maven-tools
JVM dependency intelligence via Maven Tools MCP server. Use when the user asks about Maven or Gradle dependencies, JVM library versions, safe upgrades, CVEs, license risks, release history, or project dependency health. Use when reviewing `pom.xml`, `build.gradle`, `build.gradle.kts`, or Maven coordinates. Use when the user says 'check my dependencies', 'should I upgrade X', or 'is this version safe'. Use even when the user just pastes a `groupId:artifactId` coordinate without a verb.
What this skill does
# Maven Tools Use this skill to ground JVM dependency decisions in live Maven Central data. This is an execution skill. Use Maven Tools MCP first for dependency facts, then do the reasoning in-model. Assume Maven Tools MCP is already configured; only discuss setup if the tools are unavailable. ## When to Use Activate when the user asks about: - Java, Kotlin, Scala, or JVM dependencies - Maven, Gradle, `pom.xml`, `build.gradle`, or `build.gradle.kts` - latest versions, upgrades, CVEs, licenses, dependency age, or release history - whether a dependency is safe, current, stale, or worth upgrading ## Core Boundary Use Maven Tools MCP for version, security, license, freshness, and release-pattern facts from Maven Central. - Do the reasoning in-model: recommend next steps, call out risk, and separate safe-now actions from manual-review items. - Normalize dependency inputs to `groupId:artifactId` or `groupId:artifactId:version` as needed. - For recommendation questions, evaluate concrete candidates with Maven Tools first, then add documentation context before making a strong call. - Do not use Maven metadata alone to decide library popularity, framework fit, migration effort, or performance tradeoffs. ## Tool Selection Choose the narrowest tool that matches the request: | Intent | Tool | Default Parameters | |--------|------|--------------------| | latest version lookup | `get_latest_version` | `stabilityFilter: PREFER_STABLE` | | check exact version | `check_version_exists` | none | | bulk candidate check (no current versions) | `check_multiple_dependencies` | `stabilityFilter: PREFER_STABLE` | | upgrade analysis (with current versions) | `compare_dependency_versions` | `includeSecurityScan: true`, `stabilityFilter: STABLE_ONLY` | | age/freshness | `analyze_dependency_age` | use project-appropriate threshold | | maintenance signal | `analyze_release_patterns` | `monthsToAnalyze: 24` | | release history | `get_version_timeline` | `versionCount: 20` | | full project audit | `analyze_project_health` | `includeSecurityScan: true`, `includeLicenseScan: true`, `stabilityFilter: PREFER_STABLE` | Default to `analyze_project_health` when the user says "check my dependencies" or pastes a project dependency set. Use `check_multiple_dependencies` for candidate sets without current versions. Use `compare_dependency_versions` for upgrade decisions on current versions. Use `analyze_project_health` for broad audits, not every single dependency question. ## Workflow 1. Extract dependencies from user input or the build file 2. Pick the narrowest tool that answers the request 3. Report the result in decision-oriented language: - what is current - what changed - what is safe to do now - what needs manual review For upgrade questions, prefer `compare_dependency_versions` with: - `includeSecurityScan: true` - `stabilityFilter: STABLE_ONLY` Then interpret the result conservatively: - patch and minor updates are the default safe path - major updates should be treated as manual review unless the user explicitly wants a breaking upgrade When `compare_dependency_versions` returns `same_major_stable_fallback`: - treat the top-level major upgrade as the long-term path - treat the fallback as the safest immediate upgrade target - surface both, but recommend the fallback first for conservative maintenance workflows This is especially important for "safe update" or bot-like maintenance flows. If the user asks whether a dependency is safe: 1. use `compare_dependency_versions` when remediation guidance matters 2. use `analyze_release_patterns` when maintenance risk matters 3. combine the two instead of relying only on "latest version" checks ## Documentation Handoff When the answer needs migration guides, API details, or library usage patterns, add documentation context before giving a strong recommendation. Use this order: 1. use Maven Tools MCP first for dependency facts 2. if raw Context7 tools are available in the current tool list, use them directly 3. otherwise, if standalone Context7 tools are available, use them 4. otherwise, use `WebSearch` and `WebFetch` for official docs, release notes, and migration guides 5. if no documentation path is available, say dependency facts are available but deeper doc lookup is not Use this especially for: - major upgrades - migration planning - recommendation-style comparisons between candidate libraries ## Less Helpful / Out of Scope - private artifact repositories that are not mirrored through Maven Central - non-JVM ecosystems that do not use Maven coordinates - trivial one-off lookups where the exact dependency and decision are already obvious - recommendation questions driven mostly by ecosystem adoption or benchmarks unless you also add docs and broader research ## Setup Assumption Assume the user already has Maven Tools MCP configured. - `arvindand/maven-tools-mcp:latest` is the default when raw Context7 tools should be exposed through the same server - `arvindand/maven-tools-mcp:latest-noc7` is the clean option when documentation is handled separately Only discuss installation when the tools are unavailable. ## Recovery | Issue | Action | |-------|--------| | MCP tools unavailable | Tell the user Maven Tools MCP is not configured and point them to <https://github.com/arvindand/maven-tools-mcp>. Mention `:latest` when they want raw Context7 in the same server, or `:latest-noc7` when docs are handled separately. | | Dependency not found | Verify `groupId:artifactId` format and check whether the artifact is on Maven Central. | | Raw Context7 tools unavailable | Use standalone Context7 tools if available; otherwise fall back to `WebSearch` and `WebFetch`. | | No documentation path is available | Say dependency facts are available but deeper migration or API docs are not available in the current environment. | | Security scan is incomplete or slow | Use the partial result, say CVE data may be incomplete, and continue with version/maintenance guidance. | | Version type is unclear | Treat it as unstable and prefer a known stable release. | --- > **License:** MIT > **Requires:** [Maven Tools MCP server](https://github.com/arvindand/maven-tools-mcp) > **Pairs with:** [context7 skill](../context7/) or standalone Context7 tools for documentation-heavy follow-up
Related in AI Agents
skill-development
IncludedComprehensive meta-skill for creating, managing, validating, auditing, and distributing Claude Code skills and slash commands (unified in v2.1.3+). Provides skill templates, creation workflows, validation patterns, audit checklists, naming conventions, YAML frontmatter guidance, progressive disclosure examples, and best practices lookup. Use when creating new skills, validating existing skills, auditing skill quality, understanding skill architecture, needing skill templates, learning about YAML frontmatter requirements, progressive disclosure patterns, tool restrictions (allowed-tools), skill composition, skill naming conventions, troubleshooting skill activation issues, creating custom slash commands, configuring command frontmatter, using command arguments ($ARGUMENTS, $1, $2), bash execution in commands, file references in commands, command namespacing, plugin commands, MCP slash commands, Skill tool configuration, or deciding between skills vs slash commands. Delegates to docs-management skill for official documentation.
reprompter
IncludedTransform messy prompts into well-structured, effective prompts — single or multi-agent. Use when: "reprompt", "reprompt this", "clean up this prompt", "structure my prompt", rough text needing XML tags and best practices, "reprompter teams", "repromptception", "run with quality", "smart run", "smart agents", multi-agent tasks, audits, parallel work, anything going to agent teams. Don't use when: simple Q&A, pure chat, immediate execution-only tasks. See "Don't Use When" section for details. Outputs: Structured XML/Markdown prompt, quality score (before/after), optional team brief + per-agent sub-prompts, agent team output files. Success criteria: Single mode quality score ≥ 7/10; Repromptception per-agent prompt quality score 8+/10; all required sections present, actionable and specific.
adaptive-compaction
IncludedAdaptive add-on policy and recovery layer that decides WHEN to compact, prune, snapshot, or fork -- replacing fixed-percent auto-compaction across Claude Code, Codex, and MCP-capable hosts. Trigger on auto-compact timing or damage: "when should I compact", "is it safe to compact now or start a fresh session", "auto-compact fires too early/mid-task", "switching to an unrelated task but the window still has space", "context rot", "answers get worse the longer the session runs", "the agent forgot the plan or my decisions after it summarized", "add a layer on top that manages context without changing the agent", raising autoCompactWindow to give the policy room, or installing/tuning a cross-tool compaction policy or PreCompact hook -- even when "compaction" is never said but the problem is context-window pressure or post-summarization memory loss. Do NOT use to summarize a conversation, build RAG, write a summarization prompt (decides WHEN not HOW), or answer max-context-length trivia.
agent-skill-creator
IncludedCreate cross-platform agent skills from workflow descriptions. Activates when users ask to create an agent, automate a repetitive workflow, create a custom skill, or need advanced agent creation. Triggers on phrases like create agent for, automate workflow, create skill for, every day I have to, daily I need to, turn process into agent, need to automate, create a cross-platform skill, validate this skill, export this skill, migrate this skill. Supports single skills, multi-agent suites, transcript processing, template-based creation, interactive configuration, cross-platform export, and spec validation.
llm-wiki
IncludedUse when building or maintaining a persistent personal knowledge base (second brain) in Obsidian where an LLM incrementally ingests sources, updates entity/concept pages, maintains cross-references, and keeps a synthesis current. Triggers include "second brain", "Obsidian wiki", "personal knowledge management", "ingest this paper/article/book", "build a research wiki", "compound knowledge", "Memex", or whenever the user wants knowledge to accumulate across sessions instead of being re-derived by RAG on every query.
skill-master
IncludedAgent Skills authoring, evaluation, and optimization. Create, edit, validate, benchmark, and improve skills following the agentskills.io specification. Use when designing SKILL.md files, structuring skill folders (references, scripts, assets), ingesting external documentation into skills, running trigger evals, benchmarking skill quality, optimizing descriptions, or performing blind A/B comparisons. Keywords: agentskills.io, SKILL.md, skill authoring, eval, benchmark, trigger optimization.