All skills
asyrafhussin avatar

/laravel-owasp-security

@ac26821

OWASP Top 10 security audit and secure coding guidelines for Laravel + React/Inertia.js applications. Use when auditing for vulnerabilities ("run OWASP audit", "security review", "check my app security") or writing secure Laravel code involving auth, payments, file uploads, or API design. Triggers on security-related tasks, payment handling, authentication, or any request to audit a Laravel codebase.

Use this Skill: https://skilld.dev/gh/asyrafhussin/agent-skills/laravel-owasp-security

This session only. Nothing lands on disk.

rules_template.md

≈416 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Rule Title Here

Impact: HIGH (optional impact description)

Brief explanation of the rule and why it matters in Laravel 13 + React/Inertia.js applications. Explain the security implications, what an attacker could do if this rule is violated, and which OWASP category it maps to.

Why It Matters

  • Risk: What can an attacker do if this rule is violated?
  • Impact: What is the consequence for the application or its users?
  • OWASP: Which OWASP Top 10 category this maps to

Incorrect

<?php

// ❌ Bad code example — shows the vulnerable pattern
class BadExample
{
    public function vulnerableMethod(Request $request)
    {
        // This demonstrates what NOT to do
        // Include a realistic example showing the vulnerability
    }
}

Problems:

  • Specific vulnerability 1
  • Specific vulnerability 2

Correct

<?php

declare(strict_types=1);

// ✅ Good code example — shows the secure pattern
class GoodExample
{
    public function secureMethod(Request $request): ReturnType
    {
        // This demonstrates the correct approach
        // Using Laravel 13 and PHP 8.3+ features
    }
}

Why this is safe:

  • Specific security benefit 1
  • Specific security benefit 2

Recommended Patterns

Pattern Use Case
Pattern 1 When to use
Pattern 2 When to use

Reference: OWASP Laravel Cheat Sheet

Source: SKILL.md on GitHub

1 warning16d5 checks · Risk SAFE
  • Gen Agent Trust Hub16d

    The analyzed skill is a security auditing and secure coding reference toolkit designed specifically for Laravel 13 + React/Inertia.js environments. It operates using standard pattern matching and reference documentation to provide static code reviews without executing external code or performing suspicious administrative operations. No safety violations or malicious behaviors were detected.

  • Socket16d

    No alerts

  • Snyk16d

    Risk: LOW · No issues

  • Runlayer6mo

    6/14 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at ac26821. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated 7 months ago
Other metadata
metadata
{
  "author": "AsyrafHussin",
  "version": "1.0.3",
  "laravelVersion": "13.x",
  "phpVersion": "8.3+"
}

README badge

README badge for asyrafhussin/agent-skills/laravel-owasp-security