AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Laravel Ai Features

skill-kwhorne-elyra-skills-laravel-ai-features · by kwhorne

Build AI features in Laravel with the laravel/ai SDK - agent and tool design, structured output, conversation storage, queued AI work, testing with fakes, and cost control. Use when adding AI functionality to a Laravel app, designing agents or tools with laravel/ai, reviewing AI integration code, or wiring LLM calls into jobs and Livewire components.

No reviews yet
0 installs
35 views
0.0% view→install

Install

$ agentstack add skill-kwhorne-elyra-skills-laravel-ai-features

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-kwhorne-elyra-skills-laravel-ai-features)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
3mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Laravel Ai Features? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

Laravel AI Features

Wire LLM calls into Laravel the Laravel way: agents as small focused classes, side effects through tools, slow work on queues, and everything testable with fakes.

For model-agnostic design (evals, fallbacks, prompt contracts) see llm-feature-design — this skill is the Laravel-specific layer on top.

When to use

  • Adding AI features to a Laravel app (chat, summarization, extraction, agents)
  • Designing agents/tools with the laravel/ai SDK
  • Reviewing AI integration: error handling, cost, queueing, testing
  • "Where does the LLM call go?" in a Laravel architecture

Principles

  • Agents are classes, not config. One agent = one job-to-be-done with a tight instruction set. Five vague agents lose to one sharp one per task.
  • Side effects go through tools. The model proposes; your tool code validates and executes — with the same authorization you'd demand from a controller.
  • LLM calls are slow I/O. Anything non-interactive belongs in a queued job; anything interactive should stream.
  • Untrusted in, validated out. User input can steer the model (prompt injection); model output is parsed and schema-checked before anything acts on it.

Process

1. Place the call correctly

| Use case | Placement | |---|---| | Chat / interactive | Controller or Livewire action, streamed to the UI | | Enrichment (summarize, classify, tag) | Queued job (see laravel-queue-design) | | Bulk processing | Batched queued jobs, rate-limited queue | | Inline in a web request, blocking | Almost never — only sub-second, cached, or trivial calls |

2. Design the agent

  • One agent class per task, instructions versioned in code (review like any other code)
  • Inject runtime context (user, tenant, locale) explicitly — never let the model guess
  • Pick the smallest model that passes your eval set; make the model a constructor/config concern so it's swappable

3. Design the tools

  • Tool = capability boundary. Validate parameters like a FormRequest; authorize against the acting user, not "the agent"
  • Destructive operations: tool creates a pending action requiring confirmation, or is simply not exposed
  • Return small, structured results — the tool result is prompt context and costs tokens
  • Log every tool invocation with arguments (audit trail for "why did the AI do that?")

4. Demand structured output

  • Schema-constrained responses for anything programmatic; map to DTOs/enums at the boundary
  • Validate before use; one retry with the validation error fed back, then fallback (default value, human queue, degraded UX)
  • Give the model an explicit out (null / "unknown") — or it will invent one

5. Handle conversation state

  • Use the SDK's conversation storage for chat history; cap context (last N messages or a rolling summary) — unbounded history is unbounded cost
  • Multi-tenant: conversations scoped by tenant/user like any other model, in queries and policies

6. Test it

  • Fake at the SDK boundary in feature tests: assert your code's behavior given a canned AI response — including a malformed one
  • Tools: plain unit tests (they're just classes)
  • Keep a small real-call eval suite (@group ai-evals), run on prompt/model changes, not in CI's hot path
  • Never let CI depend on a live LLM API for correctness

7. Control cost and failure

  • Token/request budgets per user or tenant (rate limiter); track cost per feature in logs/metrics
  • Timeouts + retry-with-backoff on provider errors; circuit-break to fallback behavior on provider outage (see resilience-patterns)
  • Cache deterministic calls (same input → same enrichment) keyed on a content hash + prompt version

Output format

## AI feature: 

**Agent:**  — task, model, instruction version.
**Placement:** streamed controller / queued job / batch.

### Tools
| Tool | Validates | Authorizes | Destructive? |
|------|-----------|------------|--------------|
| …    | …         | policy X   | no / confirm-gated |

### Output contract
Schema: … → on invalid: retry ×1 → fallback: …

### Tests
Faked: … | Evals: N cases (manual trigger)

### Cost guards
Budget: …/user/day, cache: …, circuit breaker: …

Anti-patterns

  • ❌ Synchronous LLM call in a web request with no timeout, spinner, or fallback
  • ❌ Tools that execute without authorization because "the agent decided"
  • ❌ Parsing free-text model output with regex instead of structured output
  • ❌ CI that calls a real LLM API — slow, flaky, expensive, nondeterministic
  • ❌ Unbounded conversation history shipped to the model on every message
  • ❌ Prompt instructions edited ad hoc with no version trail
  • ❌ One mega-agent with twenty tools instead of focused agents per task

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.