PluginBench
Skill
Pass
Audit score 90

spring-boot-engineer

jeffallan/claude-skills

Generates Spring Boot 3.x services, REST APIs, Spring Security 6, and reactive WebFlux endpoints for microservices.

What is spring-boot-engineer?

Specialist skill for building Spring Boot 3.x applications with layered architecture, Spring Data JPA, Spring Security 6 authentication, and reactive endpoints. Use when designing microservices, implementing REST APIs, configuring security, or setting up data access patterns in Java.

  • Generate Spring Boot 3.x project structures with layered architecture (entity, repository, service, controller)
  • Create REST controllers with input validation, exception handling, and proper HTTP status codes
  • Implement Spring Security 6 authentication flows, OAuth2, JWT, and method-level security
  • Set up Spring Data JPA repositories with custom queries and transaction management
  • Configure reactive WebFlux endpoints for non-blocking request handling
  • Design microservices with constructor injection and externalized configuration

How to install spring-boot-engineer

npx skills add https://github.com/jeffallan/claude-skills --skill spring-boot-engineer
Prerequisites
  • Java 17 or later
  • Spring Boot 3.x project (Maven or Gradle)
  • Familiarity with Spring Framework concepts (dependency injection, annotations)
Claude Code
Cursor
Windsurf
Cline

How to use spring-boot-engineer

  1. 1.Analyze your service requirements and define entity models, repositories, and API endpoints
  2. 2.Design the architecture including security needs, data access patterns, and cloud integration
  3. 3.Implement layers in order: entities, repositories, services (with constructor injection), controllers
  4. 4.Add Spring Security configuration and validate security rules compile and tests pass
  5. 5.Write unit and integration tests, run test suite and confirm all pass
  6. 6.Configure Actuator health checks and observability, validate `/actuator/health` returns UP

Use cases

Good for
  • Building a microservice with REST endpoints, JPA persistence, and Spring Security authentication
  • Implementing reactive endpoints using Spring WebFlux for high-throughput APIs
  • Setting up Spring Data repositories with custom query methods and transaction boundaries
  • Configuring OAuth2 or JWT-based security for API access control
  • Creating global exception handlers and validation for consistent API error responses
Who it's for
  • Backend engineers building Spring Boot microservices
  • Java developers implementing REST APIs with Spring Framework
  • Teams adopting Spring Security 6 and reactive patterns
  • Architects designing layered Spring Boot applications

spring-boot-engineer FAQ

Should I use field injection or constructor injection?

Always use constructor injection. Avoid @Autowired on fields. Constructor injection makes dependencies explicit, improves testability, and prevents NullPointerException.

How do I handle validation errors in REST APIs?

Use @Valid on @RequestBody parameters and create a @RestControllerAdvice with @ExceptionHandler for MethodArgumentNotValidException. Return structured error responses, never stack traces.

What is the difference between @Transactional and @Transactional(readOnly=true)?

Use @Transactional for write operations (create, update, delete) to manage commits and rollbacks. Use @Transactional(readOnly=true) for queries to optimize database behavior and signal intent.

Can I mix blocking and reactive code in WebFlux?

No. Do not call .block() inside WebFlux chains. Keep reactive code fully non-blocking or use traditional Spring MVC for blocking operations.

Where should I store secrets and credentials?

Never store secrets in application.properties or application.yml. Use environment variables or Spring Cloud Config Server for externalized, secure configuration.

Full instructions (SKILL.md)

Source of truth, from jeffallan/claude-skills.


name: spring-boot-engineer description: Generates Spring Boot 3.x configurations, creates REST controllers, implements Spring Security 6 authentication flows, sets up Spring Data JPA repositories, and configures reactive WebFlux endpoints. Use when building Spring Boot 3.x applications, microservices, or reactive Java applications; invoke for Spring Data JPA, Spring Security 6, WebFlux, Spring Cloud integration, Java REST API design, or Microservices Java architecture. license: MIT metadata: author: https://github.com/Jeffallan version: "1.1.0" domain: backend triggers: Spring Boot, Spring Framework, Spring Cloud, Spring Security, Spring Data JPA, Spring WebFlux, Microservices Java, Java REST API, Reactive Java role: specialist scope: implementation output-format: code related-skills: java-architect, database-optimizer, microservices-architect, devops-engineer

Spring Boot Engineer

Core Workflow

  1. Analyze requirements — Identify service boundaries, APIs, data models, security needs
  2. Design architecture — Plan microservices, data access, cloud integration, security; confirm design before coding
  3. Implement — Create services with constructor injection and layered architecture (see Quick Start below)
  4. Secure — Add Spring Security, OAuth2, method security, CORS configuration; verify security rules compile and pass tests. If compilation or tests fail: review error output, fix the failing rule or configuration, and re-run before proceeding
  5. Test — Write unit, integration, and slice tests; run ./mvnw test (or ./gradlew test) and confirm all pass before proceeding. If tests fail: review the stack trace, isolate the failing assertion or component, fix the issue, and re-run the full suite
  6. Deploy — Configure health checks and observability via Actuator; validate /actuator/health returns UP. If health is DOWN: check the components detail in the response, resolve the failing component (e.g., datasource, broker), and re-validate

