fortify-development

REVIEW · 58
Registry indexed

ACTIVATE when the user works on authentication in Laravel. This includes login, registration, password reset, email verification, two-factor authentication (2FA/TOTP/QR codes/recovery codes), passkeys, profile updates, password confirmation, or any auth-related routes and control

Verified installs0
Stars60
Version1.0.0
Quality65/100 · Promising
Trust58/100 · Do not auto-install
Audit75/100 · Needs review

Supply asset profile

Coding and developer agents

Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.

Browse track

Scenario

GitHub automation

I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.

Agent fit

Claude Code + CLI + Codex

Codex, Claude Code, Cursor, CLI, or custom agents.

Install

Ready

npx skills add promovaweb/specsfy --skill fortify-development

Maintenance

fresh

Pushed today

Risk

Needs review

Dependency or permission surface needs review

GitHub quality

60

65/100 Quality · 66/100 Trust

Coverage tags

CodingGitHub automationdesign-creativeagent-skill

Review notes

Dependency or permission surface needs review · Permission surface may require sandboxing

Agent adoption scorecard

Trust, audit, and install readiness at a glance

These scores combine public repository metadata, OpenAgentSkill review signals, maintenance freshness, and install readiness. They are a shortlist signal, not a replacement for human review.

Quality

Promising
65

Useful candidate, but compare it with alternatives before adopting.

Trust

Do not auto-install
58

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

Audit

Needs review
75

A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.

OpenAgentSkill Trust Score v5

Human review before install

Choose a stronger alternative or inspect the source manually before any install attempt.

CodexClaude CodeCursorOpenAgentSkill CLI

Stars

60 GitHub stars

Repo activity

60 stars, 23 forks

Maintenance

Pushed today

License

MIT

Install

npx skills add promovaweb/specsfy --skill fortify-development

Install safety

standard package or runtime install path

Permission surface

secrets or environment access, network or browser access

Agent outcomes

No agent outcome data yet

Docs

Strong README/SKILL.md context

Risk summary

Review before production

  • The SKILL.md content appears truncated; the final sentence about two-factor authentication in SPA mode is incomplete, which might indicate missing content in the actual file.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, network or browser access

Install readiness

Install path available

  • Install path is available
  • Repository evidence is available
  • License is declared
  • No Agent Proven outcome evidence yet

Agent-readable metadata

Machine-readable decision data for this skill.

Use this block or the embedded JSON to decide whether an agent should install this skill, choose an alternative, or ask for human review first.

Open JSON

Suited tasks

  • Workflow automation workflows
  • Claude Code teams
  • builders willing to evaluate younger projects
  • Move data between tools

Suited agents

CodexClaude CodeCursorOpenAgentSkill CLICLI

Install decision

Command
npx skills add promovaweb/specsfy --skill fortify-development
Policy
review
Human review
yes

Trust and risk

Trust
58/100
Audit
75/100
Risk level
Needs review

Outcome loop

Endpoint
/api/agent/outcome
Event ID
resolve
Outcomes
5

Install command

npx skills add promovaweb/specsfy --skill fortify-development

Do not use when

  • teams that need a vendor-supported SLA
  • production agents without a repository review
  • The SKILL.md content appears truncated; the final sentence about two-factor authentication in SPA mode is incomplete, which might indicate missing content in the actual file.
  • High-risk permission hints: Secrets or environment access
  • Dependency or permission surface needs review

Agent safety v2

43/100 · Avoid automatic install

Experimentalreview

Sparse or mixed signals. Useful for discovery, but not for autonomous installation.

Test manually in an isolated workspace and compare against safer alternatives.

Resolve via API

medium

Network access

Skill likely fetches remote pages, APIs, repositories, or external services.

medium

Filesystem access

Skill may read or write project files, documents, generated artifacts, or local workspace state.

high

Secrets or environment access

Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.

medium

Database access

Skill may inspect schemas, query databases, or work with persistent stores.

  • High-risk permission hints: Secrets or environment access
  • Dependency or permission surface needs review

Install targets

Install this skill in your agent workflow

Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install promovaweb-fortify-development

Agent resolve plan

Let an agent verify fit before installing.

The Resolve API returns the selected skill, alternatives, safety policy, audit notes, install target, and copy-paste prompt an agent can follow without scraping this page.

Open text plan

Agent should check

  • Task fit and alternatives from Resolve API.
  • Audit score, trust score, and safety policy warnings.
  • Install target compatibility for Codex, Claude Code, Cursor, or CLI.

