fortify-development

Tinjau · 58
Diindeks di Registry

ACTIVATE when the user works on authentication in Laravel. This includes login, registration, password reset, email verification, two-factor authentication (2FA/TOTP/QR codes/recovery codes), passkeys, profile updates, password confirmation, or any auth-related routes and control

Verified installs0
Star60
Versi1.0.0
Kualitas65/100 · Menjanjikan
Kepercayaan58/100 · Do not auto-install
Audit75/100 · Perlu ditinjau

Profil aset

Agent pemrograman dan pengembangan

Code review, repo analysis, testing, CI, GitHub, DevOps, and developer workflow skills.

Lihat kategori

Skenario

GitHub automation

I need my agent to triage GitHub issues, review pull requests, and summarize repository changes.

Kecocokan Agent

Claude Code + CLI + Codex

Cocok untuk Codex, Claude Code, Cursor, CLI, atau Agent khusus.

Pasang

Siap

npx skills add promovaweb/specsfy --skill fortify-development

Pemeliharaan

Terkini

1 hari sejak push

Risiko

Perlu ditinjau

Dependency or permission surface needs review

Kualitas GitHub

60

65/100 Kualitas · 66/100 Kepercayaan

Tag cakupan

CodingGitHub automationDesain dan kreatifagent-skill

Catatan ulasan

Dependency or permission surface needs review · Permission surface may require sandboxing

Kartu adopsi Agent

Kepercayaan, audit, dan kesiapan pemasangan dalam sekali lihat

Skor ini menggabungkan metadata repositori publik, sinyal ulasan OpenAgentSkill, kebaruan pemeliharaan, dan kesiapan pemasangan. Ini adalah sinyal shortlist, bukan pengganti peninjauan manusia.

Kualitas

Menjanjikan
65

Useful candidate, but compare it with alternatives before adopting.

Kepercayaan

Do not auto-install
58

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

Audit

Perlu ditinjau
75

Tinjauan yang dapat dibaca mesin tentang kesiapan pemasangan, metadata keamanan, pemeliharaan, dan risiko adopsi.

Trust Score OpenAgentSkill v5

Tinjauan manusia sebelum pemasangan

Choose a stronger alternative or inspect the source manually before any install attempt.

CodexClaude CodeCursorOpenAgentSkill CLI

Star

60 star GitHub

Aktivitas repositori

60 star dan 23 fork

Pemeliharaan

1 hari sejak push

Lisensi

MIT

Pasang

npx skills add promovaweb/specsfy --skill fortify-development

Keamanan pemasangan

Jalur pemasangan paket atau runtime standar

Cakupan izin

secrets or environment access, network or browser access

Hasil Agent

Belum ada data hasil Agent

Dokumentasi

Konteks README/SKILL.md kuat

Ringkasan risiko

Tinjau sebelum produksi

  • The SKILL.md content appears truncated; the final sentence about two-factor authentication in SPA mode is incomplete, which might indicate missing content in the actual file.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, network or browser access

Kesiapan pemasangan

Jalur pemasangan tersedia

  • Jalur pemasangan tersedia
  • Bukti repositori tersedia
  • Lisensi dinyatakan
  • Belum ada bukti hasil Agent-Proven

Metadata yang dapat dibaca Agent

Data keputusan yang dapat dibaca mesin untuk skill ini.

Gunakan blok ini atau JSON tersemat untuk memutuskan apakah Agent perlu memasang skill ini, memilih alternatif, atau meminta tinjauan manusia terlebih dahulu.

Buka JSON

Tugas yang sesuai

  • alur kerja Otomasi alur kerja
  • Tim Claude Code
  • builders willing to evaluate younger projects
  • Move data between tools

Agent yang sesuai

CodexClaude CodeCursorOpenAgentSkill CLICLI

Keputusan pemasangan

Perintah
npx skills add promovaweb/specsfy --skill fortify-development
Kebijakan
Tinjau
Tinjauan manusia
Ya

Kepercayaan dan risiko

Kepercayaan
58/100
Audit
75/100
Tingkat risiko
Perlu ditinjau

Lingkar hasil

Endpoint
/api/agent/outcome
ID event
resolve
Hasil
5

Perintah pemasangan

npx skills add promovaweb/specsfy --skill fortify-development

Jangan gunakan ketika

  • Tim yang membutuhkan SLA dengan dukungan vendor
  • production agents without a repository review
  • The SKILL.md content appears truncated; the final sentence about two-factor authentication in SPA mode is incomplete, which might indicate missing content in the actual file.
  • Petunjuk izin berisiko tinggi: Secrets or environment access
  • Dependency or permission surface needs review

Keamanan Agent v2

43/100 · Hindari pemasangan otomatis

EksperimentalTinjau

Sparse or mixed signals. Useful for discovery, but not for autonomous installation.

