112-java-maven-plugins
Use when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning (OWASP), code formatting (Spotless), version management, container image build (Jib), build information tracking, and benchma…
Install / Use
npx skills add jabrena/plinth --skill 112-java-maven-pluginsInstalls into whichever agent you are using.
SKILL.md
Installable skill definition
Quality Score
Category
SecuritySupported Platforms
Our assessment of 112-java-maven-plugins
112-java-maven-plugins scores 86/100 on our quality scale, 697th of 1,082 Security skills we index.
Its SKILL.md is 12 KB long, split into 5 sections with 1 code example: a thorough specification that gives an agent plenty to work with.
It has 441 GitHub stars, a meaningful sign that others use it.
Maintenance, license and trust
- The repository was last updated 18 days ago, so 112-java-maven-plugins is actively maintained.
- It is released under the Apache-2.0 license, a permissive license that allows use, modification and commercial use with attribution.
- Its trust signals score 100/100, with no cautions. These come from repository metadata, not a code audit — read the skill file before letting an agent act on it.
112-java-maven-plugins compared with similar skills
All 4 of these similar skills score higher than 112-java-maven-plugins; compare them before choosing.
| Skill | Score | Stars | Updated | Format |
|---|---|---|---|---|
| 112-java-maven-plugins (this skill)by jabrena | 86 | 441 | 18d ago | SKILL.md |
| LocalAIby mudler | 100 | 49.4k | today | MCP Server |
| algorithmic-artby anthropics | 100 | 177.9k | 12d ago | SKILL.md |
| pptxby anthropics | 100 | 177.9k | 12d ago | SKILL.md |
| designby nextlevelbuilder | 100 | 130.2k | 13d ago | SKILL.md |
Frequently asked questions
- How do I install 112-java-maven-plugins?
- Run
npx skills add jabrena/plinth --skill 112-java-maven-plugins. The install tabs above show the steps for each supported agent. - Which AI agents does 112-java-maven-plugins work with?
- It is written for Universal, as a SKILL.md file. Other agents that read the same format can often use it too.
- Is 112-java-maven-plugins safe to use?
- It is Apache-2.0-licensed and scores 100/100 on trust signals. Skills are instructions an agent will follow, so read the file before installing it and do not approve commands you do not understand.
- Is 112-java-maven-plugins still maintained?
- The repository was last updated 18 days ago, so 112-java-maven-plugins is actively maintained.
Skill content
View source on GitHubname: 112-java-maven-plugins description: Use when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning (OWASP), code formatting (Spotless), version management, container image build (Jib), build information tracking, and benchmarking (JMH) — through a consultative, modular step-by-step approach that only adds what you actually need. This should trigger for requests such as Add Maven plugins in pom.xml; Improve Maven plugins in pom.xml; Configure Maven quality plugins in pom.xml; Add Maven build lifecycle plugins for Java verification; Review Maven plugin versions and executions. Part of Plinth Toolkit license: Apache-2.0 metadata: author: Juan Antonio Breña Moral version: 0.19.0
Maven Plugins: pom.xml Configuration Best Practices
Configure Maven plugins and profiles in pom.xml using a structured, question-driven process that preserves existing configuration. This is an interactive SKILL.
What is covered in this Skill?
Maven plugins:
- Maven Compiler
- Maven Enforcer
- Maven Surefire
- Maven Failsafe
- HTML test reports (Surefire Report, JXR)
- Maven Spotless
- Maven Flatten
- Maven Versions
- Maven Git Commit ID
- Maven Jib
Maven profiles:
- JaCoCo (code coverage)
- PiTest (mutation testing)
- Security (OWASP dependency check)
- Static analysis (SpotBugs, PMD)
- SonarQube/SonarCloud
- JMH (Java Microbenchmark Harness)
- Cyclomatic complexity
Constraints
Before applying plugin recommendations, ensure the project is in a valid state. Use a structured, question-driven process that preserves existing configuration and adds only what the user selects.
- MANDATORY: Run
./mvnw validateormvn validatebefore applying any plugin recommendations - SAFETY: If validation fails, stop and ask the user to fix issues—do not proceed until resolved
- SCOPE: Begin with Step 1 (existing configuration analysis) before any changes. Never remove or replace existing plugins; only add new ones that do not conflict
- BEFORE READING PLUGIN REFERENCES: Run the question flow embedded in this SKILL.md first. Ask questions one-by-one in strict order, collect all selected plugins/profiles and conditional values, then read only the implementation references selected by the user's answers
When to use this skill
- Add Maven plugins in pom.xml
- Improve Maven plugins in pom.xml
- Configure Maven quality plugins in pom.xml
- Add Maven build lifecycle plugins for Java verification
- Review Maven plugin versions and executions
Workflow
- Validate project before plugin changes
Run ./mvnw validate or mvn validate and stop if validation fails.
