Quarkus Verification Loop
Run the full Quarkus pre-PR gauntlet with Muse: build, static analysis, tests with JaCoCo coverage, OWASP dependency and container scans, GraalVM native compilation, health checks, config validation, docs review.
- What
- Run the full Quarkus pre-PR gauntlet with Muse: build, static analysis, tests with JaCoCo coverage, OWASP dependency and container scans, GraalVM native compilation, health checks, config validation, docs review.
- Cost
- Free
- Needs
- Use "Quarkus Verification Loop" with your Muse.
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor: a full verification loop for Quarkus services that makes Muse run the same gauntlet before every PR, after major refactors, and pre-deploy. Ten phases, from build to docs. Build uses mvn clean verify or the Gradle equivalent, stopping on the first compilation error. Static analysis chains Checkstyle, PMD, and SpotBugs, with an optional SonarQube pass, flagging unused imports, high cyclomatic complexity, and null-pointer risks. Tests come in three flavors, all spelled out: Mockito unit tests (with the Panache persist-is-void trap documented), Testcontainers integration tests with real Postgres, and REST Assured API tests for 201 and 400 cases, with JaCoCo enforcing 80 percent line and 70 percent branch coverage. Security scanning covers OWASP dependency-check CVEs, quarkus:audit for vulnerable extensions, ZAP API scans against the OpenAPI surface, plus a checklist of secrets in env vars, input validation, auth, CORS, security headers, BCrypt, parameterized queries, and rate limiting. Native compilation tests the GraalVM build with container-build, with troubleshooting for reflection, resources, and JNI. Then k6 load testing, health check probes on /q/health, container image build with Trivy and Grype scans, config validation per environment, and a docs review including OpenAPI regeneration. A single automated bash script chains the phases and a CI-ready GitHub Actions workflow is included. By @affaan-m, listed here with credit to its creator. From the affaan-m/ECC repository (MIT). Honest caveats: native compilation is slow and optional on every PR, run it periodically; coverage thresholds are a floor, not a guarantee. Skill Harbor never reviews the code, review it yourself before use.
Version:
Install
Copy the install package below, then paste it into MuseThe install prompt below already includes the vetting steps: your agent follows the community checklist before installing anything with executable code. Want more?
Use "Quarkus Verification Loop" with your Muse. Prerequisites: none to install. Pure guidance; a Quarkus Maven or Gradle project helps. Optional: k6, Docker, Trivy. 1. Open the skill: https://github.com/affaan-m/ECC/blob/main/skills/quarkus-verification/SKILL.md and copy the full SKILL.md text. 2. Paste it into a chat with Muse and add: "Run the verification loop on my Quarkus service: [describe the project, or say which phases to skip]." 3. Work through the phases with Muse, fixing issues before moving on. Ask for the final verification checklist at the end. Tip: for a fast PR check, run phases 1 to 4 only; save native compilation and load testing for pre-deploy. Safety: a skill is plain-text instructions; it runs nothing by itself. Review generated commands before running them.
Saved to your recent installs. Find it anytime on /connect.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.