07-solid-code-quality

A set of SOLID design and defensive-programming rules for Java and Spring code. SOLID is a group of principles for keeping software responsibilities, interfaces, inheritance, and dependencies manageable.

In plain words
What is it for?
Use it when designing or reviewing Spring code. It covers class size and responsibilities, interfaces, dependency injection, validation, resource handling, null safety, and concurrent access.
Why use it?
It reduces common maintenance and reliability problems, such as oversized classes, unsafe null handling, missing input checks, resource leaks, and shared mutable state in server components.

Cursor rule

Install

Getting it into your agent

One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.

agentmods
npx agentmods add rules/movebrickschi/harness-engineering-mcp/07-solid-code-quality
Clone the repo
git clone --depth 1 https://github.com/movebrickschi/harness-engineering-mcp
Per session 0 Nothing until a file matches its globs; then the whole rule loads.
When invoked 441 The whole file, excluding the scripts and references it only reads on demand.
Security scan A 0 findings. Scan, not verified.
Origin original No closer match found in the catalogue.
Token cost

What it costs to keep this loaded

Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.

ModelPer sessionOnce invoked
Fable 5 $0.00000 $0.00441
Opus 5 $0.00000 $0.00220
Sonnet 5 $0.00000 $0.00088
Haiku 4.5 $0.00000 $0.00044

Measured yesterday against content hash 70ff90cec6c9, method: parsed. Prices are Anthropic first-party input rates as of 2026-08-30, from the pricing page.

Security

Grade A, and why

07-solid-code-quality scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured yesterday.

A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.

Nothing flagged

None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.

assets/rules/07-solid-code-quality.mdc · 57 lines

What it actually says

SOLID原则与防御式编程

SOLID原则

原则 规则 告警阈值
单一职责(SRP) 类变更理由只能有一个 类超过200行必须拆分
开闭原则(OCP) 对扩展开放,使用SPI或Conditional Bean 禁止修改已稳定的核心逻辑
里氏替换(LSP) 子类增强而非改变父类行为 禁止继承仅为复用代码
接口隔离(ISP) 接口方法不超过5个 拆分为Role Interface
依赖倒置(DIP) Spring注入必须面向接口 禁止注入具体实现类

防御式编程

空值防御

// ✅ 使用Optional
public Optional<User> findByEmail(String email) { }

// ✅ 使用@NonNull注解
public void process(@NonNull Order order) { }

// ❌ 禁止裸返回null
public User findByEmail(String email) { return null; }

输入验证

  • Controller层:Bean Validation(@Valid, @NotBlank, @Size等)
  • Domain层:Guard Clauses(方法入口处校验前置条件)

资源释放

// ✅ 必须使用try-with-resources
try (InputStream is = new FileInputStream(file)) {
    // ...
}

// ❌ 禁止手动close()
InputStream is = new FileInputStream(file);
try { /* ... */ } finally { is.close(); }

并发安全

  • 可变共享状态必须使用ThreadLocal或并发容器
  • 优先使用不可变对象(final字段)
  • 避免在Spring单例Bean中使用实例变量存储请求状态
Changes

What this file has done since we first saw it

Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.

  1. yesterday First seen · 57 lines · 441 tokens per session scan A 70ff90cec6c9

Subscribe to this mod's changes

07-solid-code-quality is a cursor rule published in the GitHub repository movebrickschi/harness-engineering-mcp (2 stars, last pushed 3mo ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 441 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.