AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Spring Boot Security Scan

skill-dolphinllc-claude-security-skills-spring-boot-security-scan · by Dolphinllc

Defensive security scan for Spring Boot applications using Spring Security. Detects permitAll on sensitive routes, disabled CSRF on stateful endpoints, wildcard CORS with credentials, missing @PreAuthorize, JdbcTemplate string concatenation, Jackson default typing, exposed actuators, and weak BCrypt strength. Invoke when the user asks to "review", "audit", or "scan" a Spring Boot project.

— No reviews yet
0 installs
33 views
0.0% view→install

Install

$ agentstack add skill-dolphinllc-claude-security-skills-spring-boot-security-scan

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • ✓ Prompt-injection patterns
  • ✓ Secret / credential exfiltration
  • ✓ Dangerous shell & filesystem operations
  • ✓ Untrusted network calls
  • ✓ Known-malicious package signatures

What it can access

  • ✓ Network access No
  • ✓ Filesystem access No
  • ✓ Shell / process execution No
  • ✓ Environment & secrets No
  • ✓ Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-dolphinllc-claude-security-skills-spring-boot-security-scan)

Reliability & compatibility

✓ Security review passed
0 installs to date
— no reviews yet
○ 5mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Spring Boot Security Scan? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Spring Boot Security Scan

Defensive scan for Spring Boot 3.x with Spring Security 6.x. Reports findings using the [shared scoring schema](../../../SCORING.md).

Scope

  • *Application.java and @Configuration classes
  • SecurityFilterChain beans / WebSecurityConfigurerAdapter (legacy)
  • @RestController / @Controller classes
  • application.{properties,yml}
  • Repositories / DAOs using JdbcTemplate, EntityManager, native queries

Procedure

  1. Locate every SecurityFilterChain bean and read the request-matcher rules in order — first match wins.
  2. Walk controller methods for @PreAuthorize / @Secured / endpoint-level rules.
  3. Inspect data-access layer for native queries built by string concat.
  4. Inspect application.{properties,yml} for secrets and actuator exposure.

Rules

| ID | Severity | Detection | Fix | |----|----------|-----------|-----| | SB-SEC-001 | critical | SecurityFilterChain with .anyRequest().permitAll() | .anyRequest().authenticated() (whitelist exceptions explicitly) | | SB-SEC-002 | high | .csrf(csrf -> csrf.disable()) on a stateful (cookie-session) app | Keep CSRF enabled; disable only for stateless JWT APIs and document why | | SB-SEC-003 | high | Custom matcher allows /actuator/** or /admin/** without role check | Require hasRole("ADMIN") | | SB-SEC-004 | medium | httpBasic() enabled together with form login on the same chain (auth confusion) | Pick one mechanism per chain | | SB-CORS-001 | high | @CrossOrigin(origins = "*") with allowCredentials = "true" | Pin origins via CorsConfigurationSource allowlist | | SB-CTRL-001 | high | @RestController method performing mutation lacks @PreAuthorize and the chain's matcher only requires authenticated() | Add @PreAuthorize("hasRole('...')") or tighten chain | | SB-CTRL-002 | medium | @RequestMapping without method = on mutating endpoints (accepts GET) | Use @PostMapping / @PutMapping etc. | | SB-VALID-001 | high | @RequestBody parameter not annotated with @Valid / @Validated | Add @Valid; declare constraints on DTO | | SB-SQL-001 | critical | jdbcTemplate.query("... " + var + " ...", ...) or String.format into SQL | Use ? placeholders + args array, or NamedParameterJdbcTemplate | | SB-SQL-002 | high | @Query(value = "SELECT ... WHERE col = '" + ... ) (concat) — or nativeQuery=true with String.format | Bind via :param | | SB-JACKSON-001 | critical | ObjectMapper.activateDefaultTyping(...) / enableDefaultTyping() enabled on input deserialization | Remove default typing; use @JsonTypeInfo allowlist | | SB-CFG-001 | critical | application.{properties,yml} contains literal credentials (spring.datasource.password=..., API keys) | Externalize via env / Vault; rotate | | SB-ACT-001 | high | management.endpoints.web.exposure.include=* without securing actuator chain | Enumerate exposed endpoints; require ACTUATOR role | | SB-ACT-002 | medium | /actuator/heapdump, /actuator/env, /actuator/configprops exposed | Disable or restrict to internal network | | SB-PWD-001 | high | BCryptPasswordEncoder() default strength used (10) for high-value accounts — acceptable but consider 12 | Use BCryptPasswordEncoder(12) for admin tier | | SB-PWD-002 | critical | NoOpPasswordEncoder / plaintext comparison | Use BCryptPasswordEncoder or Argon2PasswordEncoder | | SB-LOG-001 | medium | log.info("user={}", user) where user toString includes hash/PII | Override toString to redact or log id only |

Wrong vs. right

SB-SEC-001 (permitAll)

// ❌ Everything is open
http
  .authorizeHttpRequests(a -> a.anyRequest().permitAll())
  .build();
// ✅ Default-deny + explicit whitelist
http
  .authorizeHttpRequests(a -> a
    .requestMatchers("/", "/health", "/login").permitAll()
    .requestMatchers("/admin/**").hasRole("ADMIN")
    .anyRequest().authenticated())
  .build();

SB-SQL-001 (string concat)

// ❌
jdbcTemplate.query("SELECT * FROM users WHERE email = '" + email + "'", rowMapper);
// ✅
jdbcTemplate.query("SELECT * FROM users WHERE email = ?", rowMapper, email);

SB-JACKSON-001 (default typing)

// ❌ Polymorphic deserialization → RCE gadget chains
mapper.activateDefaultTyping(LaissezFaireSubTypeValidator.instance);
// ✅ Allowlist subtypes via annotations
@JsonTypeInfo(use = Id.NAME, property = "type")
@JsonSubTypes({ @Type(Cat.class, name = "cat"), @Type(Dog.class, name = "dog") })
public abstract class Pet { }

References

  • Spring Security: https://docs.spring.io/spring-security/reference/index.html
  • Spring Boot Actuator: https://docs.spring.io/spring-boot/docs/current/reference/html/actuator.html
  • OWASP Cheat Sheet — Java: https://cheatsheetseries.owasp.org/cheatsheets/JavaSecurityCheat_Sheet.html

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.