laravel-best-practices
laravel/boost
Apply Laravel best practices to PHP code: controllers, models, queries, security, validation, and architecture.
What is laravel-best-practices?
A comprehensive guide for writing, reviewing, and refactoring Laravel PHP code. Use this skill when working with controllers, models, migrations, Eloquent queries, jobs, policies, and other Laravel components to ensure consistency, performance, security, and maintainability.
- Identifies and prevents N+1 query problems and database performance issues
- Guides authorization, security patterns, input validation, and secret management
- Reviews controller routing, middleware, form requests, and resource handling
- Ensures proper job configuration, queue setup, caching strategies, and error handling
- Validates Eloquent model relationships, scopes, casts, and query optimization
- Enforces architectural consistency across service classes, actions, and application structure
How to install laravel-best-practices
npx skills add https://github.com/laravel/boost --skill laravel-best-practices- Laravel framework installed in the project
- Familiarity with Laravel core concepts (controllers, models, routes, middleware)
How to use laravel-best-practices
- 1.Check existing patterns in nearby files and the codebase before applying rules
- 2.Map your changes to relevant rule files in the index (db-performance, eloquent, security, validation, routing, etc.)
- 3.Read the mapped rule files before making edits
- 4.Make the smallest coherent change that maintains the application's existing architecture
- 5.Verify Laravel version-specific APIs using search-docs or framework inspection
- 6.Run tests and formatting checks, then review your diff against all mapped rules
Use cases
- Writing new Laravel controllers, models, or service classes with correct patterns
- Refactoring existing Laravel code to follow framework best practices and eliminate performance issues
- Reviewing Laravel pull requests to catch security, N+1, and architectural inconsistencies
- Optimizing Eloquent queries and database access patterns in large applications
- Setting up jobs, scheduled commands, caching, and queue configuration correctly
- Laravel backend developers
- PHP developers building or maintaining Laravel applications
- Code reviewers ensuring Laravel project consistency
- Developers optimizing Laravel application performance
laravel-best-practices FAQ
No. Check what the application already does first. Consistency is more important than following a theoretically better pattern. Only deviate for correctness or security defects.
Read `rules/db-performance.md` for query count, eager loading, indexes, and large dataset handling. For complex queries, also see `rules/advanced-queries.md`.
Read `rules/security.md` for authentication, authorization, input safety, and secrets. Read `rules/validation.md` specifically for Form Requests and validation rules.
Map your affected concerns to the rule index. For example, if modifying a model relationship, read `rules/eloquent.md`. If adding a job, read `rules/queue-jobs.md`. Cross-cutting changes often need multiple rule files.
No, unless the existing pattern has a correctness or security defect. Keep the application's architecture and naming consistent instead of introducing a second way to solve the same problem.
Full instructions (SKILL.md)
Source of truth, from laravel/boost.
name: laravel-best-practices description: "Apply this skill whenever writing, reviewing, or refactoring Laravel PHP code. This includes creating or modifying controllers, models, migrations, form requests, policies, jobs, scheduled commands, service classes, and Eloquent queries. Triggers for N+1 and query performance issues, caching strategies, authorization and security patterns, validation, error handling, queue and job configuration, route definitions, and architectural decisions. Also use for Laravel code reviews and refactoring existing Laravel code to follow best practices. Covers any task involving Laravel backend PHP code patterns." license: MIT metadata: author: laravel
Laravel Best Practices
Best practices for Laravel, organized as an index of rule files. Each rule file teaches what to do and why. For exact API syntax, verify with search-docs.
Consistency First
Before applying any rule, check what the application already does. Laravel offers multiple valid approaches, and the best choice is the one the codebase already uses, even if another pattern would be theoretically better. Inconsistency is worse than a suboptimal pattern.
Check sibling files, related controllers, models, or tests for established patterns. If one exists, follow it. Don't introduce a second way. These rules are defaults for when no pattern exists yet, not overrides.
How to Apply
- Check the changed files, nearby code, project configuration, and relevant tests for established patterns. Deviate only for a correctness or security defect, and call the deviation out.
- Map every affected concern to the rule index below. Read each mapped rule file before editing. Skip unrelated rule files.
- Make the smallest coherent change. Keep the application's architecture and naming instead of introducing a second pattern for the same job.
- Verify version-sensitive Laravel APIs for the installed version with
search-docs, or inspect the installed framework when it is unavailable. - Run the narrowest relevant tests first, then the project's formatting and static-analysis checks when the change warrants them.
- Re-read the diff against every mapped rule before finishing.
Rule Index
Cross-cutting changes often need more than one rule file.
| Concern | Read |
|---|---|
| Query count, eager loading, indexes, large datasets | rules/db-performance.md |
| Subqueries, aggregates, complex ordering and query plans | rules/advanced-queries.md |
| Models, relationships, scopes, casts | rules/eloquent.md |
| Authentication, authorization, input safety, secrets, uploads | rules/security.md |
| Form Requests and validation rules | rules/validation.md |
| Controllers, route binding, resources, middleware | rules/routing.md |
| Schema changes, columns, foreign keys, indexes | rules/migrations.md |
| Jobs, retries, uniqueness, batches, Horizon | rules/queue-jobs.md |
| Cache lifetime, invalidation, locks, memoization | rules/caching.md |
| Outbound requests, retries, timeouts, fakes | rules/http-client.md |
| Exceptions, reporting, rendering, log context | rules/error-handling.md |
| Events and notifications | rules/events-notifications.md |
| Mailables and mail assertions | rules/mail.md |
| Scheduled tasks and overlap protection | rules/scheduling.md |
| Collections, lazy iteration, bulk operations | rules/collections.md |
| Blade components, attributes, composers | rules/blade-views.md |
| Environment values and application configuration | rules/config.md |
| Tests: coverage, factories, fakes, and assertions | the testing-best-practices skill |
| Naming, helpers, file boundaries, PHP style | rules/style.md |
| Actions, services, dependencies, application structure | rules/architecture.md |
Decision Rules
- Prefer framework features and existing application abstractions over new helpers or dependencies.
- Avoid speculative abstractions. Extract code when it creates a clear domain boundary, removes meaningful duplication, or makes behavior independently testable.
- Keep database access out of Blade views and prevent hidden N+1 queries across controllers, resources, jobs, and serialization.
Related skills
More from laravel/boost and the wider catalog.

tailwindcss-development
Always invoke when the user's message includes 'tailwind' in any form. Also invoke for: building responsive grid layouts (multi-column card grids, product grids), flex/grid page structures (dashboards with sidebars, fixed topbars, mobile-toggle navs), styling UI components (cards, tables, navbars, pricing sections, forms, inputs, badges), adding dark mode variants, fixing spacing or typography, and Tailwind v3/v4 work. The core use case: writing or fixing Tailwind utility classes in HTML templates (Blade, JSX, Vue). Skip for backend PHP logic, database queries, API routes, JavaScript with no HTML/CSS component, CSS file audits, build tool configuration, and vanilla CSS.
lark-meeting
Agent skill from larksuite/cli.
lark-whiteboard-cli
Design architecture, flowchart, mindmap, and sequence diagrams in Lark Whiteboard using CLI-based DSL or Mermaid.

meegle
Feishu/Lark Meego project management CLI—query, create, and manage work items, workflows, and schedules.
brag
Agent skill from latent-spaces/brag.
brag-slim
Agent skill from latent-spaces/brag.