laravel-api

Warn

Audited by Socket on May 14, 2026

1 alert found:

Security
SecurityMEDIUM
SKILL.md

SUSPICIOUS. The Laravel API guidance is mostly coherent, but the mandatory dependence on third-party fuse-ai-pilot and Context7 agents is disproportionate to the stated purpose and introduces transitive trust and supply-chain risk. No clear credential theft or malware behavior is shown, but the skill should not require unverified external agent installations to provide Laravel API guidance.

Confidence: 86%Severity: 72%
Audit Metadata
Analyzed At
May 14, 2026, 11:25 PM
Package URL
pkg:socket/skills-sh/fusengine%2Fagents%2Flaravel-api%2F@5677e274d005096a0864cb5ae75e6e07a97a30ba
Security Audit — socket — laravel-api