All skills
asyrafhussin avatar

/php-best-practices

@e7ea05d

PHP 8.x modern patterns, PSR standards, and SOLID principles. Use when reviewing PHP code, checking type safety, auditing code quality, or ensuring PHP best practices. Triggers on "review PHP", "check PHP code", "audit PHP", or "PHP best practices".

Use this Skill: https://skilld.dev/gh/asyrafhussin/agent-skills/php-best-practices

This session only. Nothing lands on disk.

rulesmodern-named-arguments.md

≈799 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Named Arguments

Use named arguments for clarity and flexibility (PHP 8.0+).

Bad Example

<?php

declare(strict_types=1);

// Hard to understand what each argument means
$user = new User(
    1,
    'John',
    'Doe',
    'john@example.com',
    null,
    true,
    false,
    'America/New_York'
);

// What do these booleans mean?
$result = $validator->validate($data, true, false, true);

// Must pass all preceding optional arguments
$query = $repository->findAll(null, null, null, 100);

// Confusing function calls
setcookie('session', $value, 0, '/', '', true, true);

Good Example

<?php

declare(strict_types=1);

// Clear what each argument represents
$user = new User(
    id: 1,
    firstName: 'John',
    lastName: 'Doe',
    email: 'john@example.com',
    phone: null,
    isActive: true,
    isAdmin: false,
    timezone: 'America/New_York',
);

// Self-documenting boolean parameters
$result = $validator->validate(
    data: $data,
    strict: true,
    allowEmpty: false,
    throwOnError: true,
);

// Skip optional parameters - only pass what you need
$query = $repository->findAll(limit: 100);

// Much clearer
setcookie(
    name: 'session',
    value: $value,
    secure: true,
    httponly: true,
);

// Mix positional and named (positional must come first)
function createNotification(
    string $message,
    string $title = 'Notice',
    string $type = 'info',
    bool $persistent = false,
    ?int $timeout = null,
): Notification {
    return new Notification($message, $title, $type, $persistent, $timeout);
}

// Can skip defaults and only specify what differs
$notification = createNotification(
    'Your order has shipped!',
    type: 'success',
    persistent: true,
);

// Perfect for configuration objects
class DatabaseConfig
{
    public function __construct(
        public string $host = 'localhost',
        public int $port = 3306,
        public string $database = '',
        public string $username = '',
        public string $password = '',
        public string $charset = 'utf8mb4',
        public bool $persistent = false,
        public int $timeout = 30,
    ) {}
}

$config = new DatabaseConfig(
    host: 'db.example.com',
    database: 'myapp',
    username: 'admin',
    password: 'secret',
    timeout: 60,
);

// Variadic functions with named arguments
function logMessage(
    string $message,
    string $level = 'info',
    array ...$context
): void {
    // Implementation
}

logMessage(
    message: 'User logged in',
    level: 'info',
    user: ['id' => 1, 'name' => 'John'],
    ip: ['address' => '192.168.1.1'],
);

Why

  • Self-Documenting: Argument purpose is clear at call site
  • Skip Defaults: Only pass arguments that differ from defaults
  • Order Independence: Arguments can be in any order when named
  • Boolean Clarity: Named booleans are much clearer than positional
  • Refactoring Safe: Reordering parameters won't break named calls
  • IDE Support: Full autocompletion for parameter names

Source: SKILL.md on GitHub

No alerts17d5 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill is a comprehensive and safe resource for PHP 8.x best practices. It provides structured guidance on type safety, modern PHP syntax, PSR standards, and secure coding practices (such as prepared statements and password hashing). The agent is instructed to use standard environment detection commands (php -v, grep) to tailor its advice. No malicious patterns or security risks were identified.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer6mo

    39 files scanned · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at e7ea05d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated 7 months ago
Other metadata
metadata
{
  "author": "php-community",
  "version": "2.1.0",
  "phpVersion": "8.0 - 8.5"
}

README badge

README badge for asyrafhussin/agent-skills/php-best-practices