Agent skill

Php Rules

by softspark in softspark/ai-toolkit

PHP coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit.

Apache-2.0Auto-check: notesBackend & APIs

Install Php Rules

skills CLI
$ npx skills add softspark/ai-toolkit --skill php-rules -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install softspark/ai-toolkit php-rules --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/softspark/ai-toolkit.git skills-src && mkdir -p .claude/skills && cp -r skills-src/app/skills/php-rules .claude/skills/php-rules && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
php-rules
GitHub stars
179
Token cost
~3.8k tokens
SKILL.md length
1,771 words
Files
1
Skills in repo
112
Repo updated
First seen
Licence
Apache-2.0

At a glance

PHP coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit.

  • Tasks that involve Backend development
  • SKILL.md covers Standards, Naming, Type System and Functions, plus 21 more sections
  • Calls composer and php

What it does

Php Rules is an agent skill from softspark/ai-toolkit. PHP coding rules: style, patterns, security, testing. Triggers: .php, composer.json, Laravel, Symfony, PHPUnit, PSR-12, Composer.

Its SKILL.md is about 3.8k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Backend & APIs, covering Backend development. It works with PHP, Laravel and Symfony. The repository describes itself as: Professional-grade AI coding toolkit: 94 skills, 44 agents, multi-platform (Claude, Cursor, Windsurf, Copilot, Gemini, Cline, Roo Code, Aider, Augment, Antigravity, Codex CLI… The licence is Apache-2.0.

When your agent uses it

  • Tasks that involve Backend development

Example prompts

  • “/php-rules”

Requirements

  • Pre-approved tools (allowed-tools): Read

What it can do on your machine

Read from SKILL.md and the folder at commit d64db2b. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • composer
    • php

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Links to these hosts (documentation or services it may open):

    • github.com
    • symfony.com

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Php Rules loads about 3.8k tokens when it runs. Until then it costs about 35 tokens; SKILL.md has 1,771 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~35
When it runs · the whole SKILL.md, loaded when a task matches
~3.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NoteMentions a .env fileSKILL.md:233
    - Use `.env` files for local secrets. Use Vault or SSM for production.
  • NoteMentions a .env fileSKILL.md:234
    - Never commit `.env` to version control. Commit `.env.example` as template.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from softspark/ai-toolkit at commit d64db2b, republished under its Apache-2.0 licence (© softspark). 1,771 words, ~3,848 tokens.

Download SKILL.mdSave it as .claude/skills/php-rules/SKILL.md (or your agent's skills folder).
name
php-rules
description
PHP coding rules: style, patterns, security, testing. Triggers: .php, composer.json, Laravel, Symfony, PHPUnit, PSR-12, Composer.
allowed-tools
Read
effort
medium
user-invocable
false

PHP Rules

These rules come from app/rules/php/ in ai-toolkit. They cover the project's standards for coding style, frameworks, patterns, security, and testing in PHP. Apply them when writing or reviewing PHP code.

PHP Coding Style

Standards

  • Follow PSR-12 extended coding style.
  • Use declare(strict_types=1) at the top of every file.
  • Use PHP 8.1+ features: enums, fibers, readonly properties, intersection types.
  • Use PHP CS Fixer or Pint for automated formatting.

Naming

  • PascalCase: classes, interfaces, traits, enums.
  • camelCase: methods, functions, variables.
  • UPPER_SNAKE: class constants (public const MAX_RETRIES = 3).
  • snake_case: not used for methods. PSR convention is camelCase.
  • Suffix interfaces with Interface or prefix with contract name (project convention).

Type System

  • Use typed properties: private readonly string $name;.
  • Use union types: string|int. Use intersection types: Countable&Iterator.
  • Use enum (PHP 8.1) for fixed sets of values. Use backed enums for persistence.
  • Use readonly classes (PHP 8.2) for immutable DTOs.
  • Use constructor promotion: public function __construct(private string $name).
  • Use never return type for functions that throw or exit.

