Agent skill

Laravel Security

by affaan-m in affaan-m/ECC

Laravel 安全最佳实践,涵盖认证/授权、验证、CSRF、批量赋值、文件上传、密钥管理、速率限制和安全部署. An agent skill from affaan-m/ECC.

MITAuto-check passedBackend & APIs

Install Laravel Security

skills CLI
$ npx skills add affaan-m/ECC --skill laravel-security -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install affaan-m/ECC laravel-security --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/affaan-m/ECC.git skills-src && mkdir -p .claude/skills && cp -r skills-src/docs/zh-CN/skills/laravel-security .claude/skills/laravel-security && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
laravel-security
GitHub stars
277k
Used in
1 other repo
Token cost
~1.3k tokens
SKILL.md length
164 words
Files
1
Skills in repo
683
Repo updated
First seen
Licence
MIT

At a glance

Laravel 安全最佳实践,涵盖认证/授权、验证、CSRF、批量赋值、文件上传、密钥管理、速率限制和安全部署. An agent skill from affaan-m/ECC.

  • Tasks that involve Backend development
  • SKILL.md covers 何时启用, 工作原理, 核心安全设置 and 会话和 Cookie 强化, plus 17 more sections
  • Calls composer; needs APP_KEY
  • Tasks that involve Web application vulnerabilities

What it does

Laravel Security is an agent skill from affaan-m/ECC. Laravel 安全最佳实践,涵盖认证/授权、验证、CSRF、批量赋值、文件上传、密钥管理、速率限制和安全部署。

Its SKILL.md is about 1.3k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Backend development and Web application vulnerabilities. It works with Laravel. The repository describes itself as: The agent harness performance optimization system. Skills, instincts, memory, security, and research-first development for Claude Code, Codex, Opencode, Cursor and beyond. The licence is MIT.

When your agent uses it

  • Tasks that involve Backend development
  • Tasks that involve Web application vulnerabilities

Example prompts

  • “/laravel-security”

Requirements

  • A credential in APP_KEY

What it can do on your machine

Read from SKILL.md and the folder at commit 2d515e4. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • composer

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • APP_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Laravel Security loads about 1.3k tokens when it runs. Until then it costs about 18 tokens; SKILL.md has 164 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~18
When it runs · the whole SKILL.md, loaded when a task matches
~1.3k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from affaan-m/ECC at commit 2d515e4, republished under its MIT licence (© affaan-m). 164 words, ~1,348 tokens.

Download SKILL.mdSave it as .claude/skills/laravel-security/SKILL.md (or your agent's skills folder).
name
laravel-security
description
Laravel 安全最佳实践,涵盖认证/授权、验证、CSRF、批量赋值、文件上传、密钥管理、速率限制和安全部署。
origin
ECC

Laravel 安全最佳实践

针对 Laravel 应用程序的全面安全指导,以防范常见漏洞。

何时启用

  • 添加身份验证或授权时
  • 处理用户输入和文件上传时
  • 构建新的 API 端点时
  • 管理密钥和环境设置时
  • 强化生产环境部署时

工作原理

  • 中间件提供基础保护(通过 VerifyCsrfToken 实现 CSRF,通过 SecurityHeaders 实现安全标头)。
  • 守卫和策略强制执行访问控制(auth:sanctum、$this->authorize、策略中间件)。
  • 表单请求在输入到达服务之前进行验证和整形(UploadInvoiceRequest)。
  • 速率限制在身份验证控制之外增加滥用保护(RateLimiter::for('login'))。
  • 数据安全来自加密转换、批量赋值保护以及签名路由(URL::temporarySignedRoute + signed 中间件)。

核心安全设置

  • 生产环境中设置 APP_DEBUG=false
  • APP_KEY 必须设置,并在泄露时轮换
  • 设置 SESSION_SECURE_COOKIE=true 和 SESSION_SAME_SITE=lax(对于敏感应用,使用 strict)
  • 配置受信任的代理以正确检测 HTTPS
  • 设置 SESSION_HTTP_ONLY=true 以防止 JavaScript 访问
  • 对高风险流程使用 SESSION_SAME_SITE=strict
  • 在登录和权限变更时重新生成会话