- Analyze current plugin and profile configuration
Before making any changes to pom.xml:
-
Scan existing plugins in
<build><plugins>,<build><pluginManagement>, and<reporting><plugins>. -
Scan existing properties in
<properties>. -
Scan existing profiles in
<profiles>. -
Identify conflicts between existing configuration and possible additions.
-
Preserve all existing plugins, properties, and profiles.
-
Ask the user before enhancing any existing plugin, property, reporting entry, support file, or profile.
-
Skip duplicate additions unless the user explicitly requests an enhancement.
-
Check Maven Wrapper before plugin changes
Check for Maven Wrapper files in the project root:
mvnwandmvnw.cmd.mvn/wrapper/maven-wrapper.properties
If Maven Wrapper is not present, stop and ask:
"I notice this project doesn't have Maven Wrapper configured. The Maven Wrapper ensures everyone uses the same Maven version, improving build consistency across different environments. Would you like me to install it? (y/n)"
Wait for the user's response before asking any other question. If the user says "y", install it:
mvn wrapper:wrapper
- Ask Maven plugin assessment questions before reading references
Run this XML-included question flow before reading any plugin/profile implementation reference. Ask one question at a time, wait for the user's answer, and record selected plugins, profiles, and conditional values before continuing.
Question 1: What type of Java project is this?
Options:
- Java Library (for publishing to Maven Central/Nexus)
- Java CLI Application (command-line tool)
- Java Microservice (Web service/REST API/Modular monolith)
- Serverless (AWS Lambdas, Azure Functions)
- Java POC (Proof of Concept)
- Other (specify)
Question 2: Which Java version does your project target?
Options:
- Java 17 (LTS - recommended for new projects)
- Java 21 (LTS - latest LTS version)
- Java 25 (LTS - latest LTS version)
- Other (specify version)
Question 3: What build and quality aspects are important for your project?
Options:
- Format source code (Spotless)
- Maven Enforcer
- Unit Testing (Surefire)
- Unit Testing Reports (Surefire Reports)
- Integration testing (Failsafe)
- Code coverage reporting (JaCoCo)
- Mutation testing (PiTest)
- Security vulnerability scanning (OWASP)
- Security static code analysis (SpotBugs, PMD)
- Sonar
- Dependency analysis (maven-dependency-plugin)
- Version management
- Container image build (Jib)
- JMH (Java Microbenchmark Harness)
- Maven Compiler
- Cyclomatic Complexity
Note: When "Cyclomatic Complexity" is selected, Step 20 will create a PMD ruleset file and profile. The ruleset location depends on project structure: src/main/pmd/pmd-cyclomatic-complexity.xml (mono-module) or pmd/pmd-cyclomatic-complexity.xml (multi-module).
Question 3.1 (conditional): What is your target container image for Jib?
Note: This question is only asked if "Container image build (Jib)" was selected in question 3.
- Example format:
gcr.io/my-project/my-app,docker.io/username/myimage, ormyimagefor local Docker - The image name will be used in the Jib plugin
<to><image>configuration
Question 4: What is your target coverage threshold?
Options:
- 70% (moderate)
- 80% (recommended)
- 90% (high)
- Custom percentage (specify)
Note: This question is only asked if "Code coverage reporting (JaCoCo)" was selected in question 3.
Question 5: Do you want to configure Sonar/SonarCloud integration?** (y/n)
Note: This question is only asked if "Static code analysis (SpotBugs, Sonar)" was selected in question 3.
If yes, please provide the following information:
Question 5.1: What is your Sonar organization identifier?
- For SonarCloud: This is typically your GitHub username or organization name
- For SonarQube: This is your organization key as configured in SonarQube
- Example:
my-github-userormy-company-org
Question 5.2: What is your Sonar project key?
- For SonarCloud: Usually in format
GITHUB_USER_REPOSITORY_NAME(e.g.,john-doe_my-java-project) - For SonarQube: Custom project key as defined in your SonarQube instance
- Must be unique within your Sonar organization
- Example:
john-doe_awesome-java-lib
Question 5.3: What is your Sonar project display name?
- Human-readable name for your project as it appears in Sonar dashboard
- Can contain spaces and special characters
- Example:
Awesome Java LibraryorMy Microservice API
Question 5.4: Which Sonar service are you using? (conditional)
Note: This question is only asked if Sonar configuration was enabled in question 5.
