fortify-development

Prüfen · 58
Im Registry indexiert

ACTIVATE when the user works on authentication in Laravel. This includes login, registration, password reset, email verification, two-factor authentication (2FA/TOTP/QR codes/recovery codes), passkeys, profile updates, password confirmation, or any auth-related routes and control

Verified installs0
Stars60
Version1.0.0
Qualität65/100 · Vielversprechend
Vertrauen58/100 · Do not auto-install
Audit75/100 · Prüfung nötig

Asset-Profil

Coding- und Entwickler-Agents

Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.

Bereich ansehen

Szenario

GitHub automation

I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.

Agent-Fit

Claude Code + CLI + Codex

Geeignet für Codex, Claude Code, Cursor, CLI oder benutzerdefinierte Agents.

Installieren

Bereit

npx skills add promovaweb/specsfy --skill fortify-development

Wartung

Aktuell

Heute gepusht

Risiko

Prüfung nötig

Dependency or permission surface needs review

GitHub-Qualität

60

65/100 Qualität · 66/100 Vertrauen

Abdeckungs-Tags

CodingGitHub automationDesign und Kreativitätagent-skill

Review-Notizen

Dependency or permission surface needs review · Permission surface may require sandboxing

Agent-Adoptionskarte

Vertrauen, Audit und Installationsbereitschaft auf einen Blick

Diese Werte kombinieren öffentliche Repository-Metadaten, OpenAgentSkill-Reviewsignale, Wartungsaktualität und Installationsbereitschaft. Sie helfen bei der Vorauswahl, ersetzen aber keine menschliche Prüfung.

Qualität

Vielversprechend
65

Useful candidate, but compare it with alternatives before adopting.

Vertrauen

Do not auto-install
58

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

Audit

Prüfung nötig
75

Maschinenlesbare Prüfung von Installationsbereitschaft, Sicherheitsmetadaten, Wartung und Akzeptanzrisiko.

OpenAgentSkill Trust Score v5

Menschliche Prüfung vor Installation

Choose a stronger alternative or inspect the source manually before any install attempt.

CodexClaude CodeCursorOpenAgentSkill CLI

Stars

60 GitHub-Stars

Repository-Aktivität

60 Stars und 23 Forks

Wartung

Heute gepusht

Lizenz

MIT

Installieren

npx skills add promovaweb/specsfy --skill fortify-development

Installationssicherheit

Standard-Paket- oder Laufzeit-Installationspfad

Berechtigungsfläche

secrets or environment access, network or browser access

Agent-Ergebnisse

Noch keine Agent-Ergebnisdaten

Dokumentation

Starker README/SKILL.md-Kontext

Risikoübersicht

Vor Produktion prüfen

  • The SKILL.md content appears truncated; the final sentence about two-factor authentication in SPA mode is incomplete, which might indicate missing content in the actual file.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, network or browser access

Installationsbereitschaft

Installationspfad verfügbar

  • Installationspfad ist verfügbar
  • Repository-Belege sind verfügbar
  • Lizenz ist angegeben
  • Noch keine Agent-Proven-Ergebnisbelege

Agent-lesbare Metadaten

Maschinenlesbare Entscheidungsdaten für diesen Skill.

Nutze diesen Block oder das eingebettete JSON, um zu entscheiden, ob ein Agent diesen Skill installieren, eine Alternative wählen oder zuerst menschliche Prüfung anfordern soll.

JSON öffnen

Geeignete Aufgaben

  • Workflow-Automatisierung-Workflows
  • Claude-Code-Teams
  • builders willing to evaluate younger projects
  • Move data between tools

Geeignete Agents

CodexClaude CodeCursorOpenAgentSkill CLICLI

Installationsentscheidung

Befehl
npx skills add promovaweb/specsfy --skill fortify-development
Richtlinie
Prüfen
Menschliche Prüfung
Ja

Vertrauen und Risiko

Vertrauen
58/100
Audit
75/100
Risikoebene
Prüfung nötig

Ergebnis-Loop

Endpoint
/api/agent/outcome
Event-ID
resolve
Ergebnisse
5

Installationsbefehl

npx skills add promovaweb/specsfy --skill fortify-development

Nicht verwenden, wenn

  • Teams, die ein vom Anbieter unterstütztes SLA benötigen
  • production agents without a repository review
  • The SKILL.md content appears truncated; the final sentence about two-factor authentication in SPA mode is incomplete, which might indicate missing content in the actual file.
  • Hinweise auf Hochrisiko-Berechtigungen: Secrets or environment access
  • Dependency or permission surface needs review

Agent-Sicherheit v2

43/100 · Automatische Installation vermeiden

ExperimentellPrüfen

Sparse or mixed signals. Useful for discovery, but not for autonomous installation.

