Laravel security
Skill ComeOnOliver/skillshub/skills/HoangNguyen0403/agent-skills-standard/laravel-security
Security standards for hardening Laravel applications. Use when securing authentication, authorization, input validation, or CSRF in Laravel. (triggers: app/Policies/**/*.php, config/*.php, policy, gate, authorize, env, config)From its SKILL.md
npx -y skills add ComeOnOliver/skillshub --skill laravel-securityAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
SKILL.md
2.3 KB, 512 tokens by cl100k_base, as published. Nobody here has run it
Laravel Security
Priority: P0 (CRITICAL)
Structure
app/
├── Policies/ # Model-level permission
└── Http/
└── Middleware/ # Custom security layers
Implementation Guidelines
Authorization & RBAC
- Policies: Always use
php artisan make:policy PostPolicy --model=Postfor model-level authorization. - Checkers: Implement
update(User $user, Post $post): booland call$this->authorize('update', $post)in controllers. - Gates: Use
Gate::define('admin', fn(User $user) => ...)for global permissions. Check withGate::allows('admin')or Blade@can('admin'). prefer Policies for model-bound checks; use Gates for global permissions. - Admin Bypass: Define
Gate::before(fn($u) => $u->isAdmin() ? true : null)inAuthServiceProvider.
Configuration & Environment
- Environment: Only call env() inside config/*.php files. Access via
config('app.key')in your application code. never env() in controllers; use config() instead. - Caching: Run
php artisan config:cacheto validate thatenv()isn't used where it shouldn't be.
Data & Input Security
- Mass Assignment: Use Form Request with rules() and call $request->validated() for Model::create(). Define $fillable on model; never pass $request->all() to create().
- CSRF: Ensure the @csrf directive is in all Blade
<form>tags. active on web routes by default; use->except(['/webhook'])only for trusted third-party callbacks. - Role-Based Access: Use Policies with role checks in policy methods; define
Gate::beforefor admin bypass; or usespatie/laravel-permission; never inline $user->role === 'admin'.
Anti-Patterns
- No
env()outside config files: Access viaconfig()helper. - No custom auth logic: Use Laravel's built-in auth system.
- No unvalidated mass assignment: Always call
validated(). - No auth logic in Blade: Pass permissions as data from controller.
References
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.