Usage
Run status, context, rules, reports, and CI with Laravel Auditor.
The CLI is an installation, diagnostics, and reporting layer. The AI agent still does the reasoning.
Auditing a project end-to-end
- Install as a development dependency:
composer require --dev mrpunyapal/laravel-auditor
-
Expose the audit knowledge to your agent. With Laravel Boost:
php artisan boost:install(re-runphp artisan boost:updateafter package updates, orboost:update --discoverto pick up newly installed packages). Without Boost:php artisan auditor:install. -
(Optional) Register the read-only MCP context tools with your agent:
php artisan auditor:mcp
For example, with Claude Code:
claude mcp add -s local -t stdio laravel-auditor php artisan auditor:mcp
The agent can also gather the same facts without MCP via auditor:context.
- Ask your agent to audit the project:
Use the laravel-audit skill to audit this application. Discover the project first, scope the relevant domains, and report only evidenced findings.
The agent follows the skill workflow: Discover deterministic facts, Scope the domains that apply, Investigate with source and context, Verify high-severity claims, and Report structured findings with evidence.
- Render or gate the findings the agent produced:
php artisan auditor:report --findings=storage/auditor-findings.json --format=markdown
php artisan auditor:ci --findings=storage/auditor-findings.json --fail-on=high
Inspect the project
php artisan auditor:status
php artisan auditor:context --list
php artisan auditor:context project_info
php artisan auditor:context subsystems
php artisan auditor:context routes --output=storage/auditor-routes.json
From PHP:
use LaravelAuditor\Facades\LaravelAuditor;
LaravelAuditor::collect('models');
LaravelAuditor::rules()->count();
List rules
php artisan auditor:rules
php artisan auditor:rules --domain=security
php artisan auditor:rules --applicable
php artisan auditor:rules --json
--applicable hides packs whose packages are not installed (for example Livewire rules on an app without Livewire).
Render a report
The agent writes findings JSON. Auditor renders it.
php artisan auditor:report --example
php artisan auditor:report --findings=storage/auditor-findings.json
php artisan auditor:report --findings=storage/auditor-findings.json --format=json
php artisan auditor:report --findings=storage/auditor-findings.json --format=sarif
php artisan auditor:report --findings=storage/auditor-findings.json --output=storage/auditor-report.md
Formats: markdown, json, text, sarif.
Reports include project facts, severity and domain counts, a P0–P3 priority synthesis, evidence, and recommendations.
CI
php artisan auditor:ci --findings=storage/auditor-findings.json --fail-on=high
php artisan auditor:ci --findings=storage/auditor-findings.json --fail-on=high --format=sarif --output=auditor.sarif
CI fails when an open finding meets or exceeds --fail-on (critical, high, medium, low, info).
Configuration
Publish config/laravel-auditor.php to change the default domain list, extra rule directories, standalone resource target, and default report format.