SkillAtlasSkill 详情

112-java-maven-plugins

Help this project grow: Become a sponsor

审核状态:已审核Quality 80Security 80

复制安装命令

用 Codex 或 Claude 安装复制这段 Prompt,粘贴到 Codex、Claude 或其他助手里,让它先审查 Skill 页面再帮你安装。

复制前请先查看来源、License 和安全提示。

项目 README

来源文件:README.md

抓取于 2026年8月29日

Plinth for Java

jabrena%2Fcursor-rules-java | Trendshift

CI Builds

Languages: Español · 中文

Help this project grow: Become a sponsor

Goal

An opinionated AI-native workflow for evolving modern Java Enterprise SDLC practices through reusable Skills, Agents, Commands & MCP servers.

What is a Plinth?

A plinth represents the solid foundation or platform used to support statues or artworks in art and sculpture. It served as a structural and symbolic foundation for columns, statues, and entire temple podiums. Romans inherited the idea from Greek architecture but expanded its use to emphasize monumentality, hierarchy, and imperial power.

Project at a glance

  • 13 Commands
  • 9 Agents
  • 125 Skills

Latest Updates

Explore the latest published content on https://jabrena.github.io/plinth/ and follow its evolution through new skills, improvements, and fixes in the CHANGELOG.

Start in 60 seconds

Install every skill for your preferred agent:

npx skills add jabrena/plinth --skill '*' --agent cursor -y
npx skills add jabrena/plinth --skill '*' --agent claude-code -y
npx skills add jabrena/plinth --skill '*' --agent codex -y
npx skills add jabrena/plinth --skill '*' --agent github-copilot -y

Install every command for your prefered agent:

install @004-commands-installation cursor
install @004-commands-installation claude-code
install @004-commands-installation codex
install @004-commands-installation github-copilot

Install every agent for your prefered agent:

install @005-agents-installation cursor
install @005-agents-installation claude-code
install @005-agents-installation codex
install @005-agents-installation github-copilot

See it in action

You can use the project in 2 ways:

  • Use the AI-Native development workflow
  • Refactor your code with Skills

Using AI-Native development workflow

Prepare the repository with /onboarding, then identify an issue in your Kanban dashboard from Atlasian Jira, Github Issues or Azure DevOps and apply the following workflow:

/onboarding
  |
  v
Issue
  |
  v
/update-issue --> /explore-problem --> /create-acceptance-criteria
  |
  v
/create-spec --> /explore-design
  |
  v
/implement-spec --> /close-spec

/onboarding establishes root AGENTS.md and one unambiguous OpenSpec project before issue selection. It preserves existing prerequisites; when OpenSpec is missing, you select its result path with documentation/openspec as the default.

Analysis & Design

Turn an idea into an actionable change with user stories, GitHub Issues or Jira, ADRs, diagrams, AI plan mode, and OpenSpec.

Functional Specification:

CommandExplanation
/onboardingEstablish root repository guidance and one unambiguous OpenSpec project before issue work.
/update-issueUpdate an existing GitHub or Jira issue with a structured user story, acceptance criteria, and resource content.
/explore-problemEvaluate an issue from five perspectives and post a Functional Specification comment on the issue.
/create-acceptance-criteriaDerive Gherkin acceptance criteria from a Functional Specification and post them as a separate issue comment.

Technical Specification:

CommandExplanation
/create-adr (Optional)Record an architectural decision, its alternatives, rationale, and consequences.
/create-diagram (Optional)Create a focused architecture or design diagram from approved artifacts.
/create-spec (OpenSpec)Create or update one or more validated OpenSpec changes.
/explore-designCompare technical approaches and obtain an approved design direction.
Build

Implement and improve Java applications with Maven, design, coding, testing, security, documentation, Spring Boot, Quarkus, Micronaut, OpenAPI, and WireMock guidance.

CommandExplanation
/implement-specDeliver an approved plan or validated OpenSpec task list through framework-aware delegation.
/close-specArchive an OpenSpec change by name using the OpenSpec CLI.

Operate

Measure and improve production behavior through observability, profiling, benchmarking, and performance testing.

