Spatie Security

spatie/guidelines-skills/resources/boost/skills/spatie-security

by spatiec31006972d0b8c8db71e7b75c1b1d505b479023dMITListed Oct 9, 2026Updated Oct 9, 2026

Apply Spatie's security guidelines when configuring applications, databases, servers, credentials, or signed Git commits, or when reviewing code for security concerns; use for SSL setup, CSRF protection, password hashing, database permissions, and server hardening.

Instructions onlySecurity
AI-generated overview

Applies Spatie's security guidelines to application, database, server, credential, and signed Git commit configuration and code review.

What it does
This skill directs an agent to apply Spatie's security best practices when building, configuring, or reviewing applications and infrastructure. It covers application security such as SSL, CSRF protection, HTTP methods, and authorization tests; database security such as password hashing, API key encryption, and user and host isolation; server hardening such as SSH settings, unattended updates, and firewall rules; credential management; and signing Git commits. The agent reads the bundled reference file and applies the narrowest relevant controls without weakening existing protections.
When to use it
Use it when configuring or reviewing application security, database configurations, servers or infrastructure, credentials, or signed Git commits. It is also intended for reviewing code for security vulnerabilities. It is not meant for code style, business logic, or UI/UX design.
Requirements
No scripts; instructions only. The agent reads the bundled reference file references/spatie-security-guidelines.md. No packages, runtimes, credentials, or network access are specified.

Spatie Security Guidelines

Overview

Apply Spatie's security best practices when building, configuring, or reviewing applications and infrastructure.

When to Activate

  • Activate this skill when configuring application security (authentication, authorization, forms).
  • Activate this skill when setting up or reviewing database configurations.
  • Activate this skill when configuring servers or reviewing infrastructure.
  • Activate this skill when reviewing code for security vulnerabilities.
  • Activate this skill when configuring or creating signed Git commits.

Scope

  • In scope: Application security, database security, server configuration, credential management, signed Git commits.
  • Out of scope: Code style, business logic, UI/UX design.

Workflow

  1. Identify the application, database, server, credential, or Git security concern.
  2. Read references/spatie-security-guidelines.md and focus on the relevant sections.
  3. Apply the narrowest relevant security controls without weakening existing protections.

Core Rules (Summary)

  • Store unique passwords in 1Password, enable two-factor authentication, and password-protect private keys.
  • Sign all Git commits.
  • Use SSL, CSRF protection, appropriate HTTP methods, and automated authorization tests.
  • Hash passwords, encrypt stored API keys, isolate database users, and restrict database hosts.
  • Keep servers current, disable SSH password authentication, enable unattended security updates, and restrict firewall traffic.
  • Protect devices, backups, sensitive data, and browser activity.

References

  • references/spatie-security-guidelines.md

Source and attribution

Source:spatie/guidelines-skillsinresources/boost/skills/spatie-securityat commitc310069

License: MIT

Content belongs to its original authors. SourceWeft indexes it from a public repository.

Report or request removal