Agent skill

Laraveldaily Permissions Audit

by LaravelDaily in LaravelDaily/AI-Workflows-For-Laravel

This skill should be used when the user asks to "audit Laravel permissions", "review roles and permissions", "check authorization code", "find permission issues", "permissions review", "audit access…

No licenceAuto-check passedBackend & APIs

Install Laraveldaily Permissions Audit

skills CLI
$ npx skills add LaravelDaily/AI-Workflows-For-Laravel --skill laraveldaily-permissions-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install LaravelDaily/AI-Workflows-For-Laravel laraveldaily-permissions-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/LaravelDaily/AI-Workflows-For-Laravel.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/laraveldaily-permissions-audit .claude/skills/laraveldaily-permissions-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
laraveldaily-permissions-audit
GitHub stars
136
Token cost
~5.2k tokens
SKILL.md length
2,670 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
None found

At a glance

This skill should be used when the user asks to "audit Laravel permissions", "review roles and permissions", "check authorization code", "find permission issues", "permissions review", "audit access…

  • Works in 12 steps: UI-Only Authorization Without Backend… → Inline Role/Permission Checks Instead of… → Checking Roles Instead of Permissions → …
  • Asks to audit Laravel permissions
  • SKILL.md covers What to Check, Output Format and Important Guidelines
  • Calls php

What it does

Laraveldaily Permissions Audit is an agent skill from LaravelDaily/AI-Workflows-For-Laravel. This skill should be used when the user asks to "audit Laravel permissions", "review roles and permissions", "check authorization code", "find permission issues", "permissions review", "audit access control", or wants to analyze a Laravel project's roles/permissions implementation for improvements. Scans all PHP source files and reports findings with actionable suggestions.

Its SKILL.md is about 5.2k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Authorization and RBAC and Backend development. It works with Laravel and PHP.

When your agent uses it

  • Asks to audit Laravel permissions
  • Review roles and permissions
  • Check authorization code
  • Find permission issues

Example prompts

  • “audit Laravel permissions”
  • “review roles and permissions”
  • “check authorization code”
  • “/laraveldaily-permissions-audit”

Workflow steps

12 steps, taken from the step headings in SKILL.md.

  1. UI-Only Authorization Without Backend Protection
  2. Inline Role/Permission Checks Instead of Policies
  3. Checking Roles Instead of Permissions
  4. Boolean is_admin Column When Multiple Roles Exist
  5. Hardcoded Role/Permission Strings Without Enums
  6. Missing Data Scoping (Authorization Without Query Filtering)
  7. Missing Authorization Middleware on Routes
  8. Overly Complex Role System for Simple Needs
  9. Multiple Authenticatable Models Instead of Roles
  10. Spatie Teams Middleware Not Prioritized Correctly
  11. Missing Authorization Tests
  12. Registration/Onboarding Missing Default Role Assignment

What it can do on your machine

Read from SKILL.md and the folder at commit 4bff3b6. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • php

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Laraveldaily Permissions Audit loads about 5.2k tokens when it runs. Until then it costs about 102 tokens; SKILL.md has 2,670 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~102
When it runs · the whole SKILL.md, loaded when a task matches
~5.2k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 2,670 words (~5,199 tokens).

“Analyze a Laravel project's roles, permissions, and authorization implementation. Scan all PHP source files (excluding vendor/, node_modules/, storage/) and produce a structured report of findings with actionable suggestions.”

— opening of SKILL.md by LaravelDaily
name
laraveldaily-permissions-audit

Read the full SKILL.md on GitHub

Files

Just SKILL.md in skills/laraveldaily-permissions-audit of LaravelDaily/AI-Workflows-For-Laravel.

Open the folder on GitHubat commit 4bff3b6

Compare with similar skills

Laraveldaily Permissions Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Laraveldaily Permissions Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Laraveldaily Permissions Audit this skillLaravelDaily/AI-Workflows-For-Laravel136—~5.2kAutomated safety check: PassNone
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT
Tyrohasinhayder/tyro685—~1.4kAutomated safety check: PassMIT
Laravel SecurityHoangNguyen0403/agent-skills-standard572—~887Automated safety check: PassMIT
Php Framework Auditwgpsec/AboutSecurity1.8k—~767Automated safety check: NotesNone
Fortify Developmentcoollabsio/coolify63k4 repos~1.9kAutomated safety check: PassMIT

Similar skills

  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Tyro

    hasinhayder/tyro

    Framework-maintainer skill for the Tyro Laravel authorization package

    685 GitHub stars~1.4k tokensUpdated 1 mo ago
    Backend & APIsAuto-check passed
  • Laravel Security

    HoangNguyen0403/agent-skills-standard

    Harden Laravel apps with Policies for model authorization, Gate-based RBAC, validated mass assignment, and CSRF protection.

    572 GitHub stars~887 tokensUpdated yesterday
    Backend & APIsAuto-check passed
  • Php Framework Audit

    wgpsec/AboutSecurity

    PHP 框架特定安全审计。当在 PHP 白盒审计中已识别目标使用特定框架、 需要检查框架特有安全机制和常见配置缺陷时触发。

    1.8k GitHub stars~767 tokensUpdated yesterday
    Backend & APIsAuto-check: notes
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed
  • Laravel Best Practices

    anonaddy/anonaddy

    Apply this skill whenever writing, reviewing, or refactoring Laravel PHP code.

