Works with the AI tools you already use

    Claude CodeClaude CodeCursorCursorCodex CLICodex CLIMuseMuseDotsDots+22 more

    Laravel Security Hardening Review

    1

    Turn a Laravel codebase into a severity-ranked, exploit-traced security report with Laravel-native fixes your team can ship before release.

    Free

    1 installSecurity scanned
    Laravel Security Hardening Review

    Laravel Security Hardening Review

    Example session with this skill installed

    We're a week from launching a multi-tenant Laravel 11 SaaS and I need a pre-release security review. The code is in ./api — check routes/api.php, the PostController and BillingController, the User and Invoice models, all form requests, and .env.production. I'm especially worried about the invoice file upload endpoint and the reporting endpoints that take a user-supplied sort column. Give me severity-ranked findings with exact file references and the smallest Laravel-native fix for each, plus a short list of anything that must be fixed before we accept production traffic.

    • Read your context and instructions
    • Compiled the laravel security hardening
    • Generated the document

    Summary

    Security review of shopfront-api (Laravel 11, multi-tenant): 14 findings across 9 entry points — 2 critical, 4 high. All fixes are Laravel-native and fit in one PR cycle; authorization and upload issues should ship before the next deploy.

    SeverityFindingLocationFix
    CriticalDebug mode + .env web-exposed.env.production, public/APP_DEBUG=false, move env out of docroot
    Highcreate($request->all()) allows role/tenant_id injectionUserController::storeWhitelist via FormRequest::validated()
    HighInvoice lookup by ID without tenant scoping (IDOR)InvoiceController::showInvoice::where('tenant_id', $user->tenant_id)->findOrFail($id)
    HighUser-controlled sort column into orderByRawReportControllermatch() whitelist for sort + direction
    MediumInvoice uploads to public disk with original filenameUploadControllerPrivate disk + Str::uuid() filenames
    MediumNo throttle:api on password resetroutes/auth.phpAdd throttle + single-use tokens

    Next steps

    • Merge PR #482 (critical + high fixes) and re-run this audit pre-release
    • Add policy coverage to Post and Invoice models; enforce in CI
    • Purge PII from queued job payloads; pass model IDs instead
    • Re-audit webhooks and Sanctum token scopes after the next sprint

    laravel-security-hardening-review.pdf

    PDF · document

    Generated

    Example file from a real run - the skill writes it into your workspace.

    Connects securely to your tools. The creator never sees your data.

    About this skill

    Laravel applications often ship with hidden vulnerabilities in trust boundaries, request handling, and authorization. This skill transforms your Laravel codebase into a severity-ranked, exploit-traced security report with framework-native fixes.

    What it does

    • Vulnerability discovery identifies missing authorization checks, object ID enumeration, and mass assignment risks.
    • Input trust analysis reviews form requests, validation rules, and raw SQL interpolation.
    • Auth audit inspects login flows, session safety, and token revocation strategies.
    • Infrastructure hardening checks for .env exposure, debug mode leaks, and CORS misconfigurations.
    • Native remediation provides concise, idiomatic Laravel code fixes for every finding.

    How it works

    1. App Mapping defines the application type and maps all external entry points like routes, webhooks, and queues.
    2. Input Tracing follows untrusted data from query strings or JSON bodies to sensitive sinks like the database or file system.
    3. Severity Ranking categorizes findings from Critical to Informational based on real-world exploitability.
    4. Fix Generation outputs a prioritized remediation report with specific code examples for your team.

    Frameworks & tools

    Laravel 8.x through 11.x, Eloquent ORM, Laravel Sanctum, Blade templating, and PHP 8.x security standards.

    Why this beats prompting it yourself

    Generic security prompts often suggest unnecessary third-party packages or ignore Laravel features like Policy-based authorization and FormRequests. This skill uses the framework's own architecture to secure the app, ensuring fixes are maintainable and idiomatic.

    Use cases

    • Auditing a legacy Laravel app before a major version upgrade.
    • Performing a pre-release security checklist for new API endpoints.
    • Reviewing third-party integrations, webhooks, and queued jobs for data leaks.
    • Training junior developers by showing exploit paths in their PRs.

    Known limitations

    This skill focuses on the Laravel application layer. It does not audit low-level server OS hardening, network firewalls, or third-party PHP packages outside the Laravel ecosystem.

    How to install

    Works the same in every agent - Claude, Cursor, Codex, Copilot and 20+ more.

    ~30 seconds
    1. 1

      Download the ZIP

      Free skills download straight away. Paid skills unlock right after purchase.

    2. 2

      Unzip into your skills folder

      Every agent reads skills from one folder on your machine. Drop the unzipped folder in there.

    3. 3

      Ask your agent to use it

      Restart the agent if it was already running. It picks the skill up automatically - no config needed.

    Skills folder by agent

    Click the path to copy it. Create the folder if it does not exist yet.

    Reviews

    No reviews yet

    Be one of the first to try it. Every listed skill passes our trust checks below.

    Security scanned

    Passed our 8-point scan before listing

    1 install

    Downloaded by developers to date

    Free forever

    No account required to browse

    Trust & safety

    Security scanned

    Verified clean 6 days ago

    • Free to download with an account

    Listed6 days ago

    What's inside

    Frequently Asked Questions