Use when reviewing Spring Boot 4 / Java 17+ code with concrete files or diffs — pull requests, modules, or pasted Java/Spring sources — for migration risks, architecture boundary leaks, JSpecify null-safety gaps, security flaws, performance regressions, or Spring Data pitfalls. Not for Kotlin-only code, non-Spring frameworks, or generic review advice without code context.
92
89%
Does it follow best practices?
Impact
99%
2.10xAverage score across 3 eval scenarios
Passed
No findings from the security scan
Spring Boot performance review with virtual thread workload analysis
Virtual threads not recommended
33%
100%
Workload concurrency cited
100%
100%
N+1 lazy load flagged
100%
100%
Unbounded findAll flagged
100%
100%
Dead-code Caffeine bean
100%
100%
Unbounded cache / no effective TTL
100%
100%
Thread-pinning synchronized block
100%
100%
HikariCP pool not tuned
100%
100%
Missing readOnly transactions
12%
100%
Full entity instead of projection
25%
87%
File path and line numbers cited
100%
100%
Spring Boot 4 security and architecture review
Citation completeness
0%
90%
Controller-repository shortcut
0%
100%
JPA entity in API response
0%
100%
Missing authorization on admin endpoint
0%
100%
Weak password hashing
0%
100%
Sensitive data in logs
0%
100%
SQL injection via string concatenation
0%
100%
Deprecated JJWT API
0%
100%
SSRF risk flagged
0%
100%
Whitelist URL validation recommended
0%
100%
Native deserialization risk
0%
100%
Deprecated Spring null annotations
0%
100%
Missing @NullMarked package declaration
0%
100%
Missing nullability annotation on override
0%
100%
Spring Boot 4 migration code review
Web starter flagged
0%
100%
AOP starter flagged
100%
100%
Jackson group IDs flagged
100%
100%
Old Jackson imports flagged
100%
100%
Jackson2ObjectMapperBuilderCustomizer flagged
100%
100%
@MockBean flagged
100%
100%
@SpyBean flagged
100%
100%
WebMvcTest import flagged
0%
100%
TestRestTemplate flagged
100%
100%
Missing @AutoConfigureMockMvc flagged
50%
100%
spring-retry usage flagged
80%
100%
Missing @EnableResilientMethods flagged
0%
100%
HttpServiceProxyFactory flagged
42%
100%
Custom error class flagged
0%
100%
@Value config flagged
0%
100%
Java 21 not flagged
100%
100%
6277c14
Table of Contents
If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.