Atlas / MCP servers / brianirish / Laravel Companion

Laravel CompanionBLOCK

mcp/brianirish/laravel-companion

A Laravel developer's MCP companion. Get the absolute best advice, recommendations, and up-to-date documentation for the entire Laravel ecosystem.

Verdict
BLOCK
Grade
F
Trust score
38 /100
Exposed tools
25 23r · 2w · 0d
Transport
stdio · streamable-http
License
MIT
Stars
38
01

Overview

From the repository's own README, as read at the audited commit. Badges and raw HTML are left out.

formerly Laravel Docs MCP Server

[](https://github.com/brianirish/laravel-mcp-companion/releases) [](https://www.python.org/downloads/) [](https://github.com/brianirish/laravel-mcp-companion/actions/workflows/ci.yaml) [](https://codecov.io/gh/brianirish/laravel-mcp-companion) [](https://github.com/brianirish/laravel-mcp-companion/blob/main/LICENSE) [](https://github.com/brianirish/laravel-mcp-companion/pkgs/container/laravel-mcp-companion) [](https://github.com/brianirish/laravel-mcp-companion) [](https://github.com/brianirish/laravel-mcp-companion)

⚠️ BETA SOFTWARE - This project is in active development. Features may change and breaking changes may occur.

Laravel MCP Companion is a documentation aggregator and navigator for the Laravel ecosystem. It centralizes and organizes high-quality documentation from across the Laravel ecosystem, making it easily discoverable through your AI assistant.

How It Compares

Read from source at commit f7df7240e8f2OBSERVED · 2026-10-08
02

Connect

Built from this server's own package name, version and transport as found in its source — not copied from anyone's documentation, so it cannot drift against a page we do not control. Replace the environment placeholders with a token scoped to the least it needs.

claude-code (oci)
claude mcp add laravel-mcp-companion:v0.13.0 -- docker run -i --rm ghcr.io/brianirish/laravel-mcp-companion:v0.13.0:None
03

Exposed tools (25)

23 read · 2 write · 0 destructive.

ToolRiskDescription
browse_docs_by_categoryread
compare_laravel_versionsreadCompare documentation files between two Laravel versions.
find_laravel_docs_for_needreadFind Laravel documentation for a specific user need.
get_doc_structureread
get_features_for_laravel_packageread
get_laravel_content_by_difficultyreadGet Laravel documentation filtered by difficulty level.
get_laravel_learning_pathreadGet a specific curated learning path.
get_laravel_package_categoriesread
get_laravel_package_inforead
get_laravel_package_recommendationsread
get_laravel_service_inforead
get_related_laravel_packagesreadGet packages related to a specific Laravel package.
laravel_docs_inforeadGet information about the documentation version and status.
list_laravel_categoriesreadList all documentation categories.
list_laravel_docsreadList all available Laravel documentation files.
list_laravel_learning_pathsreadList all available learning paths.
list_laravel_learning_resourcesreadList available learning resources.
list_laravel_servicesread
read_laravel_doc_contentread
search_external_laravel_docsread
search_laravel_docsreadSearch all aggregated documentation: core Laravel, services, packages, learning resources.
search_laravel_learning_resourcesreadSearch through learning resources.
update_external_laravel_docswrite
update_laravel_docswrite
verify_laravel_featurereadQuickly verify if a Laravel feature/topic exists in documentation.
04

Trust audit

BLOCKgrade F · trust 38/100 Do not install this without reading the findings. The audit found something that could harm you or your machine.

LayerWhat it checksResult
L0Provenance & inventoryPASS
L1Static analysis of the codeWARN
L2Instruction surface (what it tells the agent)FAIL
L3Class-specific surfacePASS
L4Behavioural (sandbox)SKIPPED

What the source does

Filesystem
declared (4 observation(s))
Network
declared (9 observation(s))
Shell
none-observed
Dependencies
not all pinned
Secrets in source
found

Findings (25)