CommandExplanation
/profileCoordinate Java profiling from baseline detection through verified optimization.
/benchmarkSelect and coordinate JMeter, Gatling, or JMH performance workflows.

Compliance (Alpha)

Review Java systems, AI models, and how GenAI tools are used across applications and delivery pipelines for regulation-aware engineering controls, evidence, and qualified owner handoffs spanning AI, data, security, product, platform, market, and governance. These skills support engineering awareness and do not provide legal advice.

RegulationSkill
EU AI Act801-regulations-eu-ai-act
DORA802-regulations-dora
GDPR803-regulations-gdpr
NIS2804-regulations-eu-nis2
Cyber Resilience Act805-regulations-eu-cyber-resilience-act
Data Act806-regulations-eu-data-act
Digital Services Act807-regulations-eu-digital-services-act
Digital Markets Act808-regulations-eu-digital-markets-act
MiFID II810-regulations-eu-mifid-ii
Market Abuse Regulation811-regulations-eu-market-abuse-regulation
Product Liability Directive812-regulations-eu-product-liability-directive

Note: This set of skills could be a good complement for the future OWASP EU Compliance MCP.

Refactor your code with Skill

Ask your agent:

Use @110-java-maven-best-practices to review this Maven project located in examples/@maven/maven-demo
Explain the findings, apply the approved improvements, and validate the build.

The skill guides the agent through a structured Maven review while keeping you in control of proposed changes.

5-Minute Onboarding

Learn to use this project following the quick guide Getting Started in 5 minutes.

Explore the complete Commands, Agents, Skills, and MCP Servers inventories.

Project Components

The project generates a set of deliverables at the end of any iteration.

InventoryInstallationGetting Started
1. Commands@004-commands-installation Install Commands in projectCommands
2. Agents@005-agents-installation Install Agents in Cursor/ClaudeAgents
3. Skillsnpx skills add jabrena/plinth --skill '*' --agent cursor -ySkills

Compatibility

This project is compatible with any tool that supports Commands, Agents, Skills, MCP Servers and AGENTS.md.

Skill Validations

Every push runs the following validation checks in the Skill Scanners as part of the CI Pipeline to keep documentation and generated skills correct, consistent, and secure:

NamePurpose
1. MarkdownValidatorProtects the documentation layer by catching Markdown parsing drift and remote link failures before skill-specific checks run.
2. skill-checkConfirms every generated skill follows the expected packaging contract, complementing scanners that focus on behavior or security risk.
3. cisco-ai-skill-scanner by CiscoAdds behavior-oriented security coverage by looking for risky skill flows that structural validation cannot see.
4. SkillSpector by NVIDIAProvides an independent static quality and security review, useful for comparing findings against the other scanners.
5. Snyk Agent Scan by SNYKFocuses on agent-skill supply-chain and prompt-risk signals, adding another security perspective alongside Cisco and SkillSpector.

Limitations

Lack of determinism

From the outset, be aware that results from interactions with these Skills and agents are not deterministic because of how the models behave, but you can mitigate that with clear goals and validation checkpoints.

Not all models behave in the same way

Some interactive skills require Premium models for interactive use; otherwise they follow a fixed sequence of steps.

Limits of interactions with models

Models can generate code, but they cannot execute it against your local data. To bridge that gap, some Skills include scripts you run locally.

Software engineers must remain in the loop

This project supports software engineering work; it does not replace engineering judgment. A software engineer must review, guide, and validate AI-generated decisions, code, and outcomes before they are used.

Access to corporate data

Use caution when a problem involves corporate databases or other sensitive organizational data. Before granting an AI-assisted workflow access, assess authorization, privacy, data leakage, retention, and unintended modification risks. Apply least-privilege access, human review, validation, and monitoring. See OWASP GenAI Data Security Risks & Mitigations 2026, and the new set of skills about EU regulation.

Contribute

See CONTRIBUTING.md for ways to support and improve the project.

Architecture Decision Records (ADR)

  • Review the ADR index for the complete list.

