ClawAudit verdict
laravel-cloud
Laravel Cloud infrastructure management via official REST API using user-provided API token — all operations (apps, environments, deployments, databases) match documented DevOps management purpose.
⚠ Flagged for review — coarse, uncorroborated signal, not a confirmed exploit. Review the config yourself before installing.
Automated static analysis — not a human review. ClawAudit flags capabilities, not confirmed intent, and can produce false positives. Disagree with this verdict? Use Dispute below.
Findings (2)
Possible hardcoded credential
SKILL.md · code · TOKEN="your-token-here
Opens WebSocket connection
scripts/laravel-cloud.sh · prose · downgraded · websocket
Permissions & capabilities
Requires 1 environment variable. (1 sensitive: [LARAVEL_CLOUD_API_TOKEN]). Requires 1 system binary.
Is this flag fair?
Thanks — recorded.