身份验证与令牌

  • 使用 Laravel Sanctum 或 Passport 进行 API 身份验证
  • 对于敏感数据,优先使用带有刷新流程的短期令牌
  • 在注销和账户泄露时撤销令牌

路由保护示例:

php
use Illuminate\Http\Request;
use Illuminate\Support\Facades\Route;

Route::middleware('auth:sanctum')->get('/me', function (Request $request) {
    return $request->user();
});

密码安全

  • 使用 Hash::make() 哈希密码,切勿存储明文
  • 使用 Laravel 的密码代理进行重置流程
php
use Illuminate\Support\Facades\Hash;
use Illuminate\Validation\Rules\Password;

$validated = $request->validate([
    'password' => ['required', 'string', Password::min(12)->letters()->mixedCase()->numbers()->symbols()],
]);

$user->update(['password' => Hash::make($validated['password'])]);

授权:策略与门面

  • 使用策略进行模型级授权
  • 在控制器和服务中强制执行授权
php
$this->authorize('update', $project);

使用策略中间件进行路由级强制执行:

php
use Illuminate\Support\Facades\Route;

Route::put('/projects/{project}', [ProjectController::class, 'update'])
    ->middleware(['auth:sanctum', 'can:update,project']);

验证与数据清理

  • 始终使用表单请求验证输入
  • 使用严格的验证规则和类型检查
  • 切勿信任请求负载中的派生字段

批量赋值保护

  • 使用 $fillable 或 $guarded,避免使用 Model::unguard()
  • 优先使用 DTO 或显式的属性映射

SQL 注入防范

  • 使用 Eloquent 或查询构建器的参数绑定
  • 除非绝对必要,避免使用原生 SQL
php
DB::select('select * from users where email = ?', [$email]);

XSS 防范

  • Blade 默认转义输出({{ }})
  • 仅对可信的、已清理的 HTML 使用 {!! !!}
  • 使用专用库清理富文本

CSRF 保护

  • 保持 VerifyCsrfToken 中间件启用
  • 在表单中包含 @csrf,并为 SPA 请求发送 XSRF 令牌

对于使用 Sanctum 的 SPA 身份验证,确保配置了有状态请求:

php
// config/sanctum.php
'stateful' => explode(',', env('SANCTUM_STATEFUL_DOMAINS', 'localhost')),

文件上传安全

  • 验证文件大小、MIME 类型和扩展名
  • 尽可能将上传文件存储在公开路径之外
  • 如果需要,扫描文件以查找恶意软件
php
final class UploadInvoiceRequest extends FormRequest
{
    public function authorize(): bool
    {
        return (bool) $this->user()?->can('upload-invoice');
    }

    public function rules(): array
    {
        return [
            'invoice' => ['required', 'file', 'mimes:pdf', 'max:5120'],
        ];
    }
}
php
$path = $request->file('invoice')->store(
    'invoices',
    config('filesystems.private_disk', 'local') // set this to a non-public disk
);

速率限制

  • 在身份验证和写入端点应用 throttle 中间件
  • 对登录、密码重置和 OTP 使用更严格的限制
php
use Illuminate\Cache\RateLimiting\Limit;
use Illuminate\Http\Request;
use Illuminate\Support\Facades\RateLimiter;

RateLimiter::for('login', function (Request $request) {
    return [
        Limit::perMinute(5)->by($request->ip()),
        Limit::perMinute(5)->by(strtolower((string) $request->input('email'))),
    ];
});

密钥与凭据

  • 切勿将密钥提交到源代码管理
  • 使用环境变量和密钥管理器
  • 密钥暴露后及时轮换,并使会话失效

加密属性

对静态的敏感列使用加密转换。

php
protected $casts = [
    'api_token' => 'encrypted',
];

安全标头

  • 在适当的地方添加 CSP、HSTS 和框架保护
  • 使用受信任的代理配置来强制执行 HTTPS 重定向

设置标头的中间件示例:

php
use Illuminate\Http\Request;
use Symfony\Component\HttpFoundation\Response;

final class SecurityHeaders
{
    public function handle(Request $request, \Closure $next): Response
    {
        $response = $next($request);