Reference Guide

Load detailed guidance based on context:

TopicReferenceLoad When
Web Layerreferences/web.mdControllers, REST APIs, validation, exception handling
Data Accessreferences/data.mdSpring Data JPA, repositories, transactions, projections
Securityreferences/security.mdSpring Security 6, OAuth2, JWT, method security
Cloud Nativereferences/cloud.mdSpring Cloud, Config, Discovery, Gateway, resilience
Testingreferences/testing.md@SpringBootTest, MockMvc, Testcontainers, test slices

Quick Start — Minimal Working Structure

A standard Spring Boot feature consists of these layers. Use these as copy-paste starting points.

Entity

@Entity
@Table(name = "products")
public class Product {
    @Id
    @GeneratedValue(strategy = GenerationType.IDENTITY)
    private Long id;

    @NotBlank
    private String name;

    @DecimalMin("0.0")
    private BigDecimal price;

    // getters / setters or use @Data (Lombok)
}

Repository

public interface ProductRepository extends JpaRepository<Product, Long> {
    List<Product> findByNameContainingIgnoreCase(String name);
}

Service (constructor injection)

@Service
public class ProductService {
    private final ProductRepository repo;

    public ProductService(ProductRepository repo) { // constructor injection — no @Autowired
        this.repo = repo;
    }

    @Transactional(readOnly = true)
    public List<Product> search(String name) {
        return repo.findByNameContainingIgnoreCase(name);
    }

    @Transactional
    public Product create(ProductRequest request) {
        var product = new Product();
        product.setName(request.name());
        product.setPrice(request.price());
        return repo.save(product);
    }
}

REST Controller

@RestController
@RequestMapping("/api/v1/products")
@Validated
public class ProductController {
    private final ProductService service;

    public ProductController(ProductService service) {
        this.service = service;
    }

    @GetMapping
    public List<Product> search(@RequestParam(defaultValue = "") String name) {
        return service.search(name);
    }

    @PostMapping
    @ResponseStatus(HttpStatus.CREATED)
    public Product create(@Valid @RequestBody ProductRequest request) {
        return service.create(request);
    }
}

DTO (record)

public record ProductRequest(
    @NotBlank String name,
    @DecimalMin("0.0") BigDecimal price
) {}

Global Exception Handler

@RestControllerAdvice
public class GlobalExceptionHandler {
    @ExceptionHandler(MethodArgumentNotValidException.class)
    @ResponseStatus(HttpStatus.BAD_REQUEST)
    public Map<String, String> handleValidation(MethodArgumentNotValidException ex) {
        return ex.getBindingResult().getFieldErrors().stream()
            .collect(Collectors.toMap(FieldError::getField, FieldError::getDefaultMessage));
    }

    @ExceptionHandler(EntityNotFoundException.class)
    @ResponseStatus(HttpStatus.NOT_FOUND)
    public Map<String, String> handleNotFound(EntityNotFoundException ex) {
        return Map.of("error", ex.getMessage());
    }
}

Test Slice

@WebMvcTest(ProductController.class)
class ProductControllerTest {
    @Autowired MockMvc mockMvc;
    @MockBean ProductService service;

    @Test
    void createProduct_validRequest_returns201() throws Exception {
        var product = new Product(); product.setName("Widget"); product.setPrice(BigDecimal.TEN);
        when(service.create(any())).thenReturn(product);

        mockMvc.perform(post("/api/v1/products")
                .contentType(MediaType.APPLICATION_JSON)
                .content("""{"name":"Widget","price":10.0}"""))
            .andExpect(status().isCreated())
            .andExpect(jsonPath("$.name").value("Widget"));
    }
}

Constraints

MUST DO

RuleCorrect Pattern
Constructor injectionpublic MyService(Dep dep) { this.dep = dep; }
Validate API input@Valid @RequestBody MyRequest req on every mutating endpoint
Type-safe config@ConfigurationProperties(prefix = "app") bound to a record/class
Appropriate stereotype@Service for business logic, @Repository for data, @RestController for HTTP
Transaction scope@Transactional on multi-step writes; @Transactional(readOnly = true) on reads
Hide internalsCatch domain exceptions in @RestControllerAdvice; return problem details, not stack traces
Externalize secretsUse environment variables or Spring Cloud Config — never application.properties

MUST NOT DO

  • Use field injection (@Autowired on fields)
  • Skip input validation on API endpoints
  • Use @Component when @Service/@Repository/@Controller applies
  • Mix blocking and reactive code (e.g., calling .block() inside a WebFlux chain)
  • Store secrets or credentials in application.properties/application.yml
  • Hardcode URLs, credentials, or environment-specific values
  • Use deprecated Spring Boot 2.x patterns (e.g., WebSecurityConfigurerAdapter)

Documentation