Test manually in an isolated workspace and compare against safer alternatives.

Selesaikan via API

Sedang

Akses jaringan

Skill kemungkinan mengambil halaman jarak jauh, API, repositori, atau layanan eksternal.

Sedang

Akses sistem file

Skill dapat membaca atau menulis file proyek, dokumen, artefak yang dihasilkan, atau status workspace lokal.

Tinggi

Secrets or environment access

Skill metadata references credentials, tokens, environment variables, or secret-bearing workflows.

Sedang

Akses database

Skill dapat memeriksa skema, mengkueri database, atau bekerja dengan penyimpanan persisten.

  • Petunjuk izin berisiko tinggi: Secrets or environment access
  • Dependency or permission surface needs review

Target pemasangan

Pasang skill ini di alur Agent Anda

Gunakan endpoint publik untuk mengambil perintah, checklist keamanan, prompt target, dan tautan kanonis.

skill install

OpenAgentSkill CLI

Resolve policy, run the source installer safely, and report a verified install receipt.

$ npx --yes https://github.com/Leon-Drq/openagentskill/releases/download/cli-v0.2.1/openagentskill-0.2.1.tgz install promovaweb-fortify-development

Rencana resolusi Agent

Biarkan Agent memverifikasi kecocokan sebelum memasang.

API Resolve mengembalikan skill utama, alternatif, kebijakan keamanan, catatan audit, target pemasangan, dan prompt siap pakai.

Buka rencana teks

Agent harus memeriksa

  • Task fit and alternatives from Resolve API.
  • Audit score, trust score, and safety policy warnings.
  • Install target compatibility for Codex, Claude Code, Cursor, or CLI.

Salin prompt

Task: Use fortify-development in this workspace.
Resolve first: https://www.openagentskill.com/api/agent/resolve?task=Use%20fortify-development%20for%20an%20agent%20workflow&agent=codex&max_risk=medium
Review install handoff: https://www.openagentskill.com/api/skills/promovaweb-fortify-development/install
Install command: npx skills add promovaweb/specsfy --skill fortify-development
Before running it, summarize audit warnings, required permissions, and the fallback skill if install is risky.

Serah-terima Agent

Berikan jalur pemasangan kepada Agent, bukan direktori lain.

Gunakan endpoint publik untuk mengambil perintah, checklist keamanan, prompt target, dan tautan kanonis.

Buka API pemasangan

Prompt Agent

Use fortify-development for this task. Review https://www.openagentskill.com/api/skills/promovaweb-fortify-development/install, then install with: npx skills add promovaweb/specsfy --skill fortify-development

Metadata Registry

Profil yang dapat dibaca Agent untuk pemilihan skill otomatis.

API Registry menyediakan sinyal keputusan, kepercayaan, audit, use case, dan pemasangan tanpa mengikis UI.

Buka Manifest

Kecocokan Agent

66/100

Otomasi alur kerja

Platform

Claude Code

Laporan audit

Perlu ditinjau · 75/100

Tinjauan yang dapat dibaca mesin tentang kesiapan pemasangan, metadata keamanan, pemeliharaan, dan risiko adopsi.

Lihat laporan auditLihat laporan evaluasi

Panel keputusan Agent

Fallback candidate for Workflow automation

Prototype with this skill first; keep a fallback candidate ready.

66
Kesiapan
Prototipe
Tahap

Peran di stack

Kandidat cadangan

Kecocokan utama

Otomasi alur kerja

Label kepercayaan

Buat prototipe dulu

Jalur pemasangan

Perintah siap

Gunakan saat

  • alur kerja Otomasi alur kerja
  • Tim Claude Code
  • builders willing to evaluate younger projects

Bukti

  • recent repository activity
  • install command or GitHub repo available
  • profil kualitas 65/100
  • 6 event interaksi OpenAgentSkill

tinjau dulu

  • The SKILL.md content appears truncated; the final sentence about two-factor authentication in SPA mode is incomplete, which might indicate missing content in the actual file.

Jalur implementasi

  1. 1Pasang di Agent sandbox dan jalankan satu tugas Otomasi alur kerja dari awal hingga akhir.
  2. 2Compare output quality, latency, and failure behavior against at least one alternative.
  3. 3Promote it into production only after reviewing repository permissions, license, and maintenance signals.