Functions

  • Use typed parameters and return types on all functions/methods.
  • Use named arguments for readability: new User(name: 'Ada', age: 36).
  • Use null-safe operator: $user?->address?->city.
  • Use match expression over switch for value mapping.
  • Use first-class callable syntax: array_map($this->transform(...), $items).

Imports and Namespaces

  • Use PSR-4 autoloading via Composer.
  • Group use statements: classes, functions, constants.
  • Never use require/include for class loading. Use Composer autoloader.
  • Use one class per file. File name matches class name.

Error Handling

  • Use exceptions for error conditions. Never return error codes.
  • Create domain exception hierarchies extending RuntimeException or LogicException.
  • Use match with throw for exhaustive error mapping.
  • Log exceptions with context using PSR-3 logger.

Configuration

  • Use PHPStan at level 8+ for static analysis.
  • Use Rector for automated code upgrades and refactoring.
  • Use .php-cs-fixer.dist.php for formatting rules.
  • Run composer analyse (PHPStan) and composer format (Pint) in CI.

PHP Frameworks

Laravel

  • Use route model binding: Route::get('/users/{user}', ...).
  • Use Form Requests for validation: class StoreUserRequest extends FormRequest.
  • Use Eloquent scopes for reusable query constraints: scopeActive().
  • Use API Resources for response transformation: UserResource::collection($users).
  • Use config() helper for configuration. Never access env() outside config files.
  • Use middleware groups for auth, throttling, and CORS.

Eloquent ORM

  • Use relationships: hasMany, belongsTo, belongsToMany, morphMany.
  • Use eager loading: User::with('posts.comments')->get() to prevent N+1.
  • Use $fillable or $guarded on models. Prefer $fillable (explicit whitelist).
  • Use model events or observers for lifecycle hooks.
  • Use upsert() for bulk insert-or-update operations.
  • Use cursor() for memory-efficient iteration over large result sets.

Symfony

  • Use attributes for route definitions: #[Route('/api/users', methods: ['GET'])].
  • Use autowiring for dependency injection. Register services in services.yaml.
  • Use Symfony Forms for complex validation and data mapping.
  • Use Messenger component for async message handling (commands, events).
  • Use Doctrine ORM with repository pattern and query builders.

Doctrine ORM

  • Use entity classes with annotations or attributes for mapping.
  • Use repositories for data access: $em->getRepository(User::class).
  • Use DQL for type-safe queries. Use QueryBuilder for dynamic queries.
  • Use migrations: bin/console doctrine:migrations:diff and migrate.
  • Use lifecycle callbacks (@PrePersist, @PostUpdate) for entity events.

Symfony Serializer

  • Default behavior uses property names as-is. Combined with PSR-12 camelCase property names, JSON output is camelCase with zero configuration.
  • Avoid adding api_platform.name_converter: CamelCaseToSnakeCaseNameConverter globally. Known side-effect (api-platform/core #6101): overrides the project-wide MetadataAwareNameConverter, affecting Messenger serializers, custom normalizers, and CLI JSON output — not just the HTTP API.
  • Use #[SerializedName] only when justified: legacy field alias during rename, external contract mapping, ObjectNormalizer cross-version stabilization. Community practice (Symfony docs, Sylius, SymfonyCasts): prefer clean property/getter naming over aliases. When using, document the reason next to the attribute.
  • Symfony 7.3.5+ ObjectNormalizer produces isActive natively for a isActive(): bool getter (symfony/symfony #62353). Older #[SerializedName('isActive')] aliases added for pre-7.3.5 ObjectNormalizer (which produced active) are redundant after upgrade — remove them.
  • Avoid duplicate getters like isActive() + getIsActive() on the same property — ObjectNormalizer treats them as two fields and serializes ambiguously. Keep one (isXxx() for booleans, getXxx() otherwise).