Test manually in an isolated workspace and compare against safer alternatives.

Per API auflösen

Mittel

Netzwerkzugriff

Die Skill ruft wahrscheinlich Remote-Seiten, APIs, Repositories oder externe Dienste ab.

Mittel

Dateisystemzugriff

Die Skill kann Projektdateien, Dokumente, generierte Artefakte oder den lokalen Arbeitsbereich lesen oder schreiben.

Hoch

Secrets or environment access

Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.

Mittel

Datenbankzugriff

Die Skill kann Schemata prüfen, Datenbanken abfragen oder mit persistenten Speichern arbeiten.

  • Hinweise auf Hochrisiko-Berechtigungen: Secrets or environment access
  • Dependency or permission surface needs review

Installationsziele

Diesen Skill im Agent-Workflow installieren

Über den öffentlichen Endpunkt erhältst du Befehl, Sicherheitscheckliste, Ziel-Prompts und kanonische Links.

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install promovaweb-fortify-development

Agent-Auflösungsplan

Lass einen Agent die Eignung vor der Installation prüfen.

Die Resolve API liefert die beste Skill, Alternativen, Sicherheitsrichtlinien, Auditnotizen, Installationsziel und einen direkt nutzbaren Prompt.

Textplan öffnen

Agent sollte prüfen

  • Task fit and alternatives from Resolve API.
  • Audit score, trust score, and safety policy warnings.
  • Install target compatibility for Codex, Claude Code, Cursor, or CLI.

Prompt kopieren

Task: Use fortify-development in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20fortify-development%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/promovaweb-fortify-development/install
Install command: npx skills add promovaweb/specsfy --skill fortify-development
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Agent-Übergabe

Gib dem Agent den Installationspfad, nicht noch ein Verzeichnis.

Über den öffentlichen Endpunkt erhältst du Befehl, Sicherheitscheckliste, Ziel-Prompts und kanonische Links.

Installations-API öffnen

Agent-Prompt

Use fortify-development for this task. Review https://www.openagentskill.com/api/skills/promovaweb-fortify-development/install, then install with: npx skills add promovaweb/specsfy --skill fortify-development

Registry-Metadaten

Agent-lesbares Profil für die automatische Skill-Auswahl.

Die Registry API stellt Entscheidungs-, Vertrauens-, Audit-, Use-Case- und Installationssignale ohne UI-Scraping bereit.

Manifest öffnen

Agent-Fit

66/100

Workflow-Automatisierung

Plattformen

Claude Code

Audit-Bericht

Prüfung nötig · 75/100

Maschinenlesbare Prüfung von Installationsbereitschaft, Sicherheitsmetadaten, Wartung und Akzeptanzrisiko.

Audit-Bericht ansehenEval-Bericht ansehen

Agent-Entscheidungspanel

Fallback candidate for Workflow automation

Prototype with this skill first; keep a fallback candidate ready.

66
Bereitschaft
Prototyp
Phase

Rolle im Stack

Fallback-Kandidat

Primäre Eignung

Workflow-Automatisierung

Vertrauenslabel

Zuerst prototypisieren

Installationspfad

Befehl bereit

Verwenden wenn

  • Workflow-Automatisierung-Workflows
  • Claude-Code-Teams
  • builders willing to evaluate younger projects

Evidenz

  • recent repository activity
  • install command or GitHub repo available
  • Qualitätsprofil 65/100
  • 6 OpenAgentSkill-Interaktionen

zuerst prüfen

  • The SKILL.md content appears truncated; the final sentence about two-factor authentication in SPA mode is incomplete, which might indicate missing content in the actual file.