Profil kepercayaan

Do not auto-install

Trust Score v5 found insufficient evidence for agent installation. Treat this as discovery material, not an executable recommendation.

58
Trust Score OpenAgentSkill

Adopsi GitHub

Periksa

60 star GitHub

Aktivitas star/fork

Periksa

60 star dan 23 fork; aktivitas issue tidak tersedia dalam metadata saat ini

Pemeliharaan terbaru

Lulus

1 hari sejak push

Kejelasan lisensi

Lulus

MIT

Sinyal positif

  • Tinjauan AI disetujui
  • Jalur pemasangan tersedia
  • Bukti repositori tersedia
  • Repositori yang baru dipelihara
  • Perintah pemasangan tidak memiliki pola berisiko tinggi yang jelas
  • Loop hasil siap tetapi membutuhkan eksekusi Agent nyata pertama

Tinjau sebelum memasang

  • The SKILL.md content appears truncated; the final sentence about two-factor authentication in SPA mode is incomplete, which might indicate missing content in the actual file.
  • Financial research output is not financial advice; require human review before any live investment decision.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, network or browser access
  • GitHub adoption: 60 GitHub stars
  • Stars/forks activity: 60 stars, 23 forks; issue activity unavailable in current metadata
  • Dependency/runtime risk: credential or environment access, network or browser surface
  • Permission surface: secrets or environment access, network or browser access
  • Belum ada laporan hasil Agent nyata
  • Tinjauan manusia diperlukan sebelum pemasangan tanpa pengawasan

Tindakan yang disarankan

Choose a stronger alternative or inspect the source manually before any install attempt.

Profil kualitas

Menjanjikan kandidat untuk alur kerja Agent

Useful candidate, but compare it with alternatives before adopting.

65
Star GitHub
60
Keterkinian
1 hari lalu
Siap dipasang
Ya
Lisensi
MIT
Tinjau sebelum memasang: The SKILL.md content appears truncated; the final sentence about two-factor authentication in SPA mode is incomplete, which might indicate missing content in the actual file.

Kecocokan alur kerja

Gunakan skill ini pada skenario berikut

Kecocokan alur kerja

Tambahkan ke alur kerja lengkap

Daftar alternatif

Bandingkan sebelum memasang

Similar skills that may fit this task.

Bandingkan semua

Ringkasan

--- name: fortify-development description: 'ACTIVATE when the user works on authentication in Laravel. This includes login, registration, password reset, email verification, two-factor authentication (2FA/TOTP/QR codes/recovery codes), passkeys, profile updates, password confirmation, or any auth-related routes and controllers. Activate when the user mentions Fortify, auth, authentication, login, register, signup, forgot password, verify email, 2FA, passkeys, WebAuthn, or references app/Actions/Fortify/, CreateNewUser, UpdateUserProfileInformation, FortifyServiceProvider, config/fortify.php, or auth guards. Fortify is the frontend-agnostic authentication backend for Laravel that registers all auth routes and controllers. Also activate when building SPA or headless authentication, customizing login redirects, overriding response contracts like LoginResponse, or configuring login throttling. Do NOT activate for Laravel Passport (OAuth2 API tokens), Socialite (OAuth social login), or non-auth Laravel features.' license: MIT metadata: author: laravel ---

# Laravel Fortify Development

Fortify is a headless authentication backend that provides authentication routes and controllers for Laravel applications.

## Documentation

Use `search-docs` for detailed Laravel Fortify patterns and documentation.

## Usage

- **Routes**: Use `list-routes` with `only_vendor: true` and `action: "Fortify"` to see all registered endpoints - **Actions**: Check `app/Actions/Fortify/` for customizable business logic (user creation, password validation, etc.) - **Config**: See `config/fortify.php` for all options including features, guards, rate limiters, and username field - **Contracts**: Look in `Laravel\Fortify\Contracts\` for overridable response classes (`LoginResponse`, `LogoutResponse`, etc.) - **Views**: All view callbacks are set in `FortifyServiceProvider::boot()` using `Fortify::loginView()`, `Fortify::registerView()`, etc.

## Available Features

Enable in `config/fortify.php` features array:

- `Features::registration()` - User registration - `Features::resetPasswords()` - Password reset via email - `Features::emailVerification()` - Requires User to implement `MustVerifyEmail` - `Features::updateProfileInformation()` - Profile updates - `Features::updatePasswords()` - Password changes - `Features::twoFactorAuthentication()` - 2FA with QR codes and recovery codes - `Features::passkeys()` - Passwordless authentication with WebAuthn passkeys

> Use `search-docs` for feature configuration options and customization patterns.

