/laravel-security
Harden Laravel apps with Policies for model authorization, Gate-based RBAC, validated mass assignment, and CSRF protection. Use when creating authorization policies, securing env config access, or preventing mass assignment vulnerabilities.
$ npx -y skills add hoangnguyen0403/agent-skills-standard --skill laravel-security --agent claude-codeHow it fires
How this skill gets triggered: by you, by Claude, or both.
- Fires itselfAuto-invocation. Claude auto-loads it when your prompt matches the work.Auto-invocation is when the right skill fires by itself at the right moment, driven by a FLOW.md router and a hook, instead of you invoking it by name. It is the difference between a skill being installed and a skill actually getting used.Read the full definition →
- You can call itInvoke it directly when you want it.
- Slash command
/laravel-security
Context preview
The summary Claude sees to decide when to auto-load this skill.
Harden Laravel apps with Policies for model authorization, Gate-based RBAC, validated mass assignment, and CSRF protection. Use when creating authorization policies, securing env config access, or preventing mass assignment vulnerabilities.
SKILL.md
laravel-security.SKILL.mdname: laravel-security
description: Harden Laravel apps with Policies for model authorization, Gate-based RBAC, validated mass assignment, and CSRF protection. Use when creating authorization policies, securing env config access, or preventing mass assignment vulnerabilities.
metadata:
triggers:
files:
- 'app/Policies/**/*.php'
- 'config/*.php'
keywords:
- policy
- gate
- authorize
- env
- configLaravel Security
**Priority: P0 (CRITICAL)**
Workflow: Secure Resource
1. **Generate policy** — `php artisan make:policy PostPolicy --model=Post`. 2. **Implement policy methods** — Return `bool` for `view`, `update`, `delete` actions. 3. **Authorize in controller** — Call `$this->authorize('update', $post)`. 4. **Add Gate bypass** — Define `Gate::before()` for admin users in `AuthServiceProvider`. 5. **Validate inputs** — Use Form Request with `$request->validated()` for `Model::create()`.
Policy Example
See [implementation examples](references/implementation.md#policy-example) for Policy class with controller authorization.
Implementation Guidelines
Authorization & RBAC
- **Policies**: Always use **`php artisan make:policy PostPolicy --model=Post`** for model-level authorization.
- **Checkers**: Implement **`update(User $user, Post $post): bool`** and call **`$this->authorize('update', $post)`** in controllers.
- **Gates**: Use `Gate::define('admin', fn(User $user) => ...)` for global permissions. Check with `Gate::allows('admin')` or Blade `@can('admin')`. prefer Policies for model-bound checks; use Gates for global permissions.
- **Admin Bypass**: Define **`Gate::before(fn($u) => $u->isAdmin() ? true : null)`** in **`AuthServiceProvider`**.
Configuration & Environment
- **Environment**: Only call env() inside config/\*.php files. Access via `config('app.key')` in your application code. **Never env() in controllers**; use config() instead.
- **Caching**: Run **`php artisan config:cache`** to validate that `env()` isn't used where it shouldn't .
Data & Input Security
- **Mass Assignment**: Use Form Request with rules() and call $request->validated() for Model::create(). Define $fillable on model; never pass $request->all() to create().
- **CSRF**: Ensure @csrf directive in all Blade `<form>` tags. active on web routes by default; use `->except(['/webhook'])` only for trusted third-party callbacks.
- **Role-Based Access**: Use Policies with role checks in policy methods; define `Gate::before` for admin bypass; or use `spatie/laravel-permission`; never inline $user->role === 'admin'.
Anti-Patterns
- **No `env()` outside config files**: Access via `config()` helper.
- **No custom auth logic**: Use Laravel's built-in auth system.
- **No unvalidated mass assignment**: Always call `validated()`.
- **No auth logic in Blade**: Pass permissions as data from controller.
References
- [Policy & Env Best Practices](references/implementation.md)
Configuration boundary
- Read environment values only in configuration files; application code uses `config('app.key')`, never `env()` in controllers.
Canonical response anchors
When this skill applies, preserve the following domain terminology or equivalent concrete examples in the answer when relevant:
- configuration files,only in configuration,Do not call `env()
- @can('admin')
- never env() in controllers,use config() in controllers,not in controllers
- web routes,web middleware,CSRF middleware
- Additional task-grounded exact anchors: config('app.key')
Read more
name: laravel-security
description: Harden Laravel apps with Policies for model authorization, Gate-based RBAC, validated mass assignment, and CSRF protection. Use when creating authorization policies, securing env config access, or preventing mass assignment vulnerabilities.
metadata:
triggers:
files:
- 'app/Policies/**/*.php'
- 'config/*.php'
keywords:
- policy
- gate
- authorize
- env
- configLaravel Security
**Priority: P0 (CRITICAL)**
Workflow: Secure Resource
1. **Generate policy** — `php artisan make:policy PostPolicy --model=Post`. 2. **Implement policy methods** — Return `bool` for `view`, `update`, `delete` actions. 3. **Authorize in controller** — Call `$this->authorize('update', $post)`. 4. **Add Gate bypass** — Define `Gate::before()` for admin users in `AuthServiceProvider`. 5. **Validate inputs** — Use Form Request with `$request->validated()` for `Model::create()`.