Implementierungspfad

  1. 1Installieren Sie es in einem Sandbox-Agent und führen Sie eine Workflow-Automatisierung-Aufgabe vollständig aus.
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

Vertrauensprofil

Do not auto-install

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

58
OpenAgentSkill Trust Score

GitHub-Akzeptanz

Prüfen

60 GitHub-Stars

Star-/Fork-Aktivität

Prüfen

60 Stars und 23 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbar

Aktuelle Wartung

Bestanden

Heute gepusht

Lizenzklarheit

Bestanden

MIT

Positive Signale

  • KI-Prüfung genehmigt
  • Installationspfad ist verfügbar
  • Repository-Belege sind verfügbar
  • Kürzlich gewartetes Repository
  • Der Installationsbefehl weist kein offensichtliches Hochrisikomuster auf
  • Ergebniszyklus ist bereit, benötigt aber den ersten echten Agent-Lauf

Vor Installation prüfen

  • The SKILL.md content appears truncated; the final sentence about two-factor authentication in SPA mode is incomplete, which might indicate missing content in the actual file.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, network or browser access
  • GitHub adoption: 60 GitHub stars
  • Stars/forks activity: 60 stars, 23 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: credential or environment access, network or browser surface
  • Permission surface: secrets or environment access, network or browser access
  • Noch keine echten Agent-Ergebnisberichte
  • Vor unbeaufsichtigter Installation ist menschliche Prüfung erforderlich

Empfohlene Aktion

Choose a stronger alternative or inspect the source manually before any install attempt.

Qualitätsprofil

Vielversprechend Kandidat für Agent-Workflows

Useful candidate, but compare it with alternatives before adopting.

65
GitHub-Stars
60
Aktualität
Heute
Installationsbereit
Ja
Lizenz
MIT
Vor Installation prüfen: The SKILL.md content appears truncated; the final sentence about two-factor authentication in SPA mode is incomplete, which might indicate missing content in the actual file.

Workflow-Eignung

Diese Skill in diesen Szenarien nutzen

Workflow-Eignung

Zum vollständigen Workflow hinzufügen

Alternativen-Shortlist

Vor Installation vergleichen

Similar skills that may fit this task.

Alle vergleichen

Übersicht

--- name: fortify-development description: 'ACTIVATE when the user works on authentication in Laravel. This includes login, registration, password reset, email verification, two-factor authentication (2FA/TOTP/QR codes/recovery codes), passkeys, profile updates, password confirmation, or any auth-related routes and controllers. Activate when the user mentions Fortify, auth, authentication, login, register, signup, forgot password, verify email, 2FA, passkeys, WebAuthn, or references app/Actions/Fortify/, CreateNewUser, UpdateUserProfileInformation, FortifyServiceProvider, config/fortify.php, or auth guards. Fortify is the frontend-agnostic authentication backend for Laravel that registers all auth routes and controllers. Also activate when building SPA or headless authentication, customizing login redirects, overriding response contracts like LoginResponse, or configuring login throttling. Do NOT activate for Laravel Passport (OAuth2 API tokens), Socialite (OAuth social login), or non-auth Laravel features.' license: MIT metadata: author: laravel ---

# Laravel Fortify Development

Fortify is a headless authentication backend that provides authentication routes and controllers for Laravel applications.

## Documentation

Use `search-docs` for detailed Laravel Fortify patterns and documentation.

## Usage

- **Routes**: Use `list-routes` with `only_vendor: true` and `action: "Fortify"` to see all registered endpoints - **Actions**: Check `app/Actions/Fortify/` for customizable business logic (user creation, password validation, etc.) - **Config**: See `config/fortify.php` for all options including features, guards, rate limiters, and username field - **Contracts**: Look in `Laravel\Fortify\Contracts\` for overridable response classes (`LoginResponse`, `LogoutResponse`, etc.) - **Views**: All view callbacks are set in `FortifyServiceProvider::boot()` using `Fortify::loginView()`, `Fortify::registerView()`, etc.

## Available Features

Enable in `config/fortify.php` features array:

- `Features::registration()` - User registration - `Features::resetPasswords()` - Password reset via email - `Features::emailVerification()` - Requires User to implement `MustVerifyEmail` - `Features::updateProfileInformation()` - Profile updates - `Features::updatePasswords()` - Password changes - `Features::twoFactorAuthentication()` - 2FA with QR codes and recovery codes - `Features::passkeys()` - Passwordless authentication with WebAuthn passkeys

> Use `search-docs` for feature configuration options and customization patterns.

