All skills
asyrafhussin avatar

/php-best-practices

@e7ea05d

PHP 8.x modern patterns, PSR standards, and SOLID principles. Use when reviewing PHP code, checking type safety, auditing code quality, or ensuring PHP best practices. Triggers on "review PHP", "check PHP code", "audit PHP", or "PHP best practices".

Use this Skill: https://skilld.dev/gh/asyrafhussin/agent-skills/php-best-practices

This session only. Nothing lands on disk.

rulessec-input-validation.md

≈656 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Input Validation

Always validate and sanitize all external input before using it. Never trust data from users, APIs, or any external source.

Bad Example

<?php

declare(strict_types=1);

// Using raw input directly
$name = $_POST['name'];
$email = $_POST['email'];
$age = $_POST['age'];

$user = new User($name, $email, $age);
$repository->save($user);

// Trusting query parameters
$page = $_GET['page'];
$sortBy = $_GET['sort']; // Could be "id; DROP TABLE users"
$results = $db->query("SELECT * FROM items ORDER BY {$sortBy} LIMIT {$page}");

Good Example

<?php

declare(strict_types=1);

// Validate types and constraints
function createUser(array $input): User
{
    $email = filter_var($input['email'] ?? '', FILTER_VALIDATE_EMAIL);
    if ($email === false) {
        throw new ValidationException(['email' => 'Invalid email address']);
    }

    $name = trim($input['name'] ?? '');
    if ($name === '' || mb_strlen($name) > 100) {
        throw new ValidationException(['name' => 'Name must be 1-100 characters']);
    }

    $age = filter_var($input['age'] ?? null, FILTER_VALIDATE_INT, [
        'options' => ['min_range' => 1, 'max_range' => 150],
    ]);
    if ($age === false) {
        throw new ValidationException(['age' => 'Age must be between 1 and 150']);
    }

    return new User($name, $email, $age);
}

// Whitelist for dynamic columns
function getResults(PDO $pdo, array $input): array
{
    $allowedColumns = ['id', 'name', 'created_at', 'price'];
    $sortBy = in_array($input['sort'] ?? '', $allowedColumns, true)
        ? $input['sort']
        : 'id';

    $page = max(1, (int) ($input['page'] ?? 1));
    $limit = 20;
    $offset = ($page - 1) * $limit;

    $stmt = $pdo->prepare(
        "SELECT * FROM items ORDER BY {$sortBy} LIMIT :limit OFFSET :offset"
    );
    $stmt->bindValue(':limit', $limit, PDO::PARAM_INT);
    $stmt->bindValue(':offset', $offset, PDO::PARAM_INT);
    $stmt->execute();

    return $stmt->fetchAll();
}

Why

  • Prevents Injection: SQL injection, XSS, command injection all start with unvalidated input
  • Data Integrity: Ensures only valid data enters the system
  • Whitelist Over Blacklist: Whitelist allowed values instead of trying to block bad ones
  • Type Coercion: filter_var with FILTER_VALIDATE_INT returns false for non-integers
  • Defense in Depth: Validate at every boundary, not just the frontend

Source: SKILL.md on GitHub

No alerts17d5 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill is a comprehensive and safe resource for PHP 8.x best practices. It provides structured guidance on type safety, modern PHP syntax, PSR standards, and secure coding practices (such as prepared statements and password hashing). The agent is instructed to use standard environment detection commands (php -v, grep) to tailor its advice. No malicious patterns or security risks were identified.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer6mo

    39 files scanned · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at e7ea05d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated 7 months ago
Other metadata
metadata
{
  "author": "php-community",
  "version": "2.1.0",
  "phpVersion": "8.0 - 8.5"
}

README badge

README badge for asyrafhussin/agent-skills/php-best-practices