Policy Example
See [implementation examples](references/implementation.md#policy-example) for Policy class with controller authorization.
Implementation Guidelines
Authorization & RBAC
- **Policies**: Always use **`php artisan make:policy PostPolicy --model=Post`** for model-level authorization.
- **Checkers**: Implement **`update(User $user, Post $post): bool`** and call **`$this->authorize('update', $post)`** in controllers.
- **Gates**: Use `Gate::define('admin', fn(User $user) => ...)` for global permissions. Check with `Gate::allows('admin')` or Blade `@can('admin')`. prefer Policies for model-bound checks; use Gates for global permissions.
- **Admin Bypass**: Define **`Gate::before(fn($u) => $u->isAdmin() ? true : null)`** in **`AuthServiceProvider`**.
Configuration & Environment
- **Environment**: Only call env() inside config/\*.php files. Access via `config('app.key')` in your application code. **Never env() in controllers**; use config() instead.
- **Caching**: Run **`php artisan config:cache`** to validate that `env()` isn't used where it shouldn't .
Data & Input Security
- **Mass Assignment**: Use Form Request with rules() and call $request->validated() for Model::create(). Define $fillable on model; never pass $request->all() to create().
- **CSRF**: Ensure @csrf directive in all Blade `<form>` tags. active on web routes by default; use `->except(['/webhook'])` only for trusted third-party callbacks.
- **Role-Based Access**: Use Policies with role checks in policy methods; define `Gate::before` for admin bypass; or use `spatie/laravel-permission`; never inline $user->role === 'admin'.
Anti-Patterns
- **No `env()` outside config files**: Access via `config()` helper.
- **No custom auth logic**: Use Laravel's built-in auth system.
- **No unvalidated mass assignment**: Always call `validated()`.
- **No auth logic in Blade**: Pass permissions as data from controller.
References
- [Policy & Env Best Practices](references/implementation.md)
Configuration boundary
- Read environment values only in configuration files; application code uses `config('app.key')`, never `env()` in controllers.
Canonical response anchors
When this skill applies, preserve the following domain terminology or equivalent concrete examples in the answer when relevant:
- configuration files,only in configuration,Do not call `env()
- @can('admin')
- never env() in controllers,use config() in controllers,not in controllers
- web routes,web middleware,CSRF middleware
- Additional task-grounded exact anchors: config('app.key')
The portable SDLC standards layer for AI coding agents. Sync once, then work in your own runtime.
Repo: hoangnguyen0403/agent-skills-standard
Other skills on agent-skills-standard.
- /android-agp-upgrade
Upgrade an Android project to Android Gradle Plugin (AGP) 9. Use when migrating to AGP 9, updating Gradle build files, migrating to built-in Kotlin, or adopting the new AGP DSL.
Open skill - /android-architecture
Apply Clean Architecture layering, modularization, and Unidirectional Data Flow in Android projects. Use when setting up project structure, placing code in layers, configuring feature/core modules, or implementing UDF patterns; defer Compose state and ViewModel/StateFlow
Open skill - /android-background-work
Implement WorkManager and background processing correctly on Android. Use when creating Worker classes, scheduling tasks, choosing between WorkManager and Foreground Services, or setting up Hilt in workers; defer FCM and notification delivery to android-notifications.
Open skill - /android-compose-migration
Migrate an Android XML View to Jetpack Compose following a structured 10-step workflow. Use when converting XML layouts to Compose, setting up Compose in an existing View-based project, or incrementally adopting Compose.
Open skill - /android-compose
Build high-performance declarative UI with Jetpack Compose. Use when writing Composable functions, optimizing recomposition, hoisting state, or working with LazyColumn and side effects; defer deep-link and navigation routing to android-navigation.
Open skill - /android-concurrency
Write correct coroutine scopes, lifecycle collection, and dispatcher injection in Android production code. Use for suspend functions, coroutine scopes, and dispatcher mechanics; defer ViewModel StateFlow/LiveData architecture, Fragment lifecycle recipes,
Open skill