## Setup Workflows

### Two-Factor Authentication Setup

``` - [ ] Add TwoFactorAuthenticatable trait to User model - [ ] Enable feature in config/fortify.php - [ ] If the `*_add_two_factor_columns_to_users_table.php` migration is missing, publish via `php artisan vendor:publish --tag=fortify-migrations` and migrate - [ ] Set up view callbacks in FortifyServiceProvider - [ ] Create 2FA management UI - [ ] Test QR code and recovery codes ```

> Use `search-docs` for TOTP implementation and recovery code handling patterns.

### Passkeys Setup

``` - [ ] Add PasskeyAuthenticatable trait to User model and implement PasskeyUser - [ ] Enable passkeys feature in config/fortify.php - [ ] If the passkeys table migration is missing, publish via `php artisan vendor:publish --tag=fortify-migrations` and migrate - [ ] Configure passkeys relying_party_id, allowed_origins, user_handle_secret, and timeout if defaults are not suitable - [ ] Build UI with @laravel/passkeys for registration, login, confirmation, and deletion ```

> Use `search-docs` for passkey configuration options. For `@laravel/passkeys` frontend usage, refer to the package's README on npm.

### Email Verification Setup

``` - [ ] Enable emailVerification feature in config - [ ] Implement MustVerifyEmail interface on User model - [ ] Set up verifyEmailView callback - [ ] Add verified middleware to protected routes - [ ] Test verification email flow ```

> Use `search-docs` for MustVerifyEmail implementation patterns.

### Password Reset Setup

``` - [ ] Enable resetPasswords feature in config - [ ] Set up requestPasswordResetLinkView callback - [ ] Set up resetPasswordView callback - [ ] Define password.reset named route (if views disabled) - [ ] Test reset email and link flow ```

> Use `search-docs` for custom password reset flow patterns.

### SPA Authentication Setup

``` - [ ] Set 'views' => false in config/fortify.php - [ ] Install and configure Laravel Sanctum for session-based SPA authentication - [ ] Use the 'web' guard in config/fortify.php (required for session-based authentication) - [ ] Set up CSRF token handling - [ ] Test XHR authentication flows ```

> Use `search-docs` for integration and SPA authentication patterns.

#### Two-Factor Authentication in SPA Mode

When `views` is set to `false`, Fortify returns JSON responses instead of redirects.

If a user attempts to log in and two-factor authentication is enabled, the login request will return a JSON response indicating that a two-factor challenge is required:

```json { "two_factor": true } ```

## Best Practices

### Custom Authentication Logic

Override authentication behavior using `Fortify::authenticateUsing()` for custom user retrieval or `Fortify::authenticateThrough()` to customize the authentication pipeline. Override response contracts in `AppServiceProvider` for custom redirects.

### Registration Customization

Modify `app/Actions/Fortify/CreateNewUser.php` to customize user creation logic, validation rules, and additional fields.

### Rate Limiting

Configure via `fortify.limiters.login` in config. Default configuration throttles by username + IP combination.

## Key Endpoints

| Feature | Method | Endpoint | |------------------------|----------|---------------------------------------------| | Login | POST | `/login` | | Logout | POST | `/logout` | | Register | POST | `/register` | | Password Reset Request | POST | `/forgot-password` | | Password Reset | POST | `/reset-password` | | Email Verify Notice | GET | `/email/verify` | | Resend Verification | POST | `/email/verification-notification` | | Password Confirm | POST | `/user/confirm-password` | | Enable 2FA | POST | `/user/two-factor-authentication` | | Confirm 2FA | POST | `/user/confirmed-two-factor-authentication` | | 2FA Challenge | POST | `/two-factor-challenge` | | Get QR Code | GET | `/user/two-factor-qr-code` | | Recovery Codes | GET/POST | `/user/two-factor-recovery-codes` | | Passkey Login Options | GET | `/passkeys/login/options` | | Passkey Login | POST | `/passkeys/login` | | Passkey Confirm Options| GET | `/passkeys/confirm/options` | | Passkey Confirm | POST | `/passkeys/confirm` | | Passkey Options | GET | `/user/passkeys/options` | | Register Passkey | POST | `/user/passkeys` | | Delete Passkey | DELETE | `/user/passkeys/{passkey}` |

Technische Details

Version
1.0.0
Lizenz
MIT
Letzte Aktualisierung
21. Aug. 2026
Veröffentlicht
21. Aug. 2026

Entscheidungsübersicht

Fallback-Kandidat

66
Bereit
Prototyp
Phase

recent repository activity

Audit

Installationsprüfung

Installations- und Adoptionsprüfung

75
Prüfung nötig
Sicherheit
74/100
Wartung
100/100
Installieren
92/100
Vollständiges Audit öffnenEval-Bericht ansehen

Von Agent belegte Evidenz

Von Agent belegte Evidenz

Ergebnisberichte nach Resolve, Prüfung, Installation und einem begrenzten Lauf.