Options:
- SonarCloud (https://sonarcloud.io) - recommended for open source projects
- SonarQube Server (specify your server URL)
If SonarQube Server: Please provide your SonarQube server URL (e.g., https://sonar.mycompany.com)
After all applicable questions are answered, confirm the selections and map them to references:
- If Maven Compiler is selected, read
references/112-java-maven-plugins-maven-compiler-plugin.md. - If Maven Enforcer is selected, read
references/112-java-maven-plugins-maven-enforcer-plugin.md. - If Unit Testing (Surefire) is selected, read
references/112-java-maven-plugins-maven-surefire-plugin.md. - If Integration testing (Failsafe) is selected, read
references/112-java-maven-plugins-maven-failsafe-plugin.md. - If Unit Testing Reports (Surefire Reports) is selected, read
references/112-java-maven-plugins-maven-surefire-report-plugin.mdandreferences/112-java-maven-plugins-maven-jxr-plugin.md. - If Format source code (Spotless) is selected, read
references/112-java-maven-plugins-spotless-maven-plugin.md. - If Version management is selected, read
references/112-java-maven-plugins-versions-maven-plugin.md. - If build information tracking is selected, read
references/112-java-maven-plugins-git-commit-id-maven-plugin.md. - If the project is a Java Library, read
references/112-java-maven-plugins-flatten-maven-plugin.md. - If Container image build (Jib) is selected, read
references/112-java-maven-plugins-jib-maven-plugin.md. - If Dependency analysis is selected, read
references/112-java-maven-plugins-maven-dependency-plugin.md. - If Code coverage reporting (JaCoCo) is selected, read
references/112-java-maven-plugins-profile-jacoco.md. - If Mutation testing (PiTest) is selected, read
references/112-java-maven-plugins-profile-pitest.md. - If Security vulnerability scanning (OWASP) is selected, read
references/112-java-maven-plugins-profile-security.md. - If Security static code analysis (SpotBugs, PMD) is selected, read
references/112-java-maven-plugins-profile-static-analysis.md. - If Sonar is selected, read
references/112-java-maven-plugins-profile-sonar.md. - If JMH is selected, read
references/112-java-maven-plugins-profile-jmh.md. - If Cyclomatic Complexity is selected, read
references/112-java-maven-plugins-profile-cyclomatic-complexity.md. - Do not read or apply unselected plugin/profile references.
- Read selected references and add only selected configuration
Add selected plugins and profiles without removing existing ones, preserving project structure and compatibility. Add only the Maven properties, plugin configuration, profile configuration, reporting plugins, and support files required by the selected references.
- Summarize applied plugin setup
Report added plugins/profiles, rationale, and recommended follow-up commands or checks.
Reference
For detailed guidance, examples, and constraints, see:
- references/112-java-maven-plugins-maven-compiler-plugin.md
- references/112-java-maven-plugins-maven-enforcer-plugin.md
- references/112-java-maven-plugins-maven-surefire-plugin.md
- references/112-java-maven-plugins-maven-failsafe-plugin.md
- references/112-java-maven-plugins-maven-surefire-report-plugin.md
- references/112-java-maven-plugins-maven-jxr-plugin.md
- references/112-java-maven-plugins-spotless-maven-plugin.md
- references/112-java-maven-plugins-flatten-maven-plugin.md
- references/112-java-maven-plugins-versions-maven-plugin.md
- references/112-java-maven-plugins-git-commit-id-maven-plugin.md
- references/112-java-maven-plugins-jib-maven-plugin.md
- references/112-java-maven-plugins-maven-dependency-plugin.md
- [references/112-java-maven-plugins-profile-jacoco.md](references/112-j
Truncated for display — read the full file on GitHub.
Related Skills
LocalAI
49.4kLocalAI is the open-source AI engine. Run any model - LLMs, vision, voice, image, video - on any hardware. No GPU required.
algorithmic-art
177.9kCreating algorithmic art using p5.js with seeded randomness and interactive parameter exploration. Use this when users request creating art using code, generative art, algorithmic art, flow fields, or particle systems.
pptx
177.9kUse this skill any time a .pptx or .potx file is involved in any way — as input, output, or both. This includes: creating slide decks, pitch decks, or presentations; reading, parsing, or extracting text from any .pptx or .potx file (even if the extracted content will be used elsewhere, like in an em…
design
130.2kComprehensive design skill: brand identity, design tokens, UI styling, logo generation (55 styles, Gemini, Atlas Cloud, or MuAPI AI), corporate identity program (50 deliverables, CIP mockups), HTML presentations (Chart.js), banner design (22 styles, social/ads/web/print), icon design (15 styles, SVG…
Languages
Trust signals
From repository metadata: license, adoption, age and documentation. Not a code audit — see the Safety scan above for what the skill file itself contains.