HIGHPrompt injection · prompt.tool_poisoning · CWE-94, CWE-1427
docs/packages/filament/forms-fields-file-upload.md:114
> Important: Before using this feature, please ensure that you have read the security implications.
Why it matters. a tool description carrying instructions to the agent
Fix. tool descriptions describe the tool; nothing else
HIGHPrompt injection · prompt.tool_poisoning · CWE-94, CWE-1427
docs/packages/filament/forms-fields-file-upload.md:127
> Important: Before using this feature, please ensure that you have read the security implications.
Why it matters. a tool description carrying instructions to the agent
Fix. tool descriptions describe the tool; nothing else
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/external/envoyer/accounts/source-control.md:16
## [](#overview) Overview
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/external/envoyer/accounts/source-control.md:18
## [](#supported-providers) Supported Providers
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/external/envoyer/accounts/source-control.md:31
## [](#provider-management) Provider Management
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/external/envoyer/accounts/source-control.md:32
### [](#connecting-providers) Connecting Providers
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
HIGHPrompt injection · prompt.zero_width · CWE-94, CWE-1427
docs/external/envoyer/accounts/source-control.md:34
### [](#unlinking-providers) Unlinking Providers
Why it matters. invisible characters in instruction text
Fix. strip non-printing characters
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/10.x/configuration.md:262
php artisan down --secret="1630542a-246b-4b66-afa1-dd72a4c43515"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/11.x/configuration.md:288
php artisan down --secret="1630542a-246b-4b66-afa1-dd72a4c43515"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/12.x/configuration.md:327
php artisan down --secret="1630542a-246b-4b66-afa1-dd72a4c43515"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/13.x/configuration.md:344
php artisan down --secret="1630542a-246b-4b66-afa1-dd72a4c43515"
MEDIUMHard-coded secrets · secret.generic · CWE-798, CWE-321
docs/8.x/configuration.md:145
php artisan down --secret="1630542a-246b-4b66-afa1-dd72a4c43515"
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
docs/10.x/passport.md:156
PASSPORT_PRIVATE_KEY="-----BEGIN RSA PRIVATE KEY-----
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
docs/11.x/passport.md:135
PASSPORT_PRIVATE_KEY="-----BEGIN RSA PRIVATE KEY-----
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
docs/12.x/passport.md:144
PASSPORT_PRIVATE_KEY="-----BEGIN RSA PRIVATE KEY-----
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
docs/13.x/passport.md:145
PASSPORT_PRIVATE_KEY="-----BEGIN RSA PRIVATE KEY-----
MEDIUMHard-coded secrets · secret.private_key · CWE-798, CWE-321
docs/6.x/passport.md:199
PASSPORT_PRIVATE_KEY="-----BEGIN RSA PRIVATE KEY-----
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/.versions_cache.json
.versions_cache.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/external/envoyer/.cache_metadata.json
.cache_metadata.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/external/forge/.cache_metadata.json
.cache_metadata.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/external/nova/.cache_metadata.json
.cache_metadata.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWInventory / provenance · inv.hidden_file · CWE-1104
docs/external/vapor/.cache_metadata.json
.cache_metadata.json
Why it matters. hidden member outside the usual dotfiles
Fix. review its purpose
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/integration/test_complete_workflows.py:333
"../../outside.md",
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/protocol/test_tasks.py:86
"update_laravel_docs", {"version": "../../etc"},
LOWFilesystem / path · fs.traversal · CWE-22, CWE-59
tests/unit/test_cross_corpus_reads.py:73
"forge/../../12.x/routing.md",

Gates applied: no_behavioural_pass.

Audited 2026-10-08 · audit v0.4.1 · source sha f7df7240e8f2full audit observations/trust-audit/mcp-server/brianirish__laravel-companion.json · Report an issue / request a re-scan
05

Audit history

Every audit this server has had. A grade with a past is a grade somebody is still checking.

DateSourceVerdictGradeScoreChange
2026-10-08f7df7240e8f2BLOCKF38first audit
06

Questions

What is the Laravel Companion MCP server?

A Laravel developer's MCP companion. Get the absolute best advice, recommendations, and up-to-date documentation for the entire Laravel ecosystem.

What tools does Laravel Companion expose?

25 in total: 23 read-only, 2 that write, and 0 that can delete or overwrite. Every one is listed on this page with its risk.

Is Laravel Companion safe to connect to an agent?

No — not without reading the findings first. The audit graded it F (38/100) and found 7 critical or high issues in the source. Each one is listed on this page with the file and line it is on.

What credentials does Laravel Companion need?

It reads AUTH_AUDIENCE, AUTH_ISSUER, AUTH_JWKS_URI and AUTH_STATIC_TOKENS from the environment. Give it a token scoped to the least it needs — an agent that can be talked into calling a tool can be talked into calling it with your credentials.

How does Laravel Companion run?

It speaks stdio and streamable-http, so it runs as a local process your client starts. It is published on PyPI as laravel-mcp-companion.

How current is this page?

The grade is for one exact copy of the source (f7df7240e8f2), read on 2026-10-08. The repository is watched and re-audited when it changes.

Advertisement