skills/laravel/laravel-security/SKILL.md
Harden Laravel apps with Policies for model authorization, Gate-based RBAC, validated mass assignment, and CSRF protection. Use when creating authorization policies, securing env config access, or preventing mass assignment vulnerabilities.
npx skillsauth add hoangnguyen0403/agent-skills-standard laravel-securityInstall this skill globally with one command. Works with Claude Code, Cursor, and Windsurf.
3 of 9 scanners reported clean
Some scanners were skipped, did not run, or reported a non-clean status. Review each row below.
php artisan make:policy PostPolicy --model=Post.bool for view, update, delete actions.$this->authorize('update', $post).Gate::before() for admin users in AuthServiceProvider.$request->validated() for Model::create().See implementation examples for Policy class with controller authorization.
php artisan make:policy PostPolicy --model=Post for model-level authorization.update(User $user, Post $post): bool and call $this->authorize('update', $post) in controllers.Gate::define('admin', fn(User $user) => ...) for global permissions. Check with Gate::allows('admin') or Blade @can('admin'). prefer Policies for model-bound checks; use Gates for global permissions.Gate::before(fn($u) => $u->isAdmin() ? true : null) in AuthServiceProvider.config('app.key') in your application code. never env() in controllers; use config() instead.php artisan config:cache to validate that env() isn't used where it shouldn't .<form> tags. active on web routes by default; use ->except(['/webhook']) only for trusted third-party callbacks.Gate::before for admin bypass; or use spatie/laravel-permission; never inline $user->role === 'admin'.env() outside config files: Access via config() helper.validated().testing
Infer the requesting operator's technical fluency from message content (never ask directly) and adapt register — business, hybrid, or technical — across SDLC workflow output. Use when starting sdlc, brainstorm-feature, plan-feature, verify-work, publish-notes, or session-report, or whenever a request's phrasing signals a non-technical or cross-stack operator.
documentation
Define transaction boundaries, locking, and consistency guarantees for multi-step writes. Use when designing atomic operations, retries, idempotency, or concurrent write behavior.
development
Design relational or document schemas from access patterns, cardinality, and lifecycle. Use when modeling entities, choosing embed vs normalize, or shaping schema boundaries before implementation.
data-ai
Diagnose database latency with explain plans, index ownership, and query-shape review. Use when a query is slow, an index is missing, or scans and N+1 patterns appear.