API Platform

  • Use API Platform for rapid REST/GraphQL API generation from entities.
  • Use #[ApiResource] attribute for automatic CRUD endpoint generation.
  • Use custom state providers and processors for business logic.
  • Use serialization groups for controlling response shape.
  • Use filters for query parameter support: pagination, search, ordering.
  • Property names on ApiResource DTOs drive JSON keys directly (see Symfony Serializer above). Write them in camelCase — that is both the Symfony default and the dominant JSON API convention.
  • Use operation_name in extraProperties for dispatch metadata (e.g., extraProperties: ['operation_name' => 'club_activate']). The key operation_name and its snake_case values are framework metadata, not JSON wire keys — keeping them snake_case is expected.

Livewire (Laravel)

  • Use Livewire components for reactive UI without JavaScript.
  • Use wire:model for two-way data binding on form inputs.
  • Use $rules property for inline validation on component properties.
  • Use component actions for server-side event handling.
  • Use wire:loading for loading state indicators.

Queues and Workers

  • Use Laravel Horizon for Redis queue monitoring and management.
  • Use Symfony Messenger with transports (Redis, AMQP, Doctrine).
  • Use dead letter queues for failed job inspection and replay.
  • Use rate limiting on queue workers to prevent downstream overload.

PHP Patterns

Error Handling

  • Use custom exception hierarchies: class DomainException extends RuntimeException.
  • Add context to exceptions: throw new UserNotFoundException(userId: $id).
  • Use match with default => throw for exhaustive error mapping.
  • Use set_exception_handler() for global uncaught exception handling.
  • Log exceptions with PSR-3 logger and structured context.

Enums and Value Objects

  • Use backed enums for database-persisted values: enum Status: string.
  • Use from() for strict conversion, tryFrom() for nullable safe conversion.
  • Implement methods on enums for behavior: public function label(): string.
  • Use readonly classes for value objects: readonly class Money { ... }.
  • Use constructor promotion for concise value object definitions.

Repository Pattern

  • Abstract data access behind repository interfaces.
  • Repositories return domain entities, not Eloquent models or arrays.
  • Use constructor injection for repository dependencies.
  • Use specifications or criteria objects for complex query building.
  • Keep repository methods focused: one query per method.

Service Layer

  • Use service classes for business logic. Keep controllers thin.
  • Use action classes (single-method services) for discrete operations.
  • Use DTOs for data transfer between layers. Never pass request objects to services.
  • Use command/query separation: commands mutate, queries read.
  • Inject dependencies via constructor. Never use app() helper in services.

Collections and Iterators

  • Use Laravel Collections or standalone illuminate/collections for data manipulation.
  • Chain map(), filter(), reduce() for declarative data transformation.
  • Use LazyCollection for memory-efficient processing of large datasets.
  • Use generators (yield) for lazy iteration over large result sets.
  • Prefer collect() pipeline over nested loops.

Async Patterns

  • Use Laravel Queues for background job processing.
  • Use dispatch() for fire-and-forget. Use Bus::chain() for sequential jobs.
  • Use ShouldQueue interface on jobs, listeners, and mailables.
  • Set $tries, $timeout, $backoff on job classes.
  • Use batch() for parallel job execution with completion callback.
Show full SKILL.md (693 more words)Show less

Event-Driven

  • Use events and listeners for decoupled side effects.
  • Use domain events for cross-boundary communication.
  • Use ShouldQueue on listeners for async event handling.
  • Use event subscribers for grouping related listeners.
  • Keep event payloads minimal: IDs and timestamps, not full objects.

Anti-Patterns

  • Fat controllers: move logic to services/actions.
  • God models: split into focused models with traits or separate classes.
  • Using DB::raw() without parameterization: SQL injection risk.
  • Static method calls for testable dependencies: use DI instead.
  • Returning mixed types: use typed returns or Result objects.

PHP Security

SQL Injection

  • Use PDO prepared statements with bound parameters for all queries.
  • Use Eloquent/Doctrine ORM for type-safe query building.
  • Never concatenate user input into SQL strings. Never use DB::raw($input).
  • Use whereIn() with arrays, not string interpolation for IN clauses.
  • Audit raw queries: DB::select(DB::raw(...)) must use ? placeholders.