        $response->headers->add([
            'Content-Security-Policy' => "default-src 'self'",
            'Strict-Transport-Security' => 'max-age=31536000', // add includeSubDomains/preload only when all subdomains are HTTPS
            'X-Frame-Options' => 'DENY',
            'X-Content-Type-Options' => 'nosniff',
            'Referrer-Policy' => 'no-referrer',
        ]);

        return $response;
    }
}

CORS 与 API 暴露

  • 在 config/cors.php 中限制来源
  • 对于经过身份验证的路由,避免使用通配符来源
php
// config/cors.php
return [
    'paths' => ['api/*', 'sanctum/csrf-cookie'],
    'allowed_methods' => ['GET', 'POST', 'PUT', 'PATCH', 'DELETE'],
    'allowed_origins' => ['https://app.example.com'],
    'allowed_headers' => [
        'Content-Type',
        'Authorization',
        'X-Requested-With',
        'X-XSRF-TOKEN',
        'X-CSRF-TOKEN',
    ],
    'supports_credentials' => true,
];

日志记录与 PII

  • 切勿记录密码、令牌或完整的卡片数据
  • 在结构化日志中编辑敏感字段
php
use Illuminate\Support\Facades\Log;

Log::info('User updated profile', [
    'user_id' => $user->id,
    'email' => '[REDACTED]',
    'token' => '[REDACTED]',
]);

依赖项安全

  • 定期运行 composer audit
  • 谨慎固定依赖项版本,并在出现 CVE 时及时更新

签名 URL

使用签名路由生成临时的、防篡改的链接。

php
use Illuminate\Support\Facades\URL;

$url = URL::temporarySignedRoute(
    'downloads.invoice',
    now()->addMinutes(15),
    ['invoice' => $invoice->id]
);
php
use Illuminate\Support\Facades\Route;

Route::get('/invoices/{invoice}/download', [InvoiceController::class, 'download'])
    ->name('downloads.invoice')
    ->middleware('signed');

© affaan-m, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in docs/zh-CN/skills/laravel-security of affaan-m/ECC.

Open the folder on GitHubat commit 2d515e4

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in affaan-m/ECC, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Laravel Security next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Laravel Security compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Laravel Security this skillaffaan-m/ECC277k1 repos~1.3kAutomated safety check: PassMIT
Cashier Stripe Developmentluadotsh/lua3431 repos~1.2kAutomated safety check: PassMIT
Spa Auth Developmentgdarko/laravel-vue-starter145—~668Automated safety check: NotesMIT
Php Laravel Audit0xShe/PHP-Code-Audit-Skill4021 repos~821Automated safety check: PassNone
Laravel SecurityHoangNguyen0403/agent-skills-standard572—~887Automated safety check: PassMIT
Php Framework Auditwgpsec/AboutSecurity1.8k—~767Automated safety check: NotesNone

Similar skills

  • Handles Laravel Cashier Stripe integration including subscriptions, webhooks, Stripe Checkout, invoices, charges, refunds, trials, coupons, metered billing, and payment failure handling.

    343 GitHub starsUsed in 1 repo~1.2k tokens
    Backend & APIsAuto-check passed
  • Spa Auth Development

    gdarko/laravel-vue-starter

    Activate when working on SPA authentication flow, Sanctum cookie-based auth, Vue Router guards, auth store, login/register/password reset pages, or CORS/session configuration.

    145 GitHub stars~668 tokensUpdated 6 mo ago
    Backend & APIsAuto-check: notes
  • Php Laravel Audit

    0xShe/PHP-Code-Audit-Skill

    Laravel 框架特效安全审计工具。针对 Laravel 常见鉴权/CSRF/Session/模型填充/Blade 渲染等框架特性进行白盒静态审计,并将风险映射到你现有通用漏洞类型体系(AUTH/CSRF/LOGIC/XSS/CFG 等)。

    402 GitHub starsUsed in 1 repo~821 tokens
    Backend & APIsAuto-check passed
  • Laravel Security

    HoangNguyen0403/agent-skills-standard

    Harden Laravel apps with Policies for model authorization, Gate-based RBAC, validated mass assignment, and CSRF protection.

