Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add anilcancakir/laravel-agent-mcp --skill agent-mcp-investigationgit clone --depth 1 https://github.com/anilcancakir/laravel-agent-mcpWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/anilcancakir/laravel-agent-mcp/agent-mcp-investigation)<a href="https://agentmods.dev/skills/anilcancakir/laravel-agent-mcp/agent-mcp-investigation"><img src="https://agentmods.dev/badge/skills/anilcancakir/laravel-agent-mcp/agent-mcp-investigation/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/anilcancakir/laravel-agent-mcp/agent-mcp-investigation"><img src="https://agentmods.dev/badge/skills/anilcancakir/laravel-agent-mcp/agent-mcp-investigation.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00155 | $0.01826 |
| Opus 5 | $0.00077 | $0.00913 |
| Sonnet 5 | $0.00031 | $0.00365 |
| Haiku 4.5 | $0.00015 | $0.00183 |
Grade A, and why
agent-mcp-investigation scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 12d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 55 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Agent MCP Investigation
Investigate a live Laravel application through the read-only agent-mcp tools exposed over MCP at /agent-mcp. The running database and logs are the source of truth: code on disk may not match what is deployed, so ground answers in tool output rather than in models, migrations, or memory. Every tool is read-only and has no write surface, so call them as often as the investigation needs.
Authentication is a single server-admin key, not a user login. Some tools are off by default and must be enabled by the operator (config_inspect, db_slow_queries, db_active_locks, cache_keys, run_artisan); a disabled tool returns a denial. Treat a denial as the expected boundary, not an error to retry around.
Start here, by task
- Any database work: call
db_schemafirst. With no argument it lists tables; pass{"table":"<name>"}for that table's columns, indexes, and foreign keys. Confirm names against the live database instead of inferring them from models or migrations. - A 500, exception, or failed job: call
read_logsbefore proposing a fix, because the log is usually the fastest path to the cause. Narrow withlevel(error, warning, info, debug) and bound volume withlines. Reach for it proactively when behavior is odd even without an explicit error. - Reading data: prefer
db_query(structured, parameterized, schema-validated) for find, filter, and count. Usedb_raw_selectonly for queries the builder cannot express (multi-table JOINs, subqueries, aggregates, window functions); it is SELECT-only and auto-limited. - Slow background processing:
queue_backlogfor depth, thenqueue_failed_jobsfor failure detail, thenhorizon_statuswhen Horizon is deployed. - Slow queries:
db_slow_queries(if enabled) for the worst offenders, thendb_index_healthanddb_missing_fk_indexesfor structural causes, anddb_table_sizesfor bloat. - Cache questions:
cache_statusfirst (stores, optimization state, session-overlap risk), thencache_inspectfor one key. - App shape:
list_routesandinspect_routefor routing,app_aboutfor environment and versions, plusschedule_list,event_list,storage_info,env_keys(names only), andconfig_inspect(structure by default; values are gated).
What ships with it
3 files beside SKILL.md in the same directory: the scripts, references and assets a skill reads on demand. Not counted in the per-session cost; read them before you install if any of them is executable.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 12d ago First seen · 55 lines · 155 tokens per session scan A 91df7c57b326
agent-mcp-investigation is a skill published in the GitHub repository anilcancakir/laravel-agent-mcp (5 stars, last pushed 2mo ago), licensed MIT. It adds 155 tokens to every session and 1,826 once invoked, about $0.0008 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-31.
Other skills, from other repositories
data-lake
Use when external catalog queries (Hive, Iceberg, S3, HDFS, Paimon) are failing, hanging, or returning stale data. Covers Hive Metastore connectivity errors, Kerberos authentication failures (keytab expiry, GSS errors, clock skew), S3 rate limiting and SSL issues, network saturation from HMS, and metadata cache TTL…
reproduce-bug
Reproduce a reported bug in googleapis/mcp-toolbox and decide whether it is real, delivering an evidence-backed verdict: confirmed, already fixed, misconfiguration, client-side, works as intended, not reproducible, or blocked. Use whenever a maintainer asks you to reproduce, verify, confirm, or investigate a bug…
triage-issues
Triage GitHub issues in the googleapis/mcp-toolbox repo: propose the correct labels (type / priority / product / status), check for duplicates, verify a bug has enough info to act on, and draft a triage comment. Use whenever a maintainer asks you to triage, label, categorize, prioritize, or "look at" an issue (or a…
postgresql-indexing
PostgreSQL indexing best practices for Prowler: index design, partial indexes, partitioned table indexing, EXPLAIN ANALYZE validation, concurrent operations, monitoring, and maintenance. Trigger: When creating or modifying PostgreSQL indexes, analyzing query performance with EXPLAIN, debugging slow queries, reviewing…
graphjin-eval
Create, extend, run, baseline, and diagnose GraphJin agent evaluations through the graphjin eval CLI.
axiom-audit-grdb-performance
Use when the user mentions GRDB performance review, slow GRDB queries, app-group database setup audit, a ValueObservation that stopped updating, or pre-release GRDB scan.