## Setup Workflows

### Two-Factor Authentication Setup

``` - [ ] Add TwoFactorAuthenticatable trait to User model - [ ] Enable feature in config/fortify.php - [ ] If the `*_add_two_factor_columns_to_users_table.php` migration is missing, publish via `php artisan vendor:publish --tag=fortify-migrations` and migrate - [ ] Set up view callbacks in FortifyServiceProvider - [ ] Create 2FA management UI - [ ] Test QR code and recovery codes ```

> Use `search-docs` for TOTP implementation and recovery code handling patterns.

### Passkeys Setup

``` - [ ] Add PasskeyAuthenticatable trait to User model and implement PasskeyUser - [ ] Enable passkeys feature in config/fortify.php - [ ] If the passkeys table migration is missing, publish via `php artisan vendor:publish --tag=fortify-migrations` and migrate - [ ] Configure passkeys relying_party_id, allowed_origins, user_handle_secret, and timeout if defaults are not suitable - [ ] Build UI with @laravel/passkeys for registration, login, confirmation, and deletion ```

> Use `search-docs` for passkey configuration options. For `@laravel/passkeys` frontend usage, refer to the package's README on npm.

### Email Verification Setup

``` - [ ] Enable emailVerification feature in config - [ ] Implement MustVerifyEmail interface on User model - [ ] Set up verifyEmailView callback - [ ] Add verified middleware to protected routes - [ ] Test verification email flow ```

> Use `search-docs` for MustVerifyEmail implementation patterns.

### Password Reset Setup

``` - [ ] Enable resetPasswords feature in config - [ ] Set up requestPasswordResetLinkView callback - [ ] Set up resetPasswordView callback - [ ] Define password.reset named route (if views disabled) - [ ] Test reset email and link flow ```

> Use `search-docs` for custom password reset flow patterns.

### SPA Authentication Setup

``` - [ ] Set 'views' => false in config/fortify.php - [ ] Install and configure Laravel Sanctum for session-based SPA authentication - [ ] Use the 'web' guard in config/fortify.php (required for session-based authentication) - [ ] Set up CSRF token handling - [ ] Test XHR authentication flows ```

> Use `search-docs` for integration and SPA authentication patterns.

#### Two-Factor Authentication in SPA Mode

When `views` is set to `false`, Fortify returns JSON responses instead of redirects.

If a user attempts to log in and two-factor authentication is enabled, the login request will return a JSON response indicating that a two-factor challenge is required:

```json { "two_factor": true } ```

## Best Practices

### Custom Authentication Logic

Override authentication behavior using `Fortify::authenticateUsing()` for custom user retrieval or `Fortify::authenticateThrough()` to customize the authentication pipeline. Override response contracts in `AppServiceProvider` for custom redirects.

### Registration Customization

Modify `app/Actions/Fortify/CreateNewUser.php` to customize user creation logic, validation rules, and additional fields.

### Rate Limiting

Configure via `fortify.limiters.login` in config. Default configuration throttles by username + IP combination.

## Key Endpoints

| Feature | Method | Endpoint | |------------------------|----------|---------------------------------------------| | Login | POST | `/login` | | Logout | POST | `/logout` | | Register | POST | `/register` | | Password Reset Request | POST | `/forgot-password` | | Password Reset | POST | `/reset-password` | | Email Verify Notice | GET | `/email/verify` | | Resend Verification | POST | `/email/verification-notification` | | Password Confirm | POST | `/user/confirm-password` | | Enable 2FA | POST | `/user/two-factor-authentication` | | Confirm 2FA | POST | `/user/confirmed-two-factor-authentication` | | 2FA Challenge | POST | `/two-factor-challenge` | | Get QR Code | GET | `/user/two-factor-qr-code` | | Recovery Codes | GET/POST | `/user/two-factor-recovery-codes` | | Passkey Login Options | GET | `/passkeys/login/options` | | Passkey Login | POST | `/passkeys/login` | | Passkey Confirm Options| GET | `/passkeys/confirm/options` | | Passkey Confirm | POST | `/passkeys/confirm` | | Passkey Options | GET | `/user/passkeys/options` | | Register Passkey | POST | `/user/passkeys` | | Delete Passkey | DELETE | `/user/passkeys/{passkey}` |

Detail teknis

Versi
1.0.0
Lisensi
MIT
Pembaruan terakhir
21 Agu 2026
Diterbitkan
21 Agu 2026

Ringkasan keputusan

Kandidat cadangan

66
Siap
Prototipe
Tahap

recent repository activity

Audit

Tinjauan pemasangan

Tinjauan pemasangan dan adopsi

75
Perlu ditinjau
Keamanan
74/100
Pemeliharaan
100/100
Pasang
92/100
Buka audit lengkapLihat laporan evaluasi

Bukti tervalidasi Agent

Bukti tervalidasi Agent

Laporan hasil setelah resolve, tinjau, pasang, dan satu eksekusi terbatas.

