---
title: "java-security"
description: "trigger: writing Java or Kotlin: Spring, Jakarta EE, Struts, Quarkus, Micronaut, Vert.x or Android: SQL, JPA or MyBatis, Thymeleaf, JSP, JSF or FreeMarker templates, application.properties or.yml, web.xml, pom.xml or Gra"
canonical: https://agentpluginsdirectory.com/plugins/java-security--open-coder-ai
last-updated: 2026-09-25
---

# java-security
trigger: writing Java or Kotlin: Spring, Jakarta EE, Struts, Quarkus, Micronaut, Vert.x or Android: SQL, JPA or MyBatis, Thymeleaf, JSP, JSF or FreeMarker templates, application.properties or.yml, web.xml, pom.xml or Gradle builds; "customize java security" opens this skill's guided page. avoid: injection (SQL, command, code, SpEL, LDAP, XPath, template), XXE, SSRF, unsafe deserialization, path traversal and zip slip, weak crypto and trust-all TLS, disabled Spring Security protections, exposed secrets and actuator data, known-exploited dependency versions, exported Android components; and the bugs, leaks and style breaches SpotBugs, Sonar, PMD and Checkstyle report. 129 rules in 16 packs, security: java, crypto, spring, jakarta, persistence, templates, logging, build, android; quality: bugs, concurrency, resources, exceptions, performance, style, testing, each rule or pack allow|deny|ask in.chock/security.json; absent = deny.
- Slug: java-security--open-coder-ai
- Publisher: chock-core
- Repository: https://github.com/open-coder-ai/chock-catalog
- Manifest: base/java-security/plugin.json
- Version: 0.4.1
- License: Apache-2.0
- Category (editorial): other
- Skills: 1 (java-security)
- MCP servers: 0
- Stars: 3
- Repository created: 2026-08-17
- Repository last pushed: 2026-09-24
- Publisher type: Organization
- Listing: https://agentpluginsdirectory.com/plugins/java-security--open-coder-ai
- Schema: https://agent-plugins.org/schemas/1.0.0/plugin.schema.json

## Skills

- java-security: trigger: writing Java or Spring code, MyBatis mappers, JSP, Thymeleaf or FreeMarker templates, application.properties or application.yml. avoid: string-interpolated SQL, unescaped template output, unsafe deserialization, a wildcard CORS origin with credentials, wildcard actuator exposure, an unveri…

Descriptions come from the frontmatter of each SKILL.md, punctuation lightly normalized.