    572 GitHub stars~887 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Php Framework Audit

    wgpsec/AboutSecurity

    PHP 框架特定安全审计。当在 PHP 白盒审计中已识别目标使用特定框架、 需要检查框架特有安全机制和常见配置缺陷时触发。

    1.8k GitHub stars~767 tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • Runs and interprets Psalm security (taint) analysis on a Laravel project.

    230 GitHub stars~4.7k tokensUpdated 6 days ago
    SecurityAuto-check passed

More from affaan-m/ECC

All 682 skills in this repo
  • Skill Stocktake

    affaan-m/ECC

    Audits your installed Claude skills and commands for quality, with a quick mode for recently changed skills and a full mode that evaluates all of them through subagents.

    277k GitHub starsUsed in 5 repos~3.1k tokens
    Auto-check passed
  • Ingests, indexes, searches, edits and monitors video, audio and live streams through the VideoDB Python SDK, returning stream links, clips and timestamps.

    277k GitHub starsUsed in 3 repos~3.5k tokens
    Auto-check: notes
  • Docs Governance

    affaan-m/ECC

    Route broad documentation-governance requests to existing ECC skills and run an opt-in, read-only audit of mapped documentation roles, links, ADR indexes, and evidence references.

    277k GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Rules Distillation

    affaan-m/ECC

    Scans installed skills for principles that recur across them and proposes rule-file changes: append, revise, add a section, create a file or leave as covered.

    277k GitHub starsUsed in 2 repos~2.3k tokens
    Auto-check passed
  • Builds DRAFT counterparty agreements from one markdown template and a small JSON spec per party, with clauses picked by the party's role.

    277k GitHub stars~2.9k tokensUpdated today
    Auto-check passed
  • Set an ECC-specific frontend design direction for production UI work.

    277k GitHub starsUsed in 1 repo~2.2k tokens
    Auto-check passed

Works with

Categories

Questions about Laravel Security

What does Laravel Security do?

Laravel 安全最佳实践,涵盖认证/授权、验证、CSRF、批量赋值、文件上传、密钥管理、速率限制和安全部署. An agent skill from affaan-m/ECC. Laravel Security is an agent skill from affaan-m/ECC.

When should I use Laravel Security?

Laravel Security fits situations like: tasks that involve Backend development; tasks that involve Web application vulnerabilities.

How do I install Laravel Security in Claude Code?

Run `npx skills add affaan-m/ECC --skill laravel-security -a claude-code`. Or copy the skill folder (docs/zh-CN/skills/laravel-security in affaan-m/ECC) into .claude/skills/laravel-security in your project. Claude Code loads it when a task matches its description.

How do I install Laravel Security in Codex?

Run `npx skills add affaan-m/ECC --skill laravel-security -a codex`. Or copy the skill folder (docs/zh-CN/skills/laravel-security in affaan-m/ECC) into .agents/skills/laravel-security in your project. Codex loads it when a task matches its description.

Can I use Laravel Security in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add affaan-m/ECC --skill laravel-security -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/laravel-security, .gemini/skills/laravel-security, .github/skills/laravel-security and .opencode/skills/laravel-security in your project.

What does Laravel Security need to run?

Going by SKILL.md and its folder, Laravel Security needs the command-line tools its instructions call (composer) and credentials named APP_KEY. Our summary lists: A credential in APP_KEY.

Does Laravel Security access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Laravel Security safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Laravel Security use?

Laravel Security is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Laravel Security use?

About 1.3k tokens (SKILL.md is roughly 5.4k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Laravel Security?

Skills that share tags, products or a category with Laravel Security: Cashier Stripe Development (luadotsh/lua, 343 stars), Spa Auth Development (gdarko/laravel-vue-starter, 145 stars), Php Laravel Audit (0xShe/PHP-Code-Audit-Skill, 402 stars) and Laravel Security (HoangNguyen0403/agent-skills-standard, 572 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Laravel Security?

affaan-m (a GitHub user) maintains it in affaan-m/ECC, which has 276,673 GitHub stars. The repository holds 683 skills in this directory. The repository was last updated on October 11, 2026.

Source: affaan-m/ECC on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.