Installation
Install Laravel Auditor in a Laravel application with or without Laravel Boost.
Laravel Auditor is an early 0.1.x development dependency. It is an engineering tool used during auditing, not a runtime requirement and not a scanner that runs on its own.
composer require --dev mrpunyapal/laravel-auditor
Requirements: PHP 8.3+ and Laravel 12 or 13. After install, open your AI agent and ask it to use the laravel-audit skill. The agent does the reasoning; this package supplies the workflow and context.
Decide your integration path
The installation path depends on whether your project uses Laravel Boost.
Install Laravel Auditor
│
├── Using Laravel Boost?
│ └── Run boost:install / boost:update
│
└── Not using Boost?
└── Run auditor:install --agents=...
If Laravel Boost is already installed, do not run auditor:install. Boost consumes Auditor's skills and guidelines directly from the package's resources/boost/ directory. Running auditor:install would duplicate what Boost already provides.
With Laravel Boost
php artisan boost:install
After package updates:
php artisan boost:update
This exposes Auditor's audit-specific skills and guidelines through Boost. The context tools are also registered inside Boost's MCP server automatically. No additional setup is needed.
Standalone (no Boost)
php artisan auditor:install --agents=claude_code
The standalone installer publishes skills and wires the selected agent. Interactive runs ask which agents to configure. Non-interactive runs with no --agents, no config, and no project markers wire nothing.
What it does
The installer is idempotent and safe. It:
- detects whether Laravel Boost is already installed
- publishes skills, guidelines, schemas, and examples to
.ai/ - asks which AI agent(s) the project uses (or resolves them automatically)
- writes thin adapter files that point the agent at the shared audit knowledge
- copies the
laravel-auditskill into the agent's native skills directory - registers the
laravel-auditorMCP server for agents that support MCP - publishes
config/laravel-auditor.phpwhen it is missing - reports exactly what it created or left unchanged
What it will not overwrite
The installer respects your project. It will not:
- overwrite user-owned files (like a
CLAUDE.mdyou wrote yourself) unless you pass--force - duplicate Boost setup when Boost is detected
- modify application code
Agent selection
When run interactively, the installer asks which AI agents to configure (pre-selecting any that were detected). In non-interactive environments (CI, scripts), agents are resolved in this order:
- The
--agentsoption (if provided) - The
laravel-auditor.agentsconfig value - Project detection (looks for agent-specific files like
CLAUDE.md,opencode.json, or.github/copilot-instructions.md)
When none of those resolve, no agents are wired. Re-run with --agents to attach skills and MCP for a specific tool. A .github or .vscode directory alone is not treated as Copilot.
Unknown --agents values are skipped with a warning. To wire an agent that is not in the built-in list, add it under laravel-auditor.custom_agents and pass that key to --agents. See Agent setup.
Options
# Preview what would be created without writing anything:
php artisan auditor:install --dry-run
# Refresh Auditor-owned resources (skills, guidelines, adapters):
php artisan auditor:install --force
# Wire only specific agents:
php artisan auditor:install --agents=claude_code,opencode
--force refreshes Auditor-owned resources. It appends to user-owned files rather than overwriting them, unless the file already contains an <!-- laravel-auditor --> marker block, in which case it replaces that block.
Publish tags
You can also publish individual resource groups with Artisan:
php artisan vendor:publish --tag="laravel-auditor"
php artisan vendor:publish --tag="laravel-auditor-config"
php artisan vendor:publish --tag="laravel-auditor-resources"
php artisan vendor:publish --tag="laravel-auditor-schema"
php artisan vendor:publish --tag="laravel-auditor-examples"
Verify
After installation, confirm everything is wired correctly:
php artisan auditor:status
php artisan auditor:rules --applicable
auditor:status shows the package version, integration mode (Boost or standalone), audit domains, rule counts, and available context tools. auditor:rules --applicable lists only the rules that match your project's installed packages.
Next
- Agent setup — connect to your specific AI agent
- Usage — audit workflow and commands
- MCP tools — register context tools with your agent