
On the bundled invoice component: 14 findings (11 high, 2 medium, 1 low) from 10 rules, including $WIRE.deleteInvoice() with no authorization and $apiToken readable in view-source.
Who it’s for
For Laravel teams who ship Livewire components to production.
What breaks, and when
Every public method is callable from the browser through $WIRE and every public property can be rewritten by the visitor; on the sample, deleteInvoice() ran with no authorization.
What you get
• SKILL.md, an offline Node scanner (scripts/scan.js) and the 10-rule table
• file:line, severity and what the browser can call, read or rewrite
See it first
The real output of the bundled example is on getreadystack.com/skills/livewire-security-audit/ — free, no sign-up, so you see what it finds before you pay.
Install in 30 seconds
Unzip into ~/.claude/skills/, then ask Claude Code: “Can a user call any of our Livewire methods or change a property they shouldn’t? Don’t edit anything yet.”. Needs Node 16+.
What it does not do
It does not run your app or see middleware, route policies or parent classes; no network calls, no edits without your OK.
FAQ
Q: How is this different from asking Claude without the skill?
A: The skill carries a dated rule table and a scanner that reads every file, so Claude quotes the exact date and line instead of guessing from memory.
Q: How do I get the files?
A: In your Whop library after paying: the lesson “livewire-security-audit.zip”.