Java JEPs from Java 8 onward

Java uses JEPs (JDK Enhancement Proposals) to describe new language and platform features. This repository tracks which JEPs could improve the Skills and guidance here.

Further resources

Talks, articles, reference links, skill portals, and related projects live in Project references.

Developed by humans with support from Cursor and Codex, with ❤️ from Madrid

开发与工程

中风险

  • 来源需自行核对维护者身份。
  • 包含脚本或命令调用,安装前请复核。
  • 未检测到明显外部权限要求。
  • 未检测到高风险命令。
  • 扫描发现:2 条。

Codex — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/jabrena/plinth.git
  3. 将 "skills/112-java-maven-plugins" 文件夹复制到 Codex 的 skills 目录中。
  4. 重启 Codex 让新的 skill 生效。

Codex — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Codex 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Codex 让新的 skill 生效。

Claude Code — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/jabrena/plinth.git
  3. 将 "skills/112-java-maven-plugins" 文件夹复制到 Claude Code 的 skills 目录中。
  4. 重启 Claude Code 让新的 skill 生效。

Claude Code — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Claude Code 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Claude Code 让新的 skill 生效。

Cursor — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/jabrena/plinth.git
  3. 将 "skills/112-java-maven-plugins" 文件夹复制到 Cursor 的 skills 目录中。
  4. 重启 Cursor 让新的 skill 生效。

Cursor — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Cursor 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Cursor 让新的 skill 生效。

GitHub Copilot — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/jabrena/plinth.git
  3. 将 "skills/112-java-maven-plugins" 文件夹复制到 GitHub Copilot 的 skills 目录中。
  4. 重启 GitHub Copilot 让新的 skill 生效。

GitHub Copilot — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 GitHub Copilot 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 GitHub Copilot 让新的 skill 生效。

Windsurf — Git Clone 安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 克隆仓库:git clone https://github.com/jabrena/plinth.git
  3. 将 "skills/112-java-maven-plugins" 文件夹复制到 Windsurf 的 skills 目录中。
  4. 重启 Windsurf 让新的 skill 生效。

Windsurf — 手动复制安装

  1. 安装前请先查看来源仓库和风险报告。
  2. 从源仓库下载 SKILL.md 及相关文件。
  3. 在 Windsurf 的 skills 目录中创建新文件夹。
  4. 将所有 skill 文件复制到新文件夹中。
  5. 重启 Windsurf 让新的 skill 生效。
查看 SKILL.md 原文
name: 112-java-maven-plugins
description: Use when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning (OWASP), code formatting (Spotless), version management, container image build (Jib), build information tracking, and benchmarking (JMH) — through a consultative, modular step-by-step approach that only adds what you actually need. This should trigger for requests such as Add Maven plugins in pom.xml; Improve Maven plugins in pom.xml; Configure Maven quality plugins in pom.xml; Add Maven build lifecycle plugins for Java verification; Review Maven plugin versions and executions. Part of Plinth Toolkit
license: Apache-2.0
metadata:
  author: Juan Antonio Breña Moral
  version: 0.18.0

Maven Plugins: pom.xml Configuration Best Practices

Configure Maven plugins and profiles in pom.xml using a structured, question-driven process that preserves existing configuration. This is an interactive SKILL.

What is covered in this Skill?

Maven plugins:

  • Maven Compiler
  • Maven Enforcer
  • Maven Surefire
  • Maven Failsafe
  • HTML test reports (Surefire Report, JXR)
  • Maven Spotless
  • Maven Flatten
  • Maven Versions
  • Maven Git Commit ID
  • Maven Jib

Maven profiles:

  • JaCoCo (code coverage)
  • PiTest (mutation testing)
  • Security (OWASP dependency check)
  • Static analysis (SpotBugs, PMD)
  • SonarQube/SonarCloud
  • JMH (Java Microbenchmark Harness)
  • Cyclomatic complexity

Constraints

Before applying plugin recommendations, ensure the project is in a valid state. Use a structured, question-driven process that preserves existing configuration and adds only what the user selects.