Copy prompt

Task: Use fortify-development in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20fortify-development%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/promovaweb-fortify-development/install
Install command: npx skills add promovaweb/specsfy --skill fortify-development
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent handoff

Give an agent the install path, not another directory page.

Use the public install endpoint to fetch the command, safety checklist, target prompts, and canonical links for this skill.

Open install API

Agent prompt

Use fortify-development for this task. Review https://www.openagentskill.com/api/skills/promovaweb-fortify-development/install, then install with: npx skills add promovaweb/specsfy --skill fortify-development

Registry metadata

Agent-readable profile for automatic skill selection.

This page exposes the same decision, trust, audit, use-case, and install signals through the Registry API, so agents can rank this skill without scraping the UI.

Open manifest

Agent fit

66/100

Workflow automation

Platforms

Claude Code

Audit report

Needs review · 75/100

A machine-readable review of install readiness, security metadata, maintenance, and adoption risk.

View audit reportView eval report

Agent decision cockpit

Fallback candidate for Workflow automation

Prototype with this skill first; keep a fallback candidate ready.

66
Readiness
Prototype
Stage

Role in stack

Fallback candidate

Primary fit

Workflow automation

Trust label

Prototype first

Install path

Command ready

Use when

  • Workflow automation workflows
  • Claude Code teams
  • builders willing to evaluate younger projects

Evidence

  • recent repository activity
  • install command or GitHub repo available
  • 65/100 quality profile
  • 6 OpenAgentSkill engagement events

review first

  • The SKILL.md content appears truncated; the final sentence about two-factor authentication in SPA mode is incomplete, which might indicate missing content in the actual file.

Implementation path

  1. 1Install it in a sandbox agent and run one Workflow automation task end to end.
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

Trust profile

Do not auto-install

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

58
OpenAgentSkill Trust Score

GitHub adoption

CHECK

60 GitHub stars

Stars/forks activity

CHECK

60 stars, 23 forks; issue activity unavailable in current metadata

Recent maintenance

PASS

Pushed today

License clarity

PASS

MIT

Good signals

  • AI review approved
  • Install path is available
  • Repository evidence is available
  • Recently maintained repository
  • Install command has no obvious high-risk pattern
  • Outcome loop is ready but needs first real agent run

Review before install

  • The SKILL.md content appears truncated; the final sentence about two-factor authentication in SPA mode is incomplete, which might indicate missing content in the actual file.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, network or browser access
  • GitHub adoption: 60 GitHub stars
  • Stars/forks activity: 60 stars, 23 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: credential or environment access, network or browser surface
  • Permission surface: secrets or environment access, network or browser access
  • No real agent outcome reports yet
  • Human review required before unattended installation

Recommended action

Choose a stronger alternative or inspect the source manually before any install attempt.

Quality profile

Promising candidate for agent workflows

Useful candidate, but compare it with alternatives before adopting.

65
GitHub stars
60
Freshness
Today
Install ready
Yes
License
MIT
Review before install: The SKILL.md content appears truncated; the final sentence about two-factor authentication in SPA mode is incomplete, which might indicate missing content in the actual file.

Workflow fit

Use this skill in these scenarios

Workflow fit

Add it to a complete workflow

Alternative shortlist

Compare before you install

Similar skills that may fit this task.

Compare all

Overview

--- name: fortify-development description: 'ACTIVATE when the user works on authentication in Laravel. This includes login, registration, password reset, email verification, two-factor authentication (2FA/TOTP/QR codes/recovery codes), passkeys, profile updates, password confirmation, or any auth-related routes and controllers. Activate when the user mentions Fortify, auth, authentication, login, register, signup, forgot password, verify email, 2FA, passkeys, WebAuthn, or references app/Actions/Fortify/, CreateNewUser, UpdateUserProfileInformation, FortifyServiceProvider, config/fortify.php, or auth guards. Fortify is the frontend-agnostic authentication backend for Laravel that registers all auth routes and controllers. Also activate when building SPA or headless authentication, customizing login redirects, overriding response contracts like LoginResponse, or configuring login throttling. Do NOT activate for Laravel Passport (OAuth2 API tokens), Socialite (OAuth social login), or non-auth Laravel features.' license: MIT metadata: author: laravel ---

# Laravel Fortify Development

Fortify is a headless authentication backend that provides authentication routes and controllers for Laravel applications.

