# Laravel Security · HamzaAlayed

> The Laravel security-review cookbook — STRIDE applied to Laravel primitives, the authn / authz / mass-assignment / upload / injection checklist, advisory lookup procedure, and the finding format. Use when threat-modeling a feature, reviewing a PR that touches auth / PII / billing / uploads / middleware, or triaging a suspected vulnerability. Findings only — fixes land with the owning builder after human awareness.

## Facts
- Page: https://tashan.sh/capability/skill-hamzaalayed-laravel-security
- tashan id: skill:HamzaAlayed/laravel-security
- Source: https://github.com/HamzaAlayed/laravel-claude-agents
- Type: skill
- Category: security
- tashan score: 42.0 / 100
- Adoption: 14.0
- Upkeep: 64.0
- Freshness: 100.0
- Evidence coverage: 84% of the inputs this score can use
- Health: active
- Instruction depth: not yet graded
- License: MIT
- Official: no

## Install

```sh
cp -r laravel-security ~/.claude/skills/
```

## Security audit
Not scanned. We audit npm-published capabilities; this one has no npm package we can resolve, or has not reached the queue. This is not a clean bill of health.

---
Measured 2026-08-21 by tashan (https://tashan.sh) from public evidence. Scorer s5.