  • MANDATORY: Run ./mvnw validate or mvn validate before applying any plugin recommendations
  • SAFETY: If validation fails, stop and ask the user to fix issues—do not proceed until resolved
  • SCOPE: Begin with Step 1 (existing configuration analysis) before any changes. Never remove or replace existing plugins; only add new ones that do not conflict
  • BEFORE READING PLUGIN REFERENCES: Run the question flow embedded in this SKILL.md first. Ask questions one-by-one in strict order, collect all selected plugins/profiles and conditional values, then read only the implementation references selected by the user's answers

When to use this skill

  • Add Maven plugins in pom.xml
  • Improve Maven plugins in pom.xml
  • Configure Maven quality plugins in pom.xml
  • Add Maven build lifecycle plugins for Java verification
  • Review Maven plugin versions and executions

Workflow

  1. Validate project before plugin changes

Run ./mvnw validate or mvn validate and stop if validation fails.

  1. Analyze current plugin and profile configuration

Before making any changes to pom.xml:

  1. Scan existing plugins in <build><plugins>, <build><pluginManagement>, and <reporting><plugins>.

  2. Scan existing properties in <properties>.

  3. Scan existing profiles in <profiles>.

  4. Identify conflicts between existing configuration and possible additions.

  5. Preserve all existing plugins, properties, and profiles.

  6. Ask the user before enhancing any existing plugin, property, reporting entry, support file, or profile.

  7. Skip duplicate additions unless the user explicitly requests an enhancement.

  8. Check Maven Wrapper before plugin changes

Check for Maven Wrapper files in the project root:

  • mvnw and mvnw.cmd
  • .mvn/wrapper/maven-wrapper.properties

If Maven Wrapper is not present, stop and ask:

"I notice this project doesn't have Maven Wrapper configured. The Maven Wrapper ensures everyone uses the same Maven version, improving build consistency across different environments. Would you like me to install it? (y/n)"

Wait for the user's response before asking any other question. If the user says "y", install it:

mvn wrapper:wrapper
  1. Ask Maven plugin assessment questions before reading references

Run this XML-included question flow before reading any plugin/profile implementation reference. Ask one question at a time, wait for the user's answer, and record selected plugins, profiles, and conditional values before continuing.

Question 1: What type of Java project is this?

Options:

  • Java Library (for publishing to Maven Central/Nexus)
  • Java CLI Application (command-line tool)
  • Java Microservice (Web service/REST API/Modular monolith)
  • Serverless (AWS Lambdas, Azure Functions)
  • Java POC (Proof of Concept)
  • Other (specify)

Question 2: Which Java version does your project target?

Options:

  • Java 17 (LTS - recommended for new projects)
  • Java 21 (LTS - latest LTS version)
  • Java 25 (LTS - latest LTS version)
  • Other (specify version)

Question 3: What build and quality aspects are important for your project?

Options:

  • Format source code (Spotless)
  • Maven Enforcer
  • Unit Testing (Surefire)
  • Unit Testing Reports (Surefire Reports)
  • Integration testing (Failsafe)
  • Code coverage reporting (JaCoCo)
  • Mutation testing (PiTest)
  • Security vulnerability scanning (OWASP)
  • Security static code analysis (SpotBugs, PMD)
  • Sonar
  • Dependency analysis (maven-dependency-plugin)
  • Version management
  • Container image build (Jib)
  • JMH (Java Microbenchmark Harness)
  • Maven Compiler
  • Cyclomatic Complexity

Note: When "Cyclomatic Complexity" is selected, Step 20 will create a PMD ruleset file and profile. The ruleset location depends on project structure: src/main/pmd/pmd-cyclomatic-complexity.xml (mono-module) or pmd/pmd-cyclomatic-complexity.xml (multi-module).


Question 3.1 (conditional): What is your target container image for Jib?

Note: This question is only asked if "Container image build (Jib)" was selected in question 3.

  • Example format: gcr.io/my-project/my-app, docker.io/username/myimage, or myimage for local Docker
  • The image name will be used in the Jib plugin <to><image> configuration

Question 4: What is your target coverage threshold?

Options:

  • 70% (moderate)
  • 80% (recommended)
  • 90% (high)
  • Custom percentage (specify)

Note: This question is only asked if "Code coverage reporting (JaCoCo)" was selected in question 3.


