Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
/plugin marketplace add AratKruglik/claude-sdlcnpx agentmods add plugins/aratkruglik/claude-sdlc/java-foundationgit clone --depth 1 https://github.com/AratKruglik/claude-sdlcGrade A, and why
java-foundation scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
{
"name": "java-foundation",
"version": "1.3.0",
"description": "Shared Java foundation skills for the SDLC marketplace. Contains stack-agnostic conventions: java-conventions (modern Java idioms — records, sealed types, Optional, streams, immutability, null discipline), build-tooling (Maven vs Gradle detection, wrappers, dependency/BOM management, semver) and jvm-testing (JUnit 5, Mockito, AssertJ, Testcontainers). Referenced cross-plugin by every Java framework provider (java-plugin, spring-boot-plugin). No agent, no stack profile — pure shared library.",
"author": {
"name": "Oleksii Kruhlyk",
"url": "https://github.com/AratKruglik"
},
"license": "MIT",
"homepage": "https://github.com/AratKruglik/claude-sdlc",
"keywords": ["java", "jvm", "maven", "gradle", "junit", "shared", "foundation", "sdlc"],
"dependencies": ["sdlc"]
}
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 14 lines scan A f38c92fae0cc
java-foundation is a plugin published in the GitHub repository AratKruglik/claude-sdlc (31 stars, last pushed 28d ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
cursor-rules-java marketplace
Plugin marketplace listing 61 plugins: 012-agile-epic, 013-agile-feature, 014-agile-user-story, 021-tooling-github, 030-architecture-adr-general.
developer-kit-java
Comprehensive Java development toolkit with Spring Boot, testing, LangChain4J, and AWS integration.
spring-boot-skills marketplace
Plugin marketplace listing 2 plugins: spring-boot-4-skills, spring-boot-3-skills.
spring-tools
Spring Tools Language Server — real-time diagnostics, completions, and code navigation for Spring Boot projects. Operates standalone without requiring JDT Language Server. On first run, downloads the language server JAR (checksum-verified) from cdn.spring.io and launches it as a local Java process; requires Java 21+…
cellar
Look up the public API of any JVM dependency (Scala 3, Scala 2, Java) from the terminal.
marketplace
Java debugging tools for AI agents using JDB (Java Debugger CLI).