laravel-docs

Fail

Audited by Snyk on Jul 21, 2026

Risk Level: CRITICAL
Full Analysis

CRITICAL E006: Malicious code pattern detected in skill scripts.

  • Malicious code pattern detected (high risk: 1.00). The AI/MCP documentation includes an exposed MCP server (http/stdio) plus example tools/resources that allow remote AI assistants to run Artisan commands, execute arbitrary SELECT SQL and return User::all()->toJson(), which together constitute a high-risk remote-access / data-exfiltration/backdoor capability if exposed to untrusted agents.

MEDIUM W009: Direct money access capability detected (payment gateways, crypto, banking).

  • Direct money access detected (high risk: 1.00). The skill documentation explicitly references payment gateway integrations (Laravel Cashier for Stripe and Paddle, and a Billing docs link). These are specific tools/APIs for payment processing and thus constitute direct financial execution capability.

Issues (2)

E006
CRITICAL

Malicious code pattern detected in skill scripts.

W009
MEDIUM

Direct money access capability detected (payment gateways, crypto, banking).

Audit Metadata
Risk Level
CRITICAL
Analyzed
Jul 21, 2026, 08:27 PM
Issues
2
Security Audit — snyk — laravel-docs