Question 5: Do you want to configure Sonar/SonarCloud integration?** (y/n)

Note: This question is only asked if "Static code analysis (SpotBugs, Sonar)" was selected in question 3.

If yes, please provide the following information:


Question 5.1: What is your Sonar organization identifier?

  • For SonarCloud: This is typically your GitHub username or organization name
  • For SonarQube: This is your organization key as configured in SonarQube
  • Example: my-github-user or my-company-org

Question 5.2: What is your Sonar project key?

  • For SonarCloud: Usually in format GITHUB_USER_REPOSITORY_NAME (e.g., john-doe_my-java-project)
  • For SonarQube: Custom project key as defined in your SonarQube instance
  • Must be unique within your Sonar organization
  • Example: john-doe_awesome-java-lib

Question 5.3: What is your Sonar project display name?

  • Human-readable name for your project as it appears in Sonar dashboard
  • Can contain spaces and special characters
  • Example: Awesome Java Library or My Microservice API

Question 5.4: Which Sonar service are you using? (conditional)

Note: This question is only asked if Sonar configuration was enabled in question 5.

Options:

  • SonarCloud (https://sonarcloud.io) - recommended for open source projects
  • SonarQube Server (specify your server URL)

If SonarQube Server: Please provide your SonarQube server URL (e.g., https://sonar.mycompany.com)


After all applicable questions are answered, confirm the selections and map them to references:

  • If Maven Compiler is selected, read references/112-java-maven-plugins-maven-compiler-plugin.md.
  • If Maven Enforcer is selected, read references/112-java-maven-plugins-maven-enforcer-plugin.md.
  • If Unit Testing (Surefire) is selected, read references/112-java-maven-plugins-maven-surefire-plugin.md.
  • If Integration testing (Failsafe) is selected, read references/112-java-maven-plugins-maven-failsafe-plugin.md.
  • If Unit Testing Reports (Surefire Reports) is selected, read references/112-java-maven-plugins-maven-surefire-report-plugin.md and references/112-java-maven-plugins-maven-jxr-plugin.md.
  • If Format source code (Spotless) is selected, read references/112-java-maven-plugins-spotless-maven-plugin.md.
  • If Version management is selected, read references/112-java-maven-plugins-versions-maven-plugin.md.
  • If build information tracking is selected, read references/112-java-maven-plugins-git-commit-id-maven-plugin.md.
  • If the project is a Java Library, read references/112-java-maven-plugins-flatten-maven-plugin.md.
  • If Container image build (Jib) is selected, read references/112-java-maven-plugins-jib-maven-plugin.md.
  • If Dependency analysis is selected, read references/112-java-maven-plugins-maven-dependency-plugin.md.
  • If Code coverage reporting (JaCoCo) is selected, read references/112-java-maven-plugins-profile-jacoco.md.
  • If Mutation testing (PiTest) is selected, read references/112-java-maven-plugins-profile-pitest.md.
  • If Security vulnerability scanning (OWASP) is selected, read references/112-java-maven-plugins-profile-security.md.
  • If Security static code analysis (SpotBugs, PMD) is selected, read references/112-java-maven-plugins-profile-static-analysis.md.
  • If Sonar is selected, read references/112-java-maven-plugins-profile-sonar.md.
  • If JMH is selected, read references/112-java-maven-plugins-profile-jmh.md.
  • If Cyclomatic Complexity is selected, read references/112-java-maven-plugins-profile-cyclomatic-complexity.md.
  • Do not read or apply unselected plugin/profile references.
  1. Read selected references and add only selected configuration

Add selected plugins and profiles without removing existing ones, preserving project structure and compatibility. Add only the Maven properties, plugin configuration, profile configuration, reporting plugins, and support files required by the selected references.

  1. Summarize applied plugin setup

Report added plugins/profiles, rationale, and recommended follow-up commands or checks.

Reference

For detailed guidance, examples, and constraints, see:

发现问题?提交给管理员复核

评分:

评论 (0)

暂无评论,成为第一个评论者吧!