Installation

Install Laravel Auditor in a Laravel application with or without Laravel Boost.

Laravel Auditor is an early 0.1.x development dependency. It is an engineering tool used during auditing, not a runtime requirement and not a scanner that runs on its own.

composer require --dev mrpunyapal/laravel-auditor

Requirements: PHP 8.3+ and Laravel 12 or 13. After install, open your AI agent and ask it to use the laravel-audit skill. The agent does the reasoning; this package supplies the workflow and context.

Decide your integration path

The installation path depends on whether your project uses Laravel Boost.

Install Laravel Auditor
        │
        ├── Using Laravel Boost?
        │       └── Run boost:install / boost:update
        │
        └── Not using Boost?
                └── Run auditor:install --agents=...

If Laravel Boost is already installed, do not run auditor:install. Boost consumes Auditor's skills and guidelines directly from the package's resources/boost/ directory. Running auditor:install would duplicate what Boost already provides.

With Laravel Boost

php artisan boost:install

After package updates:

php artisan boost:update

This exposes Auditor's audit-specific skills and guidelines through Boost. The context tools are also registered inside Boost's MCP server automatically. No additional setup is needed.

Standalone (no Boost)

php artisan auditor:install --agents=claude_code

The standalone installer publishes skills and wires the selected agent. Interactive runs ask which agents to configure. Non-interactive runs with no --agents, no config, and no project markers wire nothing.

What it does

The installer is idempotent and safe. It:

  • detects whether Laravel Boost is already installed
  • publishes skills, guidelines, schemas, and examples to .ai/
  • asks which AI agent(s) the project uses (or resolves them automatically)
  • writes thin adapter files that point the agent at the shared audit knowledge
  • copies the laravel-audit skill into the agent's native skills directory
  • registers the laravel-auditor MCP server for agents that support MCP
  • publishes config/laravel-auditor.php when it is missing
  • reports exactly what it created or left unchanged

What it will not overwrite

The installer respects your project. It will not:

  • overwrite user-owned files (like a CLAUDE.md you wrote yourself) unless you pass --force
  • duplicate Boost setup when Boost is detected
  • modify application code

Agent selection

When run interactively, the installer asks which AI agents to configure (pre-selecting any that were detected). In non-interactive environments (CI, scripts), agents are resolved in this order:

  1. The --agents option (if provided)
  2. The laravel-auditor.agents config value
  3. Project detection (looks for agent-specific files like CLAUDE.md, opencode.json, or .github/copilot-instructions.md)

When none of those resolve, no agents are wired. Re-run with --agents to attach skills and MCP for a specific tool. A .github or .vscode directory alone is not treated as Copilot.

Unknown --agents values are skipped with a warning. To wire an agent that is not in the built-in list, add it under laravel-auditor.custom_agents and pass that key to --agents. See Agent setup.

Options

# Preview what would be created without writing anything:
php artisan auditor:install --dry-run

# Refresh Auditor-owned resources (skills, guidelines, adapters):
php artisan auditor:install --force

# Wire only specific agents:
php artisan auditor:install --agents=claude_code,opencode

--force refreshes Auditor-owned resources. It appends to user-owned files rather than overwriting them, unless the file already contains an <!-- laravel-auditor --> marker block, in which case it replaces that block.

Publish tags

You can also publish individual resource groups with Artisan:

php artisan vendor:publish --tag="laravel-auditor"
php artisan vendor:publish --tag="laravel-auditor-config"
php artisan vendor:publish --tag="laravel-auditor-resources"
php artisan vendor:publish --tag="laravel-auditor-schema"
php artisan vendor:publish --tag="laravel-auditor-examples"

Verify

After installation, confirm everything is wired correctly:

php artisan auditor:status
php artisan auditor:rules --applicable

auditor:status shows the package version, integration mode (Boost or standalone), audit domains, rule counts, and available context tools. auditor:rules --applicable lists only the rules that match your project's installed packages.

Next

  • Agent setup — connect to your specific AI agent
  • Usage — audit workflow and commands
  • MCP tools — register context tools with your agent