Spatie Security

spatie/guidelines-skills/resources/boost/skills/spatie-security

作者 spatiec31006972d0b8c8db71e7b75c1b1d505b479023dMIT收录于 2026年10月9日更新于 2026年10月9日

Apply Spatie's security guidelines when configuring applications, databases, servers, credentials, or signed Git commits, or when reviewing code for security concerns; use for SSL setup, CSRF protection, password hashing, database permissions, and server hardening.

仅含说明Security
AI 生成的概览

在配置应用、数据库、服务器、凭据和签名 Git 提交,或审查代码安全问题时应用 Spatie 的安全准则。

功能
该技能指导智能体在构建、配置或审查应用与基础设施时应用 Spatie 的安全最佳实践。内容涵盖应用安全(如 SSL、CSRF 防护、HTTP 方法和授权测试)、数据库安全(如密码哈希、API 密钥加密、数据库用户与主机隔离)、服务器加固(如 SSH 设置、无人值守更新和防火墙规则)、凭据管理以及签名 Git 提交。智能体会阅读随附的参考文件,并在不削弱现有防护的前提下应用最窄范围的相关控制措施。
适用场景
适用于配置或审查应用安全、数据库配置、服务器或基础设施、凭据或签名 Git 提交的场景。也用于审查代码中的安全漏洞。不适用于代码风格、业务逻辑或 UI/UX 设计。
运行要求
无脚本,仅为说明性内容。智能体会阅读随附的参考文件 references/spatie-security-guidelines.md。未说明需要任何软件包、运行时、凭据或网络访问。

Spatie Security Guidelines

Overview

Apply Spatie's security best practices when building, configuring, or reviewing applications and infrastructure.

When to Activate

  • Activate this skill when configuring application security (authentication, authorization, forms).
  • Activate this skill when setting up or reviewing database configurations.
  • Activate this skill when configuring servers or reviewing infrastructure.
  • Activate this skill when reviewing code for security vulnerabilities.
  • Activate this skill when configuring or creating signed Git commits.

Scope

  • In scope: Application security, database security, server configuration, credential management, signed Git commits.
  • Out of scope: Code style, business logic, UI/UX design.

Workflow

  1. Identify the application, database, server, credential, or Git security concern.
  2. Read references/spatie-security-guidelines.md and focus on the relevant sections.
  3. Apply the narrowest relevant security controls without weakening existing protections.

Core Rules (Summary)

  • Store unique passwords in 1Password, enable two-factor authentication, and password-protect private keys.
  • Sign all Git commits.
  • Use SSL, CSRF protection, appropriate HTTP methods, and automated authorization tests.
  • Hash passwords, encrypt stored API keys, isolate database users, and restrict database hosts.
  • Keep servers current, disable SSH password authentication, enable unattended security updates, and restrict firewall traffic.
  • Protect devices, backups, sensitive data, and browser activity.

References

  • references/spatie-security-guidelines.md

来源与署名

来源:spatie/guidelines-skills位于resources/boost/skills/spatie-security提交c310069

许可证: MIT

内容归原作者所有。SourceWeft 从公开仓库中收录这些内容。

举报或申请下架