Laravel security
Skill ComeOnOliver/skillshub/skills/HoangNguyen0403/agent-skills-standard/laravel-security
π§ The right skill, one API call. AI agent skills registry with token-efficient skill resolution. 5,000+ skills from 500+ top repos.
npx -y skills add ComeOnOliver/skillshub --skill laravel-securityAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
What its author says it does
Copied from the file, not written here
Security standards for hardening Laravel applications. Use when securing authentication, authorization, input validation, or CSRF in Laravel. (triggers: app/Policies/**/*.php, config/*.php, policy, gate, authorize, env, config)
SKILL.md
2.3 KB, as published. Nobody here has run it
Laravel Security
Priority: P0 (CRITICAL)
Structure
app/
βββ Policies/ # Model-level permission
βββ Http/
βββ Middleware/ # Custom security layers
Implementation Guidelines
Authorization & RBAC
- Policies: Always use
php artisan make:policy PostPolicy --model=Postfor model-level authorization. - Checkers: Implement
update(User $user, Post $post): booland call$this->authorize('update', $post)in controllers. - Gates: Use
Gate::define('admin', fn(User $user) => ...)for global permissions. Check withGate::allows('admin')or Blade@can('admin'). prefer Policies for model-bound checks; use Gates for global permissions. - Admin Bypass: Define
Gate::before(fn($u) => $u->isAdmin() ? true : null)inAuthServiceProvider.
Configuration & Environment
- Environment: Only call env() inside config/*.php files. Access via
config('app.key')in your application code. never env() in controllers; use config() instead. - Caching: Run
php artisan config:cacheto validate thatenv()isn't used where it shouldn't be.
Data & Input Security
- Mass Assignment: Use Form Request with rules() and call $request->validated() for Model::create(). Define $fillable on model; never pass $request->all() to create().
- CSRF: Ensure the @csrf directive is in all Blade
<form>tags. active on web routes by default; use->except(['/webhook'])only for trusted third-party callbacks. - Role-Based Access: Use Policies with role checks in policy methods; define
Gate::beforefor admin bypass; or usespatie/laravel-permission; never inline $user->role === 'admin'.
Anti-Patterns
- No
env()outside config files: Access viaconfig()helper. - No custom auth logic: Use Laravel's built-in auth system.
- No unvalidated mass assignment: Always call
validated(). - No auth logic in Blade: Pass permissions as data from controller.