Java / Spring source review
SkillSecuritySecurity review of Java code, dangerous sinks and Spring pitfalls. Load when reviewing a Java/ Spring codebase/PR, on .java source in scope, or "review this Java". Signals: pom.xml/build.gradle, Spring/Spring Boot, ObjectInputStream, XML parsers, Runtime.exec, JNDI/lookups.
Instructions available. Your AI can read the instructions. Execution depends on the setup they require.
Account requirements not reviewed. Check the skill instructions before use; ahel provides instructions and does not run this skill.
Add ahel to your AI once: Claude, ChatGPT, Cursor, Claude Code or Codex. Then ask it to use this.
Then ask your AI: use the Java / Spring source review skill
What this skill tells your AI
The instructions your AI receives, as published by noorqureshi/sploitagent in skills/code-review/code-review-java/SKILL.md and read by ahel’s review.
When it applies
Reviewing Java source, most often a Spring/Spring Boot service. Java's biggest hitters are deserialization, XXE-by-default, and expression-language injection — all high impact and all grep-able.
Why it works
Several Java APIs are unsafe by default (XML parsers resolve external entities; ObjectInputStream
instantiates arbitrary classes) and frameworks expose powerful expression languages (SpEL/OGNL) that
turn a string into code. Tracing the source to a request parameter or message body confirms reach.
Sinks & patterns (grep, then trace to user input)
- Deserialization:
ObjectInputStream.readObject, JacksonenableDefaultTyping/polymorphic types, XMLDecoder, SnakeYAMLnew Yaml().load, unsafereadValuewith type info → RCE gadgets. - XXE:
DocumentBuilderFactory,SAXParser,XMLInputFactory,TransformerFactorywithoutsetFeature(disallow-doctype)/secure-processing. - Command exec:
Runtime.getRuntime().exec,ProcessBuilderwith concatenated input. - Expression injection: SpEL (
SpelExpressionParser,@Value("#{...}")on input), OGNL (Struts), MVEL; template engines with unescaped output. - SQL/HQL:
Statement/string-built queries,createQuerywith concatenation. - SSRF:
URL.openConnection,RestTemplate,HttpClient,WebClienton user URLs. - JNDI:
InitialContext.lookup, log4j-style${jndi:...}(Log4Shell) reachable from input.
Framework specifics
- Spring: mass assignment via
@ModelAttribute/DataBinder(missingsetAllowedFields), exposed/unsecured Actuator endpoints,@RequestMappingpath traversal, permit-all misconfig inSecurityFilterChain, SpEL in@PreAuthorize. - Struts/older MVC: OGNL injection (S2-* CVEs).
Method
rgfor the sinks; trace to controller params, headers, or message consumers.- Check XML parser factory configuration everywhere XML is read.
- Review the Spring Security config for accidental
permitAll()/disabled CSRF on state-changing routes. - Confirm with
web-deserialization,web-xxe,web-ssrf, orweb-command-injection.
Gotchas
- Jackson is safe unless default/polymorphic typing is enabled — check for it specifically.
find-sec-bugs/CodeQL surface candidates; you still must prove input reaches the sink.- Log4Shell-style lookups can fire from headers (User-Agent, X-Forwarded-For), not just body.
References
OWASP Deserialization & XXE cheat sheets; SpEL/OGNL injection research; find-sec-bugs rules.
Signals
- GitHub stars
- 20
- Forks
- 7
- Last commit
- Sep 2026
Advanced
- Item type
- skill
- Key
code-review-java- Source
- github.com/noorqureshi/sploitagent
github.com/noorqureshi/sploitagent
Related picks
Skill · jabrena
The pick for Javajava-api-consistency-validator
Skill · arabelatso
The pick for Javaaudit-dependencies
Skill · stbenjam
The pick for Dependenciesreview-dependencies
Skill · tobihagemann
The pick for Dependenciesowasp-security
Skill · davila7
The pick for Web (OWASP)owasp-web
Skill · nahid-sparktales
The pick for Web (OWASP)