Cipi Agent for Laravel — webhook deploy, health check, and server integration with MCP (Model Context Protocol) support for AI assistants
Cipi Agent demonstrates solid definition quality with well-structured tool definitions across 6 tools. All tools have descriptions ranging from 73-380 characters, fitting within the 10-1024 baseline. Input schemas are present for all tools with proper JSON Schema typing. However, several tools lack parameter descriptions, and some descriptions could be more explicit about prerequisites and side effects. Tool naming follows verb-first conventions (health, deploy, logs, artisan, db_query). The logs tool is exemplary with comprehensive parameter documentation (5 params, all with descriptions and enums). The deploy and artisan tools expose write operations but lack confirmation mechanisms. Security-sensitive tools (artisan, db_query) have no documented permission gates. Error handling and recovery guidance are implicit rather than explicit in descriptions.
Get detailed information about this application: app user, PHP version, Laravel version, environment, queue/cache drivers, and Cipi configuration.
Run an Artisan command on this Laravel application (e.g. "migrate:status", "queue:size", "cache:clear"). Long-running and interactive commands are blocked.
Execute SQL queries against the application database for data investigation and debugging. Supports SELECT (read) and INSERT/UPDATE/DELETE (write). Destructive DDL (DROP TABLE, TRUNCATE, etc.) is blocked. Results are limited to 100 rows. Equivalent to running queries in "cipi app tinker".
Trigger a new zero-downtime deployment for this application. Writes a deploy trigger file; the Cipi cron picks it up and runs Deployer within 1 minute.
Check the health status of this Laravel application. Returns status of the app, database, cache, and queue worker.
Destructive tools (deploy, artisan, db_query) lack confirmation/dry-run mechanics. No idempotentHint or destructiveHint annotations present. Agents may execute irreversible operations without explicit confirmation.
artisan and db_query tools accept free-form command/query strings with no validation guidance in descriptions. Risk of SQL injection, command injection, or execution of dangerous Artisan commands (e.g., 'down', 'migrate:rollback'). Descriptions mention 'Long-running and interactive commands are blocked' and 'Destructive DDL (DROP TABLE, TRUNCATE) is blocked' but do not explain validation rules or provide error recovery guidance.
No explicit permission gates or scope declarations documented. Tools expose sensitive operations (database writes, deployment triggers, log access) without documenting required permissions or access control model. Users/agents cannot know if they have authority before calling.
| Scored | Grade | Overall | Spec posture | Rubric |
|---|---|---|---|---|
| 2026-09-23 | C | 68 | 2026-07-28+ | v2 |
Read application and infrastructure logs. Supports Laravel app logs, Nginx, PHP-FPM, queue worker, and deploy logs with optional severity filtering and keyword search. Equivalent to "cipi app logs <app> --type=<type>" on the CLI.
Error handling and recovery guidance are absent or minimal. Descriptions state what is blocked (e.g., 'Destructive DDL is blocked') but do not explain what error the LLM receives, or what to do next if an Artisan command fails. No recovery guides.
artisan tool description does not specify which commands are blocked. Only a generic statement: 'Long-running and interactive commands are blocked.' Agents cannot predict which calls will fail, forcing trial-and-error.
db_query tool description mentions a 100-row result limit but no pagination mechanism is documented. If results exceed 100 rows, agents cannot retrieve the rest. No next_cursor or offset parameters offered.
deploy tool description lacks clarity on side effects and timing. States 'Writes a deploy trigger file; the Cipi cron picks it up and runs Deployer within 1 minute', but does not clarify: Is this request idempotent? Can it be called multiple times safely? What if a deploy is already in progress?