0
Terbukti
Needs first agent runPasang otomatis: tinjau duluTerakhir: Tidak diketahui
Tingkat sukses
Kegagalan terbaru
Hasil
0
Kualitas output
Gagal
0
Tidak relevan
0
Pemasangan
0
Diblokir risiko
0
Perlu penyiapan
0
Produksi
0

Belum ada data hasil Agent. Eksekusi pertama dapat melaporkan keberhasilan, kebutuhan setup, blok risiko, kegagalan, atau tidak relevan melalui /api/agent/outcome.

Pasang

Tambahkan ke alur Agent

Gratis dan sumber terbuka. Tinjau laporan sebelum memasang pada Agent produksi.

Siklus pertumbuhan

Kit berbagi

X

Draf berbasis skenario untuk fortify-development, siap untuk posting manual di X.

Catatan kurator
fortify-development: ACTIVATE when the user works on authentication in Laravel. This includes login, registration,...

60 stars

https://www.openagentskill.com/skills/promovaweb-fortify-development?ref=x
Buka draf X
Balasan opsional dengan perintah pemasangan
Listing + install path for fortify-development:
https://www.openagentskill.com/skills/promovaweb-fortify-development?ref=x

Install: npx skills add promovaweb/specsfy --skill fortify-development
Buka draf balasan

Sumber listing

Diindeks Registry

Dapat diklaim

Listing ini diindeks dari sumber publik dan belum ditandai resmi hingga klaim pemelihara disetujui.

Kreator
promovaweb
Diindeks oleh
Indeks komunitas OpenAgentSkill

Atribusi menautkan ke repositori publik atau profil kreator. Kreator dapat mengklaim listing untuk memperbarui sinyal kepemilikan.

Klaim skill ini

Klaim pemilik

Klaim listing skill ini

Listing Diindeks Registry ini dikaitkan dengan promovaweb, tetapi belum ditandai resmi. Klaim untuk menambahkan sinyal pemilik terverifikasi dan membuat pembaruan peluncuran, pemasangan, serta audit berikutnya lebih tepercaya.

Kit backlink kreator

Tambahkan badge bukti ke README Anda

Tampilkan listing kanonis, sinyal kepercayaan dan audit saat ini, serta bukti Agent-Proven nyata di tempat pengembang mengevaluasi repositori.

[![Listed on OpenAgentSkill](https://www.openagentskill.com/api/badge/promovaweb-fortify-development?metric=listed&label=Listed)](https://www.openagentskill.com/skills/promovaweb-fortify-development)
[![OpenAgentSkill Trust](https://www.openagentskill.com/api/badge/promovaweb-fortify-development?metric=trust&label=Trust)](https://www.openagentskill.com/skills/promovaweb-fortify-development)
[![OpenAgentSkill Audit](https://www.openagentskill.com/api/badge/promovaweb-fortify-development?metric=audit&label=Audit)](https://www.openagentskill.com/skills/promovaweb-fortify-development/audit)
[![Agent Proven](https://www.openagentskill.com/api/badge/promovaweb-fortify-development?metric=proven&label=Agent%20Proven)](https://www.openagentskill.com/skills/promovaweb-fortify-development)

Penulis

P

promovaweb

@promovaweb

Kecocokan platform

Sinyal kesehatan

Star GitHub
60
Skor kualitas
36/100
Push GitHub terakhir
21 Agu 2026
Petunjuk framework
Tidak diketahui
Tampilan OpenAgentSkill
6
Salinan pemasangan
0
Klik keluar
0

Sinyal komunitas

Bagikan apakah skill ini bermanfaat untuk alur kerja Agent Anda. Masukan gabungan meningkatkan peringkat dari waktu ke waktu.

Kepercayaan & keamanan

Do not auto-install

58
  • Adopsi GitHub60 star GitHubPeriksa
  • Aktivitas star/fork60 star dan 23 fork; aktivitas issue tidak tersedia dalam metadata saat iniPeriksa
  • Pemeliharaan terbaru1 hari sejak pushLulus
  • Kejelasan lisensiMITLulus
  • Kelengkapan README/SKILL.mdMetadata memuat konteks penggunaan dan alur kerja yang cukupLulus
  • Risiko dependensi/runtimecredential or environment access, network or browser surfacePeriksa