredArgsConstructor` is fine. Avoid field `@Autowired` injection. - Bind configuration with validated `@ConfigurationProperties` records, use `application.yaml` and profile files such as `application-dev.yml`/`application-prod.yml`, and select profiles with `SPRING_PROFILES_ACTIVE`. Never hardcode secrets. - Use immutable record DTOs and validate inputs with Jakarta Bean V...

  • 549 stars
  • 0 votes
  • 1 copy
  • 2 views
  • Added September 5, 2026
developmentspringdatabase

Security analysis

A100/100

Pro scans all 11 files and shows the line behind each finding

Scanned September 5, 2026

npx -y skills add HoangNguyen0403/agent-skills-standard --skill spring-boot-best-practices --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Spring Boot Best Practices?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Spring Boot Best Practices
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/hoangnguyen0403-spring-boot-best-practices-agent-skills-standard/badge)](https://www.skillsdirectory.com/skills/hoangnguyen0403-spring-boot-best-practices-agent-skills-standard)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
Use a small set of enforceable production defaults:

- Prefer constructor injection, with final dependencies; Lombok `@RequiredArgsConstructor` is fine. Avoid field `@Autowired` injection.
- Bind configuration with validated `@ConfigurationProperties` records, use `application.yaml` and profile files such as `application-dev.yml`/`application-prod.yml`, and select profiles with `SPRING_PROFILES_ACTIVE`. Never hardcode secrets.
- Use immutable record DTOs and validate inputs with Jakarta Bean Validation.
- Centralize errors with `@ControllerAdvice` and RFC 7807 `ProblemDetail`; never expose stack traces.
- Log through SLF4J (for example `@Slf4j`) with structured arguments, not `System.out` or log-and-swallow handling.
- Add Spotless or Checkstyle and manage JDK 21+ consistently, for example with SDKMAN.

For database-backed services, keep transaction boundaries in services and use read-only transactions for read paths where appropriate. Add health, metrics, and secure operational endpoints as deployment requirements. Make the rules testable in CI: fail on formatting violations, validate configuration at startup, scan dependencies for CVEs, and exercise error and profile-specific paths. The important principle is explicit dependencies, typed configuration, safe failures, and observable behavior rather than a long list of annotations.


Files in this skill

  • eval-1.baseline.md857 B
  • eval-1.with-skill.md1.3 KB
  • eval-2.baseline.md711 B
  • eval-2.with-skill.md1 KB
  • eval-3.baseline.md750 B
  • eval-3.with-skill.md1.1 KB
  • trigger-1.md132 B
  • trigger-2.md125 B
  • trigger-3.md145 B
  • trigger-4.md138 B

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…