## Documentation

Use `search-docs` for detailed Laravel Fortify patterns and documentation.

## Usage

- **Routes**: Use `list-routes` with `only_vendor: true` and `action: "Fortify"` to see all registered endpoints - **Actions**: Check `app/Actions/Fortify/` for customizable business logic (user creation, password validation, etc.) - **Config**: See `config/fortify.php` for all options including features, guards, rate limiters, and username field - **Contracts**: Look in `Laravel\Fortify\Contracts\` for overridable response classes (`LoginResponse`, `LogoutResponse`, etc.) - **Views**: All view callbacks are set in `FortifyServiceProvider::boot()` using `Fortify::loginView()`, `Fortify::registerView()`, etc.

## Available Features

Enable in `config/fortify.php` features array:

- `Features::registration()` - User registration - `Features::resetPasswords()` - Password reset via email - `Features::emailVerification()` - Requires User to implement `MustVerifyEmail` - `Features::updateProfileInformation()` - Profile updates - `Features::updatePasswords()` - Password changes - `Features::twoFactorAuthentication()` - 2FA with QR codes and recovery codes - `Features::passkeys()` - Passwordless authentication with WebAuthn passkeys

> Use `search-docs` for feature configuration options and customization patterns.

## Setup Workflows

### Two-Factor Authentication Setup

``` - [ ] Add TwoFactorAuthenticatable trait to User model - [ ] Enable feature in config/fortify.php - [ ] If the `*_add_two_factor_columns_to_users_table.php` migration is missing, publish via `php artisan vendor:publish --tag=fortify-migrations` and migrate - [ ] Set up view callbacks in FortifyServiceProvider - [ ] Create 2FA management UI - [ ] Test QR code and recovery codes ```

> Use `search-docs` for TOTP implementation and recovery code handling patterns.

### Passkeys Setup

``` - [ ] Add PasskeyAuthenticatable trait to User model and implement PasskeyUser - [ ] Enable passkeys feature in config/fortify.php - [ ] If the passkeys table migration is missing, publish via `php artisan vendor:publish --tag=fortify-migrations` and migrate - [ ] Configure passkeys relying_party_id, allowed_origins, user_handle_secret, and timeout if defaults are not suitable - [ ] Build UI with @laravel/passkeys for registration, login, confirmation, and deletion ```

> Use `search-docs` for passkey configuration options. For `@laravel/passkeys` frontend usage, refer to the package's README on npm.

### Email Verification Setup

``` - [ ] Enable emailVerification feature in config - [ ] Implement MustVerifyEmail interface on User model - [ ] Set up verifyEmailView callback - [ ] Add verified middleware to protected routes - [ ] Test verification email flow ```

> Use `search-docs` for MustVerifyEmail implementation patterns.

### Password Reset Setup

``` - [ ] Enable resetPasswords feature in config - [ ] Set up requestPasswordResetLinkView callback - [ ] Set up resetPasswordView callback - [ ] Define password.reset named route (if views disabled) - [ ] Test reset email and link flow ```

> Use `search-docs` for custom password reset flow patterns.

### SPA Authentication Setup

``` - [ ] Set 'views' => false in config/fortify.php - [ ] Install and configure Laravel Sanctum for session-based SPA authentication - [ ] Use the 'web' guard in config/fortify.php (required for session-based authentication) - [ ] Set up CSRF token handling - [ ] Test XHR authentication flows ```

> Use `search-docs` for integration and SPA authentication patterns.

#### Two-Factor Authentication in SPA Mode

When `views` is set to `false`, Fortify returns JSON responses instead of redirects.

If a user attempts to log in and two-factor authentication is enabled, the login request will return a JSON response indicating that a two-factor challenge is required:

```json { "two_factor": true } ```

## Best Practices

### Custom Authentication Logic

Override authentication behavior using `Fortify::authenticateUsing()` for custom user retrieval or `Fortify::authenticateThrough()` to customize the authentication pipeline. Override response contracts in `AppServiceProvider` for custom redirects.

### Registration Customization

Modify `app/Actions/Fortify/CreateNewUser.php` to customize user creation logic, validation rules, and additional fields.

### Rate Limiting

Configure via `fortify.limiters.login` in config. Default configuration throttles by username + IP combination.

