AI Agent Hub
Back to skills
💻

Spring Boot Backend Expert

Development Updated 2026.08.30

Paste the following prompt into your AI chat to install this skill:

Please follow the guide at https://skillhub.cn/install/skillhub.md to install the @kunlungrowth/kg-spring-boot-engineer skill in my AI assistant.

About this skill

Problem

When building Spring Boot APIs, the hard part is not only making an endpoint work. It is deciding controller boundaries, DTO validation, Spring Security 6 filters, JPA query behavior, and preventing sensitive fields from leaking into responses. This skill turns those concerns into a repeatable engineering workflow before code generation.

How it works

  • Requirement check: confirm the endpoint, HTTP method, security model, and persistence boundary.
  • Layering: separate controller, service, and repository so business logic does not sit in the entry point.
  • Implementation: produce validated DTOs, Spring Security 6 configuration, JPA entities, or WebFlux reactive endpoints.
  • Self-review: inspect transaction boundaries, N+1 queries, security filter chains, and response fields for sensitive data.
  • Artifact output: return a SpringBootSpec with endpoint, method, dto, security, and notes for later security review or optimization.

Boundaries

It fits enterprise Java services, REST endpoints, Spring Security 6, and WebFlux use cases. It is not intended for non-Spring ecosystems or legacy Java 8 projects. For Quarkus or broader Java architecture decisions, use a separate skill.

Use Cases

  • Generate a validated DTO, REST controller, and JPA repository for a new order endpoint while hiding sensitive fields.
  • Design login, authorization, and filter chain behavior with Spring Security 6 instead of scattering auth logic in controllers.
  • Convert a blocking endpoint into a WebFlux reactive endpoint and clarify controller, service, and repository boundaries.
  • Produce a SpringBootSpec artifact with endpoint, method, DTO, security, and notes for later security review.

Best For

  • Java engineers maintaining Spring Boot modules who need to define endpoint layering, DTO validation, and security boundaries.
  • Backend engineers extending enterprise services who need to add REST endpoints while checking transactions, N+1 queries, and sensitive fields.
  • Security engineers working with Spring Security 6 who need to translate filter chains, roles, and endpoint requirements into a reviewable artifact.
  • Java developers modernizing reactive services who need to convert blocking endpoints into WebFlux endpoints and clarify service boundaries.