0
Belegt
Needs first agent runAuto-Installation: zuerst prüfenLetzter: Unbekannt
Erfolgsrate
Letzter Fehler
Ergebnisse
0
Ausgabequalität
Fehlgeschlagen
0
Nicht relevant
0
Installationen
0
Durch Risiko blockiert
0
Einrichtung erforderlich
0
Produktion
0

Noch keine Agent-Ergebnisdaten. Der erste Lauf kann Erfolg, Einrichtungsbedarf, Risikoblockaden, Fehler oder Irrelevanz über /api/agent/outcome melden.

Installieren

Zum Agent-Workflow hinzufügen

Kostenlos und Open Source. Bericht vor der Installation in Produktions-Agents prüfen.

Wachstums-Loop

Share-Kit

X

Szenariobasierter Entwurf für fortify-development, bereit für einen manuellen X-Post.

Kuratorenhinweis
fortify-development: ACTIVATE when the user works on authentication in Laravel. This includes login, registration,...

60 stars

https://www.openagentskill.com/skills/promovaweb-fortify-development?ref=x
X-Entwurf öffnen
Optionale Antwort mit Installationsbefehl
Listing + install path for fortify-development:
https://www.openagentskill.com/skills/promovaweb-fortify-development?ref=x

Install: npx skills add promovaweb/specsfy --skill fortify-development
Antwortentwurf öffnen

Quelle des Eintrags

Registry-indexiert

Beanspruchbar

Dieser Eintrag wurde aus öffentlichen Quellen indexiert und ist erst nach Genehmigung eines Maintainer-Anspruchs offiziell.

Ersteller
promovaweb
Indexiert von
OpenAgentSkill Community-Index

Die Zuordnung verlinkt auf das öffentliche Repository oder Creator-Profil. Creator können den Eintrag beanspruchen, um Eigentümersignale zu aktualisieren.

Diesen Skill beanspruchen

Eigentümeranspruch

Diesen Skill-Eintrag beanspruchen

Dieser Registry-indexiert-Eintrag wird promovaweb zugeschrieben, ist aber noch nicht offiziell markiert. Beanspruche ihn, um ein verifiziertes Eigentümersignal hinzuzufügen und künftige Launch-, Installations- und Audit-Updates vertrauenswürdiger zu machen.

Creator-Backlink-Kit

Evidenz-Badges in deine README einfügen

Zeige den kanonischen Eintrag, aktuelle Vertrauens- und Audit-Signale sowie echte Agent-Proven-Evidenz dort, wo Entwickler das Repository bewerten.

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/promovaweb-fortify-development?metric=listed&label=Listed)](https://www.openagentskill.com/skills/promovaweb-fortify-development)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/promovaweb-fortify-development?metric=trust&label=Trust)](https://www.openagentskill.com/skills/promovaweb-fortify-development)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/promovaweb-fortify-development?metric=audit&label=Audit)](https://www.openagentskill.com/skills/promovaweb-fortify-development/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/promovaweb-fortify-development?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/promovaweb-fortify-development)

Autor

P

promovaweb

@promovaweb

Plattform-Fit

Gesundheitssignale

GitHub-Stars
60
Qualitätswert
36/100
Letzter GitHub-Push
21. Aug. 2026
Framework-Hinweise
Unbekannt
OpenAgentSkill-Aufrufe
6
Installationskopien
0
Externe Klicks
0

Community-Signal

Teile mit, ob dieser Skill für deinen Agent-Workflow nützlich ist. Zusammengefasstes Feedback verbessert das Ranking im Laufe der Zeit.

Vertrauen & Sicherheit

Do not auto-install

58
  • GitHub-Akzeptanz60 GitHub-StarsPrüfen
  • Star-/Fork-Aktivität60 Stars und 23 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbarPrüfen
  • Aktuelle WartungHeute gepushtBestanden
  • LizenzklarheitMITBestanden
  • README/SKILL.md-VollständigkeitMetadaten enthalten ausreichend Nutzungs- und Workflow-KontextBestanden
  • Abhängigkeits-/Laufzeitrisikocredential or environment access, network or browser surfacePrüfen