CtrlK
BlogDocsLog inGet started
Tessl Logo

laravel-best-practices

Enforce Laravel best practices for code generation and review — SRP, skinny controllers, FormRequests, Policies, service/action classes, Eloquent, Blade safety, and Inertia conventions.

65

Quality

82%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Laravel Best Practices

When to use this skill

Implementing or refactoring controllers, FormRequests, service/action classes, jobs, policies, or observers; reviewing code or diffs; designing application layering or tests.


Key backend rules

IDRuleSeverity
SRP-001One reason to change per class; extract FormRequest + Service/Actionhigh
MVC-001Controllers orchestrate only; move queries to scopes, logic to serviceshigh
VAL-001Validation in FormRequest (rules() + authorize()); use ->validated()critical
SVC-001Business logic in a service/action with a single handle() methodhigh
AUTH-001Authorization in Policies; $this->authorize() in controllers onlyhigh
CONF-001Never call env() outside config files; use config('key') everywherehigh
BLADE-001No DB queries in Blade; eager load with with()/load() to avoid N+1critical
PERF-001Use chunk()/cursor()/lazy() for large datasets; offload to queued jobsmedium
ELO-001Prefer Eloquent + Collections; use sole(), firstOrCreate(), model castslow
NAMING-001Follow Laravel naming conventions (singular controllers, PascalCase models)medium

Key Inertia rules

See the inertia-development skill for full React + Vue conventions.

IDRule
INRT-002Page components: Page suffix, default export
INRT-006Type page props with TypeScript interfaces; usePage<T>() for shared data
INRT-007useForm for submissions — never raw axios/fetch
INRT-008usePage() for auth/flash — no prop drilling
INRT-009<Link> for internal navigation — no <a>

Review output format

For each finding: rule_id, evidence (file + lines), recommendation, patch outline, test impact.

Test generation

Prefer Pest. Cover: FormRequest rules + authorize(), Service/Action business rules (unit, mocked deps), Feature tests (happy path + validation + authz failure).

Repository
masterfermin02/laravel-agent-skill
Last updated
First committed

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.