spatie-security
Apply Spatie's security guidelines when configuring applications, databases, servers, credentials, or signed Git commits, or when reviewing code for security concerns; use for SSL setup, CSRF protection, password hashing, database permissions, and server hardening.
How do I install this agent skill?
npx skills add https://github.com/spatie/guidelines-skills --skill spatie-securityIs this agent skill safe to install?
- Gen Agent Trust Hubpass
The skill provides a set of security best practices for application and infrastructure configuration based on Spatie's guidelines. It does not contain executable code, malicious patterns, or suspicious external references.
- Socketpass
No alerts
- Snykpass
Risk: LOW · No issues
- Runlayerwarn
1/1 file flagged
- ZeroLeakspass
Score: 93/100 · 2 sections analyzed
What does this agent skill do?
Spatie Security Guidelines
Overview
Apply Spatie's security best practices when building, configuring, or reviewing applications and infrastructure.
When to Activate
- Activate this skill when configuring application security (authentication, authorization, forms).
- Activate this skill when setting up or reviewing database configurations.
- Activate this skill when configuring servers or reviewing infrastructure.
- Activate this skill when reviewing code for security vulnerabilities.
- Activate this skill when configuring or creating signed Git commits.
Scope
- In scope: Application security, database security, server configuration, credential management, signed Git commits.
- Out of scope: Code style, business logic, UI/UX design.
Workflow
- Identify the application, database, server, credential, or Git security concern.
- Read
references/spatie-security-guidelines.mdand focus on the relevant sections. - Apply the narrowest relevant security controls without weakening existing protections.
Core Rules (Summary)
- Store unique passwords in 1Password, enable two-factor authentication, and password-protect private keys.
- Sign all Git commits.
- Use SSL, CSRF protection, appropriate HTTP methods, and automated authorization tests.
- Hash passwords, encrypt stored API keys, isolate database users, and restrict database hosts.
- Keep servers current, disable SSH password authentication, enable unattended security updates, and restrict firewall traffic.
- Protect devices, backups, sensitive data, and browser activity.
References
references/spatie-security-guidelines.md
How can the creator link this skill?
Add the canonical catalog link to the repository README so users can inspect current installs and available audits. The publishing guide covers the complete discovery path.
<a href="https://skillzs.dev/skills/spatie/guidelines-skills/spatie-security">View spatie-security on skillZs</a>