deploying-laravel-cloud
Warn
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: MEDIUMCOMMAND_EXECUTIONREMOTE_CODE_EXECUTIONEXTERNAL_DOWNLOADSDATA_EXFILTRATIONPROMPT_INJECTION
Full Analysis
- [COMMAND_EXECUTION]: Provides instructions to run arbitrary shell commands on remote cloud environments via the
cloud command:runtool. - [REMOTE_CODE_EXECUTION]: Facilitates the execution of arbitrary PHP code on remote instances using the
cloud tinkerfeature. - [EXTERNAL_DOWNLOADS]: Fetches official documentation from the well-known service domain at
https://cloud.laravel.com/docs/llms.txt. - [EXTERNAL_DOWNLOADS]: Installs the
laravel/cloud-clitool globally during setup via the Composer package manager. - [DATA_EXFILTRATION]: Accesses sensitive financial and resource usage data using the
cloud usagecommand. - [PROMPT_INJECTION]: The skill faces indirect prompt injection risks by processing external documentation and CLI output.
- Ingestion points: Remote content fetched via WebFetch and dynamic shell output.
- Boundary markers: No specific delimiters or safety instructions are used to isolate untrusted external content.
- Capability inventory: High-privilege actions including remote shell access, code execution, and environment variable modification.
- Sanitization: No explicit input validation or sanitization logic is present for data ingested from external sources.
Audit Metadata