## Key Endpoints

| Feature | Method | Endpoint | |------------------------|----------|---------------------------------------------| | Login | POST | `/login` | | Logout | POST | `/logout` | | Register | POST | `/register` | | Password Reset Request | POST | `/forgot-password` | | Password Reset | POST | `/reset-password` | | Email Verify Notice | GET | `/email/verify` | | Resend Verification | POST | `/email/verification-notification` | | Password Confirm | POST | `/user/confirm-password` | | Enable 2FA | POST | `/user/two-factor-authentication` | | Confirm 2FA | POST | `/user/confirmed-two-factor-authentication` | | 2FA Challenge | POST | `/two-factor-challenge` | | Get QR Code | GET | `/user/two-factor-qr-code` | | Recovery Codes | GET/POST | `/user/two-factor-recovery-codes` | | Passkey Login Options | GET | `/passkeys/login/options` | | Passkey Login | POST | `/passkeys/login` | | Passkey Confirm Options| GET | `/passkeys/confirm/options` | | Passkey Confirm | POST | `/passkeys/confirm` | | Passkey Options | GET | `/user/passkeys/options` | | Register Passkey | POST | `/user/passkeys` | | Delete Passkey | DELETE | `/user/passkeys/{passkey}` |

Technical details

Version
1.0.0
License
MIT
Last updated
Aug 21, 2026
Published
Aug 21, 2026

Decision snapshot

Fallback candidate

66
Ready
Prototype
Stage

recent repository activity

Audit

Install review

Install and adoption review

75
Needs review
Security
74/100
Maintenance
100/100
Install
92/100
Open full auditView eval report

Agent-proven evidence

Agent-proven evidence

Outcome reports after resolve, review, install, and one narrow run.

0
Proven
Needs first agent runAuto-install: review firstLast: Unknown
Success rate
Recent failure
Outcomes
0
Output quality
Failed
0
Not relevant
0
Installs
0
Risk blocked
0
Setup needed
0
Production
0

No agent outcome data yet. The first agent run can report success, setup needs, risk blocks, failure, or not-relevant through /api/agent/outcome.

Install

Add to agent workflow

Free and open source. Review the report before installing into production agents.

Growth loop

Share kit

X

Scenario-led draft for fortify-development, ready for a manual X post.

Curator note
fortify-development: ACTIVATE when the user works on authentication in Laravel. This includes login, registration,...

60 stars

https://www.openagentskill.com/skills/promovaweb-fortify-development?ref=x
Open X draft
Optional reply with install command
Listing + install path for fortify-development:
https://www.openagentskill.com/skills/promovaweb-fortify-development?ref=x

Install: npx skills add promovaweb/specsfy --skill fortify-development

Listing source

Registry indexed

Claimable

This listing was indexed from public sources and is not marked official until a maintainer claim is approved.

Creator
promovaweb
Indexed by
OpenAgentSkill community index

Attribution links to the public repository or creator profile. Creators can claim the listing to update ownership signals.

Claim this skill

Owner claim

Claim this skill listing

This Registry indexed listing is attributed to promovaweb but is not marked official yet. Claim it to add a verified owner signal and make future launch, install, and audit updates easier to trust.

Creator backlink kit

Add the evidence badges to your README

Show the canonical listing, current trust and audit signals, and real Agent-Proven evidence where developers evaluate the repository.

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/promovaweb-fortify-development?metric=listed&label=Listed)](https://www.openagentskill.com/skills/promovaweb-fortify-development)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/promovaweb-fortify-development?metric=trust&label=Trust)](https://www.openagentskill.com/skills/promovaweb-fortify-development)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/promovaweb-fortify-development?metric=audit&label=Audit)](https://www.openagentskill.com/skills/promovaweb-fortify-development/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/promovaweb-fortify-development?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/promovaweb-fortify-development)

Author

P

promovaweb

@promovaweb

Platform fit

Health signals

GitHub stars
60
Quality score
36/100
Last GitHub push
Aug 21, 2026
Framework hints
Unknown
OpenAgentSkill views
6
Install copies
0
Outbound clicks
0

Community signal

Share whether this skill looks useful for your agent workflow. Aggregated feedback improves rankings over time.

Trust & safety

Do not auto-install

58
  • GitHub adoption60 GitHub starsCHECK
  • Stars/forks activity60 stars, 23 forks; issue activity unavailable in current metadataCHECK
  • Recent maintenancePushed todayPASS
  • License clarityMITPASS
  • README/SKILL.md completenessMetadata includes enough usage and workflow contextPASS
  • Dependency/runtime riskcredential or environment access, network or browser surfaceCHECK