deploying-laravel-cloud

Warn

Audited by Gen Agent Trust Hub on Aug 2, 2026

Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
  • [COMMAND_EXECUTION]: Provides instructions to run arbitrary shell commands on remote cloud environments via the cloud command:run tool.
  • [REMOTE_CODE_EXECUTION]: Facilitates the execution of arbitrary PHP code on remote instances using the cloud tinker feature.
  • [EXTERNAL_DOWNLOADS]: Fetches official documentation from the well-known service domain at https://cloud.laravel.com/docs/llms.txt.
  • [EXTERNAL_DOWNLOADS]: Installs the laravel/cloud-cli tool globally during setup via the Composer package manager.
  • [DATA_EXFILTRATION]: Accesses sensitive financial and resource usage data using the cloud usage command.
  • [PROMPT_INJECTION]: The skill faces indirect prompt injection risks by processing external documentation and CLI output.
  • Ingestion points: Remote content fetched via WebFetch and dynamic shell output.
  • Boundary markers: No specific delimiters or safety instructions are used to isolate untrusted external content.
  • Capability inventory: High-privilege actions including remote shell access, code execution, and environment variable modification.
  • Sanitization: No explicit input validation or sanitization logic is present for data ingested from external sources.
Audit Metadata
Risk Level
MEDIUM
Analyzed
Aug 2, 2026, 03:58 PM
Security Audit — agent-trust-hub — deploying-laravel-cloud