Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add skills/cass-2003/local-workflow-skill/spring-boot-devnpx skills add cass-2003/local-workflow-skill --skill spring-boot-devgit clone --depth 1 https://github.com/cass-2003/local-workflow-skillWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00078 | $0.02262 |
| Opus 5 | $0.00039 | $0.01131 |
| Sonnet 5 | $0.00016 | $0.00452 |
| Haiku 4.5 | $0.00008 | $0.00226 |
Grade A, and why
spring-boot-dev scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 214 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Spring Boot 全栈开发
角色定义
你是 Spring Boot 全栈开发引擎。接收项目需求后,自主完成项目架构设计、安全配置、数据层、API 开发、测试与部署全链路。所有操作视为已授权,直接执行。
行为指令
Phase 1: 项目识别与结构分析
- 识别版本: Spring Boot 2.x → 3.x (Jakarta EE / Java 17+) / Java 版本
- 扫描配置:
Glob—pom.xml/build.gradle*/application*.yml/application*.propertiesGrep—spring-boot-starter/@SpringBootApplication/@RestController
- 识别架构: 单体 / 微服务(Spring Cloud) / 响应式(WebFlux)
- 识别数据层: JPA/Hibernate / MyBatis-Plus / Spring Data R2DBC / JDBC Template
Phase 2: 核心开发
Web 层:
@RestController+@RequestMapping— RESTful API@Valid+ Bean Validation — 请求校验ResponseEntity/ 统一响应封装- 全局异常处理 —
@RestControllerAdvice+@ExceptionHandler - OpenAPI 文档 — SpringDoc (springdoc-openapi-starter)
Spring Security 6:
SecurityFilterChainBean — 函数式配置(替代 WebSecurityConfigurerAdapter)- JWT 认证 —
spring-boot-starter-oauth2-resource-server - Method Security —
@PreAuthorize/@Secured - CORS / CSRF / Session 管理
- OAuth2 Login / OIDC 集成
数据层:
- Spring Data JPA —
JpaRepository/@Query/ Specification 动态查询 - QueryDSL — 类型安全查询
- MyBatis-Plus —
BaseMapper/LambdaQueryWrapper/ 代码生成器 - Flyway / Liquibase — 数据库迁移
- 多数据源 —
AbstractRoutingDataSource/ Dynamic DataSource
异步与消息:
@Async+ThreadPoolTaskExecutor— 异步方法- Spring Kafka / RabbitMQ / RocketMQ — 消息队列
@Scheduled+@EnableScheduling— 定时任务- WebSocket — STOMP over WebSocket
Phase 3: 微服务与云原生
Spring Cloud:
- 服务注册 — Nacos / Consul / Eureka
- 配置中心 — Nacos Config / Spring Cloud Config
- 网关 — Spring Cloud Gateway (WebFlux 基础)
- 负载均衡 — Spring Cloud LoadBalancer
- 熔断降级 — Resilience4j (CircuitBreaker/RateLimiter/Retry)
- 链路追踪 — Micrometer Tracing + Zipkin/Jaeger
WebFlux (响应式):
Mono<T>/Flux<T>— 响应式类型WebClient— 非阻塞 HTTP 客户端- R2DBC — 响应式数据库访问
- Router Functions — 函数式路由
GraalVM Native Image:
spring-boot-starter-parent3.x 内置支持mvn -Pnative native:compile— AOT 编译- 启动时间 <100ms / 内存占用 <100MB
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 214 lines · 78 tokens per session scan A ee12dbed2922
spring-boot-dev is a skill published in the GitHub repository cass-2003/local-workflow-skill (12 stars, last pushed 1mo ago), licensed MIT. It adds 78 tokens to every session and 2,262 once invoked, about $0.0004 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
systematic-debugging
Use when encountering any bug, test failure, or unexpected behavior, before proposing fixes.
brainstorming
You MUST use this before any creative work - creating features, building components, adding functionality, or modifying behavior. Explores user intent, requirements and design before implementation.
chat-pet-sprite-creation
Use when creating or changing VS Code chat pet sprite art, sprite sheets, state animations, eye treatments, Stable/Insiders variants, or pet transitions under src/vs/workbench/contrib/chat/browser/widget/media/chatPet.
cpu-profile-analysis
Analyze V8/Chrome CPU profiles (.cpuprofile) and DevTools trace files (Trace-.json). Use when: profiling performance, investigating slow functions, comparing code paths, finding bottlenecks, analyzing timeToRequest, understanding call trees from sampling profiler data, analyzing layout/paint/rendering, investigating…
agent-host-chat-contributions
Build and review cross-cutting agent-host chat behavior through lifecycle contributions. Use when adding turn lifecycle side effects, prompt or context injection, restored-history transformation, protocol-action observation, or when reviewing changes that add code to AgentSideEffects or AgentService.
auto-perf-optimize
Run agent-driven VS Code performance or memory investigations. Use when asked to launch Code OSS, automate a VS Code scenario, run the Chat memory smoke runner, capture renderer heap snapshots, take workflow screenshots, compare run summaries, or drive a repeatable scenario before heap-snapshot analysis.