Spatie Security

spatie/guidelines-skills/resources/boost/skills/spatie-security

作者 spatiec31006972d0b8c8db71e7b75c1b1d505b479023dMIT收錄於 2026年10月9日更新於 2026年10月9日

Apply Spatie's security guidelines when configuring applications, databases, servers, credentials, or signed Git commits, or when reviewing code for security concerns; use for SSL setup, CSRF protection, password hashing, database permissions, and server hardening.

僅含說明Security
AI 產生的概覽

在設定應用程式、資料庫、伺服器、憑證與簽署 Git 提交,或審查程式碼安全問題時套用 Spatie 的安全準則。

功能
此技能會引導代理在建置、設定或審查應用程式與基礎設施時套用 Spatie 的安全最佳實務。內容涵蓋應用程式安全(例如 SSL、CSRF 防護、HTTP 方法與授權測試)、資料庫安全(例如密碼雜湊、API 金鑰加密、資料庫使用者與主機隔離)、伺服器強化(例如 SSH 設定、無人值守更新與防火牆規則)、憑證管理,以及簽署 Git 提交。代理會閱讀隨附的參考檔案,並在不削弱現有防護的前提下套用範圍最窄的相關控制措施。
適用情境
適用於設定或審查應用程式安全、資料庫設定、伺服器或基礎設施、憑證或簽署 Git 提交的情況。也用於審查程式碼中的安全弱點。不適用於程式碼風格、業務邏輯或 UI/UX 設計。
執行需求
沒有指令碼,僅為指示性內容。代理會閱讀隨附的參考檔案 references/spatie-security-guidelines.md。未說明需要任何套件、執行環境、憑證或網路存取。

Spatie Security Guidelines

Overview

Apply Spatie's security best practices when building, configuring, or reviewing applications and infrastructure.

When to Activate

  • Activate this skill when configuring application security (authentication, authorization, forms).
  • Activate this skill when setting up or reviewing database configurations.
  • Activate this skill when configuring servers or reviewing infrastructure.
  • Activate this skill when reviewing code for security vulnerabilities.
  • Activate this skill when configuring or creating signed Git commits.

Scope

  • In scope: Application security, database security, server configuration, credential management, signed Git commits.
  • Out of scope: Code style, business logic, UI/UX design.

Workflow

  1. Identify the application, database, server, credential, or Git security concern.
  2. Read references/spatie-security-guidelines.md and focus on the relevant sections.
  3. Apply the narrowest relevant security controls without weakening existing protections.

Core Rules (Summary)

  • Store unique passwords in 1Password, enable two-factor authentication, and password-protect private keys.
  • Sign all Git commits.
  • Use SSL, CSRF protection, appropriate HTTP methods, and automated authorization tests.
  • Hash passwords, encrypt stored API keys, isolate database users, and restrict database hosts.
  • Keep servers current, disable SSH password authentication, enable unattended security updates, and restrict firewall traffic.
  • Protect devices, backups, sensitive data, and browser activity.

References

  • references/spatie-security-guidelines.md

來源與署名

來源:spatie/guidelines-skills位於resources/boost/skills/spatie-security提交c310069

授權條款: MIT

內容歸原作者所有。SourceWeft 從公開儲存庫中收錄這些內容。

檢舉或申請下架