Laravel Security Best Practices
Harden Laravel with Muse: production config, Sanctum and Passport auth, Gates and Policies, Eloquent mass-assignment safety, CSRF, XSS, file uploads, and API security.
- What
- Harden Laravel with Muse: production config, Sanctum and Passport auth, Gates and Policies, Eloquent mass-assignment safety, CSRF, XSS, file uploads, and API security.
- Cost
- Free
- Needs
- Use "Laravel Security Best Practices" with your Muse.
- Install
- Copy the installer prompt below into your Muse — your agent does the rest.
Curated by Skill Harbor: a security hardening guide that makes Muse review a Laravel application against the framework's real security surface. It starts with production configuration (APP_DEBUG off, APP_KEY set and validated at boot, secure session cookies, HTTPS enforcement with correctly scoped trusted proxies), then covers authentication with Sanctum token abilities, Argon2/bcrypt password hashing, strong password rules with breach checking, and session regeneration on login. Authorization covers Gates with a super-admin before() hook, model Policies wired through controllers and Blade, and role middleware. Eloquent security is a highlight: fillable whitelisting instead of open guarded arrays, safe() and validated() over request all(), parameterized whereRaw, and hidden attributes for API responses. CSRF covers the VerifyCsrfToken middleware with careful webhook-only exemptions, XSS covers Blade auto-escaping and the dangerous raw echo with user input, input validation covers FormRequest rules with post-validation sanitization, and API security covers per-endpoint rate limiters, Sanctum versus Passport guidance, and CORS whitelisting. File uploads get MIME, size and dimension validation with private-disk storage and signed URLs, and the skill closes with composer audit in CI, secret management, encrypted queue payloads and a security event audit log. By @affaan-m, listed here with credit to its creator. From the affaan-m/ECC repository (MIT). Honest caveats: a checklist is not a pentest; never paste real secrets into a chat while using it; Sanctum versus Passport advice depends on your auth model, decide deliberately. Skill Harbor never reviews the code, review it yourself before use.
Version:
Install
Copy the install package below, then paste it into MuseThe install prompt below already includes the vetting steps: your agent follows the community checklist before installing anything with executable code. Want more?
Use "Laravel Security Best Practices" with your Muse. Prerequisites: none to install. Pure guidance; a Laravel project helps. 1. Open the skill: https://github.com/affaan-m/ECC/blob/main/skills/laravel-security/SKILL.md and copy the full SKILL.md text. 2. Paste it into a chat with Muse and add: "Audit this Laravel project against the security checklist: [paste config and key files, with secrets redacted]." 3. Work through the findings: production config, auth, Gates/Policies, Eloquent mass assignment, CSRF, XSS, uploads, API limits. Tip: ask "which three findings are the most dangerous and what is the exact fix for each?" Safety: a skill is plain-text instructions; it runs nothing by itself. Never paste real secrets into a chat. Review generated commands before running them.
Saved to your recent installs. Find it anytime on /connect.
Questions
How do I install a build?
Every product page includes a copy-paste install prompt. Paste it into your Muse and it sets the build up for you — no manual configuration.
Where does my money go?
Straight to the seller. Skill Harbor never processes payments: checkout happens on the seller’s own page, usually Stripe.
What does the ✓ next to a creator’s name mean?
It means we confirmed the identity of the person behind the listing. It says nothing about the code itself — always check a build before installing it.