Install
$ agentstack add mcp-stumason-laravel-kick ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ● Network access Used
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ● Environment & secrets Used
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Laravel Kick
[](https://github.com/StuMason/laravel-kick/actions/workflows/tests.yml) [](https://github.com/StuMason/laravel-kick/actions/workflows/lint.yml) [](https://packagist.org/packages/stumason/laravel-kick) [](LICENSE)
MCP server and REST API for Laravel application introspection.
Connect your MCP client directly to your Laravel app. Check health, read logs, inspect queues, run commands - all through natural conversation.
Installation
composer require stumason/laravel-kick
Add to .env:
KICK_ENABLED=true
KICK_TOKEN=your-secure-random-token
MCP Setup
Add to ~/Library/Application Support/Claude/claude_desktop_config.json:
{
"mcpServers": {
"my-app": {
"command": "npx",
"args": [
"mcp-remote@latest",
"https://your-app.com/mcp/kick",
"--transport",
"http-only",
"--header",
"Authorization:${AUTH_HEADER}"
],
"env": {
"AUTH_HEADER": "Bearer your-kick-token"
}
}
}
}
Then ask the LLM:
- "Check the health of my app"
- "Show me the last 20 ERROR entries in the logs"
- "What's failing in the queue?"
- "Clear the config cache"
Available Tools
| Tool | Description | |------|-------------| | kick_health | Database, cache, storage, redis connectivity | | kick_stats | CPU, memory, disk, uptime | | kick_logs_list | List log files | | kick_logs_read | Read logs with filtering | | kick_queue_status | Queue overview, failed jobs | | kick_queue_retry | Retry failed jobs | | kick_artisan_list | List available commands | | kick_artisan_run | Execute whitelisted commands |
REST API
The same functionality is available via HTTP:
curl -H "Authorization: Bearer $TOKEN" https://app.com/kick/health
curl -H "Authorization: Bearer $TOKEN" https://app.com/kick/stats
curl -H "Authorization: Bearer $TOKEN" "https://app.com/kick/logs/laravel.log?level=ERROR"
curl -X POST -H "Authorization: Bearer $TOKEN" -d '{"command":"cache:clear"}' https://app.com/kick/artisan
See the API documentation for all endpoints.
Security
- Disabled by default (
KICK_ENABLED=false) - Token-based authentication with scopes
- Artisan command whitelist
- Path traversal protection
- Automatic PII scrubbing from logs
Requirements
- PHP 8.4+
- Laravel 12
License
MIT
Source & license
This open-source MCP server is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: StuMason
- Source: StuMason/laravel-kick
- License: MIT
- Homepage: https://stumason.github.io/laravel-kick
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.