All skills
asyrafhussin avatar

/laravel-owasp-security

@ac26821

OWASP Top 10 security audit and secure coding guidelines for Laravel + React/Inertia.js applications. Use when auditing for vulnerabilities ("run OWASP audit", "security review", "check my app security") or writing secure Laravel code involving auth, payments, file uploads, or API design. Triggers on security-related tasks, payment handling, authentication, or any request to audit a Laravel codebase.

Use this Skill: https://skilld.dev/gh/asyrafhussin/agent-skills/laravel-owasp-security

This session only. Nothing lands on disk.

README.md

≈543 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Laravel OWASP Security

OWASP Top 10 security audit and secure coding guidelines for Laravel 13 + React/Inertia.js applications.

Overview

This skill provides:

  • Full OWASP Top 10 security audit checklist mapped to Laravel 13 patterns
  • 6 React/Inertia.js-specific security checks (R1–R6)
  • Auto-detection of React + Inertia.js stack
  • PASS/FAIL/N/A audit output with file:line references
  • Secure coding reference with incorrect vs. correct PHP/TSX examples

Categories

OWASP Top 10 Checklist (A01–A10)

  1. Broken Access Control (A01:2021) — CRITICAL
  2. Cryptographic Failures (A02:2021) — CRITICAL
  3. Injection — SQL, Mass Assignment, XSS (A03:2021) — CRITICAL
  4. Insecure Design (A04:2021) — HIGH
  5. Security Misconfiguration (A05:2021) — HIGH
  6. Vulnerable & Outdated Components (A06:2021) — MEDIUM
  7. Identification & Authentication Failures + Session (A07:2021) — HIGH
  8. Software & Data Integrity Failures — CSRF + Deserialization (A08:2021) — HIGH
  9. Security Logging & Monitoring Failures (A09:2021) — MEDIUM
  10. Server-Side Request Forgery — SSRF (A10:2021) — HIGH

Additional Checks

  • Command Injection & Dangerous Functions
  • Security Headers

React + Inertia.js Checks (R1–R6)

  • R1. XSS in React Components
  • R2. Inertia.js Data Exposure (Critical)
  • R3. CSRF in Inertia.js
  • R4. Authentication State in React
  • R5. Sensitive Data in Browser
  • R6. Dependency Security

Usage

Run a security audit:

  • "Run OWASP audit on my Laravel app"
  • "Security review of app/Http/Controllers"
  • "Check my codebase for OWASP vulnerabilities"

Use as a secure coding reference:

  • "How do I safely handle file uploads in Laravel?"
  • "How do I prevent XSS in React with Inertia?"
  • "What is the correct way to pass data from Laravel to Inertia?"

References

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The analyzed skill is a security auditing and secure coding reference toolkit designed specifically for Laravel 13 + React/Inertia.js environments. It operates using standard pattern matching and reference documentation to provide static code reviews without executing external code or performing suspicious administrative operations. No safety violations or malicious behaviors were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    6/14 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at ac26821. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated 7 months ago
Other metadata
metadata
{
  "author": "AsyrafHussin",
  "version": "1.0.3",
  "laravelVersion": "13.x",
  "phpVersion": "8.3+"
}

README badge

README badge for asyrafhussin/agent-skills/laravel-owasp-security