Skip to content
Development
Skill

/api-platform-security

Secure API Platform resources with security expressions, voters, securityPostValidation, and operation-level access control

From plugin
dev-toolings-superpowers-symfony
18744 skills7 agents13 commands1 hook
Install
$ npx -y skills add dev-toolings/superpowers-symfony --skill api-platform-security --agent claude-code

How it fires

How this skill gets triggered: by you, by Claude, or both.

  • Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
  • You can call itInvoke it directly when you want it.
  • Slash command/api-platform-security

Context preview

The summary Claude sees to decide when to auto-load this skill.

Secure API Platform resources with security expressions, voters, securityPostValidation, and operation-level access control

SKILL.md

api-platform-security.SKILL.md
name: symfony:api-platform-security
allowed-tools:
  - Read
  - Write
  - Edit
  - Bash
  - Glob
  - Grep
description: Secure API Platform resources with security expressions, voters, securityPostValidation, and operation-level access control

Api Platform Security (Symfony)

Use when

  • Designing or evolving API Platform contracts and operations.
  • Aligning serialization, validation, and security behavior.

Default workflow

1. Define operation-level contract and payload boundaries. 2. Implement resource/DTO/provider/processor changes with explicit mapping. 3. Apply operation-specific validation and security constraints. 4. Validate functional behavior across happy and negative paths.

Guardrails

  • Keep API contract explicit and version-aware.
  • Avoid exposing internal entity fields implicitly.
  • Prevent drift between docs and actual serialization.

Progressive disclosure

  • Use this file for execution posture and risk controls.
  • Open references when deep implementation details are needed.

Output contract

  • API artifacts changed (resource/DTO/provider/processor).
  • Contract/security decisions and rationale.
  • Functional verification results.

References

  • `reference.md`
  • `docs/complexity-tiers.md`
Ships withdev-toolings-superpowers-symfony

Symfony AI development superpowers for Claude Code. 44 expert skills, 7 specialized subagents, and 13 slash commands covering API Platform v4, Doctrine ORM 3, TDD with Pest & PHPUnit, Symfony Messenger, security/voters, and DDD / hexagonal architecture.

Get the whole plugin