Download the PHP package timmonaghan/laravel-security-agent without Composer
On this page you can find all versions of the php package timmonaghan/laravel-security-agent. It is possible to download/install these versions without Composer. Possible dependencies are resolved automatically.
Download timmonaghan/laravel-security-agent
More information about timmonaghan/laravel-security-agent
Files in timmonaghan/laravel-security-agent
Package laravel-security-agent
Short Description AI-powered security agent for Laravel — monitors logs and responds to threats via Claude.
License MIT
Informations about the package laravel-security-agent
Laravel Security Agent
AI-powered threat detection for Laravel applications. Monitors logs for suspicious activity and uses a Claude AI agent (via tool use) to classify threats, block IPs, and alert administrators.
Requirements
- PHP 8.1+
- Laravel 8, 9, 10, 11, or 12
- Guzzle 7+
- An Anthropic API key
Installation
1. Require the package
2. Publish the config
3. Publish and run the migrations
4. (Optional) Publish the email view
5. Add environment variables to .env
6. Ensure the Laravel scheduler is running
The package auto-registers the security-agent:monitor command in the Laravel scheduler.
Admin Web Panel
Laravel Security Agent ships with a built-in web panel for monitoring and configuration.
Access it at: https://your-app.com/lsa-admin (or your configured LSA_ADMIN_PATH)
The panel provides:
- Dashboard — live counts of security events and blocked IPs, plus a table of the 10 most recent events with IP, pattern type, confidence score, and outcome.
- Settings — change the active Claude model and update the Anthropic API key without touching the server. Changes are written directly to your
.envfile. - Password protection — set
LSA_ADMIN_PASSWORDin.envto secure the panel. The panel is disabled (403) if no password is configured.
To use a custom URL path:
How It Works
- Log polling —
security-agent:monitorruns on the configured schedule and reads new log lines using a byte-offset (stored in cache), so it only processes new entries. - Pattern detection — Lines are scanned for
sqli,auth_brute_force, and404_floodpatterns. Matching batches are dispatched asAnalyzeThreatjobs. - AI analysis —
ThreatAgentsends the suspicious batch to Claude with four tools:get_ip_history,get_recent_events,block_ip,send_alert. Claude reasons over the evidence and calls tools as needed (max 10 turns). - Auto-block or alert — High-confidence threats (≥ threshold) are written to
lsa_ip_blocklistwith an expiry. Lower-confidence threats trigger an admin email. - Audit trail — Every event and agent decision is stored in
lsa_security_eventswith a human-readable summary. - API rate limiting — Built-in rate limiter prevents runaway Claude API calls under heavy log volume.
Blocklist Middleware (Optional)
The package ships a ready-made middleware. To enforce the IP blocklist on incoming requests, register it in app/Http/Kernel.php:
Rollback
Notes
- Queue driver
syncis supported (MVP default) but an async driver (Redis, database) is recommended for production to avoid blocking the scheduler process during Claude API calls. - IPv4 only in this release.
- Database tables are prefixed with
lsa_(lsa_security_events,lsa_ip_blocklist) to avoid collisions with host app tables.
All versions of laravel-security-agent with dependencies
illuminate/support Version ^8.0|^9.0|^10.0|^11.0|^12.0
illuminate/console Version ^8.0|^9.0|^10.0|^11.0|^12.0
illuminate/database Version ^8.0|^9.0|^10.0|^11.0|^12.0
illuminate/queue Version ^8.0|^9.0|^10.0|^11.0|^12.0
illuminate/mail Version ^8.0|^9.0|^10.0|^11.0|^12.0
guzzlehttp/guzzle Version ^7.0