All skills
asyrafhussin avatar

/php-best-practices

@e7ea05d

PHP 8.x modern patterns, PSR standards, and SOLID principles. Use when reviewing PHP code, checking type safety, auditing code quality, or ensuring PHP best practices. Triggers on "review PHP", "check PHP code", "audit PHP", or "PHP best practices".

Use this Skill: https://skilld.dev/gh/asyrafhussin/agent-skills/php-best-practices

This session only. Nothing lands on disk.

rulestype-mixed-avoid.md

≈775 tokens on demand. Your agent reads this file only when SKILL.md points to it.

Avoid Mixed Type

Avoid using mixed type; prefer specific types or union types instead.

Bad Example

<?php

declare(strict_types=1);

class DataProcessor
{
    // mixed accepts anything - no type safety
    public function process(mixed $data): mixed
    {
        // What can we do with $data? Anything!
        // What does this return? Who knows!
        return $data;
    }

    // mixed hides the actual expected types
    public function transform(mixed $input, mixed $options): mixed
    {
        // Lost all type information
    }
}

class Cache
{
    // Using mixed as a crutch
    public function get(string $key): mixed
    {
        return $this->storage[$key] ?? null;
    }

    public function set(string $key, mixed $value): void
    {
        $this->storage[$key] = $value;
    }
}

Good Example

<?php

declare(strict_types=1);

class DataProcessor
{
    // Specific union type instead of mixed
    public function process(array|object $data): array
    {
        if (is_object($data)) {
            return get_object_vars($data);
        }
        return $data;
    }

    // Generic-like approach using templates (PHPStan/Psalm)
    /**
     * @template T
     * @param T $input
     * @return T
     */
    public function transform(mixed $input): mixed
    {
        // When mixed is unavoidable, use generics for type tracking
        return $input;
    }
}

// Type-safe cache using generics
/**
 * @template T
 */
class TypedCache
{
    /** @var array<string, T> */
    private array $storage = [];

    /**
     * @param T $value
     */
    public function set(string $key, mixed $value): void
    {
        $this->storage[$key] = $value;
    }

    /**
     * @return T|null
     */
    public function get(string $key): mixed
    {
        return $this->storage[$key] ?? null;
    }
}

// Specific cache implementations
class UserCache
{
    /** @var array<string, User> */
    private array $users = [];

    public function get(string $id): ?User
    {
        return $this->users[$id] ?? null;
    }

    public function set(string $id, User $user): void
    {
        $this->users[$id] = $user;
    }
}

// When mixed is truly needed, document why
class JsonEncoder
{
    /**
     * Encodes any JSON-serializable value.
     * Mixed is appropriate here as JSON can encode any scalar, array, or object.
     *
     * @param scalar|array|object|null $value
     */
    public function encode(mixed $value): string
    {
        return json_encode($value, JSON_THROW_ON_ERROR);
    }
}

Why

  • Type Safety Lost: mixed disables all type checking
  • Hidden Bugs: Type errors only appear at runtime
  • Poor Documentation: Callers don't know what to pass
  • IDE Limitations: No autocompletion or type hints
  • Maintenance Burden: Future developers must guess types
  • Better Alternatives: Union types, generics, or specific types are clearer

Source: SKILL.md on GitHub

No alerts17d5 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    This skill is a comprehensive and safe resource for PHP 8.x best practices. It provides structured guidance on type safety, modern PHP syntax, PSR standards, and secure coding practices (such as prepared statements and password hashing). The agent is instructed to use standard environment detection commands (php -v, grep) to tailor its advice. No malicious patterns or security risks were identified.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer6mo

    39 files scanned · No issues

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at e7ea05d. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub last month.

Steadyupdated 7 months ago
Other metadata
metadata
{
  "author": "php-community",
  "version": "2.1.0",
  "phpVersion": "8.0 - 8.5"
}

README badge

README badge for asyrafhussin/agent-skills/php-best-practices