Back to skill

Security audit

SpringBoot升级-BW

Security checks for vulnerabilities and agentic risk

Overview

This is a documentation-only Spring Boot upgrade skill with expected repository search, dependency changes, and validation commands, and no hidden execution or credential behavior found.

Install this as an upgrade assistant, not as a passive reference: it can direct substantial project edits and Maven/OpenRewrite runs. Use it on a feature branch, review generated changes before merging, and confirm any enterprise-specific dependencies or recipes are trusted and available in your environment.

Vulnerability Patterns
  • Prompt InjectionInstruction Override, Hidden Instructions, Exfiltration Commands
  • Data ExfiltrationExternal Transmission, Env Variable Harvesting, File System Enumeration
  • Privilege EscalationExcessive Permissions, Sudo/Root Execution, Credential Access
  • Supply ChainUnpinned Dependencies, External Script Fetching, Obfuscated Code
  • Excessive AgencyUnrestricted Tool Access, Autonomous Decision Making, Scope Creep

Static analysis

No suspicious patterns detected.