    4.9k GitHub starsUsed in 13 repos~1.2k tokens
    Backend & APIsAuto-check passed

More from LaravelDaily/AI-Workflows-For-Laravel

  • Laraveldaily Testing Audit

    LaravelDaily/AI-Workflows-For-Laravel

    This skill should be used when the user asks to "audit Laravel tests", "review test coverage", "check testing practices", "find missing tests", "testing review", "improve tests", or wants to analyze…

    136 GitHub stars~4.6k tokensUpdated 5 mo ago
    Auto-check: notes
  • Laraveldaily Queues Audit

    LaravelDaily/AI-Workflows-For-Laravel

    This skill should be used when the user asks to "audit Laravel queues", "review queue implementation", "check job code", "find queue issues", "queue review", or wants to analyze a Laravel project's…

    136 GitHub stars~4.9k tokensUpdated 5 mo ago
    Auto-check passed
  • Laraveldaily Structure Audit

    LaravelDaily/AI-Workflows-For-Laravel

    This skill should be used when the user asks to "audit Laravel project structure", "review project architecture", "check code organization", "find over-engineering", "find fat controllers"…

    136 GitHub stars~4.6k tokensUpdated 5 mo ago
    Auto-check passed
  • Laraveldaily API Audit

    LaravelDaily/AI-Workflows-For-Laravel

    This skill should be used when the user asks to "audit Laravel API", "review API architecture", "check API code", "find API issues", "API review", or wants to analyze a Laravel API project for…

    136 GitHub stars~5.6k tokensUpdated 5 mo ago
    Auto-check passed
  • Laraveldaily Eloquent Audit

    LaravelDaily/AI-Workflows-For-Laravel

    This skill should be used when the user asks to "audit Eloquent code", "review Eloquent usage", "check model code", "find N+1 queries", "find query performance issues", "Eloquent review", or wants…

    136 GitHub stars~6.5k tokensUpdated 5 mo ago
    Auto-check passed
  • Laraveldaily Production Readiness Audit

    LaravelDaily/AI-Workflows-For-Laravel

    Perform a comprehensive security audit of all project files in the current working directory.

    136 GitHub stars~1.9k tokensUpdated 5 mo ago
    Auto-check: notes

Works with

Categories

Questions about Laraveldaily Permissions Audit

What does Laraveldaily Permissions Audit do?

This skill should be used when the user asks to "audit Laravel permissions", "review roles and permissions", "check authorization code", "find permission issues", "permissions review", "audit access…. Laraveldaily Permissions Audit is an agent skill from LaravelDaily/AI-Workflows-For-Laravel. This skill should be used when the user asks to "audit Laravel permissions", "review roles and permissions", "check authorization code", "find permission issues", "permissions review", "audit access control", or wants to analyze a Laravel project's roles/permissions implementation for improvements.

When should I use Laraveldaily Permissions Audit?

Laraveldaily Permissions Audit fits situations like: asks to audit Laravel permissions; review roles and permissions; check authorization code; find permission issues.

How do I install Laraveldaily Permissions Audit in Claude Code?

Run `npx skills add LaravelDaily/AI-Workflows-For-Laravel --skill laraveldaily-permissions-audit -a claude-code`. Or copy the skill folder (skills/laraveldaily-permissions-audit in LaravelDaily/AI-Workflows-For-Laravel) into .claude/skills/laraveldaily-permissions-audit in your project. Claude Code loads it when a task matches its description.

How do I install Laraveldaily Permissions Audit in Codex?

Run `npx skills add LaravelDaily/AI-Workflows-For-Laravel --skill laraveldaily-permissions-audit -a codex`. Or copy the skill folder (skills/laraveldaily-permissions-audit in LaravelDaily/AI-Workflows-For-Laravel) into .agents/skills/laraveldaily-permissions-audit in your project. Codex loads it when a task matches its description.

Can I use Laraveldaily Permissions Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add LaravelDaily/AI-Workflows-For-Laravel --skill laraveldaily-permissions-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/laraveldaily-permissions-audit, .gemini/skills/laraveldaily-permissions-audit, .github/skills/laraveldaily-permissions-audit and .opencode/skills/laraveldaily-permissions-audit in your project.

What does Laraveldaily Permissions Audit need to run?

Going by SKILL.md and its folder, Laraveldaily Permissions Audit needs the command-line tools its instructions call (php).

Does Laraveldaily Permissions Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Laraveldaily Permissions Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Laraveldaily Permissions Audit use?

No licence was found for Laraveldaily Permissions Audit or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Laraveldaily Permissions Audit use?

About 5.2k tokens (SKILL.md is roughly 21k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Laraveldaily Permissions Audit?

Skills that share tags, products or a category with Laraveldaily Permissions Audit: Configuring Horizon (coollabsio/coolify, 63k stars), Tyro (hasinhayder/tyro, 685 stars), Laravel Security (HoangNguyen0403/agent-skills-standard, 572 stars) and Php Framework Audit (wgpsec/AboutSecurity, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Laraveldaily Permissions Audit?

LaravelDaily (a GitHub user) maintains it in LaravelDaily/AI-Workflows-For-Laravel, which has 136 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on April 15, 2026.

Source: LaravelDaily/AI-Workflows-For-Laravel on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.