XSS Prevention

  • Blade templates auto-escape with {{ }}. Never use {!! !!} with user data.
  • Use htmlspecialchars() with ENT_QUOTES when outputting outside Blade.
  • Set Content-Security-Policy headers to restrict inline scripts.
  • Sanitize rich-text input with HTMLPurifier before storage.
  • Use strip_tags() only as a secondary measure, not primary defense.

CSRF Protection

  • Use @csrf directive in all Blade forms.
  • Use VerifyCsrfToken middleware (enabled by default in Laravel).
  • Use X-CSRF-TOKEN header for AJAX requests from SPA frontends.
  • Exclude only webhook endpoints from CSRF verification (with careful validation).

Authentication

  • Use password_hash() with PASSWORD_ARGON2ID or PASSWORD_BCRYPT.
  • Use Laravel Sanctum for SPA/mobile API authentication.
  • Use Laravel Passport for full OAuth2 server implementation.
  • Implement rate limiting on login endpoints: ThrottleRequests middleware.
  • Use multi-factor authentication for admin accounts.

Authorization

  • Use Laravel Gates and Policies for authorization logic.
  • Use $this->authorize('update', $post) in controllers.
  • Check resource ownership in policies, not just role membership.
  • Default deny: use Gate::before() for super-admin bypass, nothing else.
  • Use middleware can:permission for route-level authorization.

File Upload

  • Validate file MIME type server-side. Do not trust Content-Type header.
  • Store uploads outside the web root. Use storage/ with Storage::disk().
  • Generate random filenames. Never use original user-provided filenames.
  • Set maximum file size limits in validation and PHP upload_max_filesize.
  • Scan uploaded files for malware in production environments.

Mass Assignment

  • Use $fillable on Eloquent models. Never use $guarded = [].
  • Use Form Requests to whitelist fields before model assignment.
  • Use DTOs for data transfer. Never pass $request->all() to create().
  • Audit forceFill() and forceCreate() usage (bypasses guarding).

Secrets and Configuration

  • Use .env files for local secrets. Use Vault or SSM for production.
  • Never commit .env to version control. Commit .env.example as template.
  • Use config() helper, never env() outside of config files (caching issue).
  • Never log request content containing passwords or tokens.
  • Use APP_DEBUG=false in production. Debug mode leaks sensitive data.

PHP Testing

Framework

  • Use PHPUnit 10+ as the primary test framework.
  • Use Pest PHP for expressive, minimal-boilerplate testing (built on PHPUnit).
  • Use Mockery for flexible mocking. Use PHPUnit built-in mocks for simple cases.
  • Use Testcontainers (via Docker) for integration tests with databases.

File Naming

  • Test files: FooTest.php in tests/ mirroring src/ namespace structure.
  • Unit tests: tests/Unit/. Integration tests: tests/Integration/ or tests/Feature/.
  • PHPUnit config: phpunit.xml.dist at project root.
  • Use @group annotations for test categorization.

Structure (PHPUnit)

  • Use #[Test] attribute (PHP 8) or test prefix for test methods.
  • Use setUp() / tearDown() for per-test initialization and cleanup.
  • Use #[DataProvider('dataMethodName')] for parameterized tests.
  • Name tests: testMethodName_Scenario_ExpectedResult or descriptive snake_case.

Structure (Pest)

  • Use test('description', function () { ... }) for test cases.
  • Use it('should do something', ...) for BDD-style descriptions.
  • Use beforeEach() / afterEach() for setup and teardown.
  • Use dataset() for shared test data across multiple tests.
  • Use ->with([...]) for inline parameterized tests.

Assertions

  • Use $this->assertSame() for strict equality (type + value).
  • Use $this->assertInstanceOf(Foo::class, $result) for type checks.
  • Use $this->expectException(FooException::class) before the throwing call.
  • Use $this->assertCount(), $this->assertContains() for collections.
  • Pest: use expect($value)->toBe(), ->toBeInstanceOf(), ->toThrow().

Mocking (Mockery)

  • Create mocks: $mock = Mockery::mock(UserRepository::class).
  • Stub: $mock->shouldReceive('find')->with(1)->andReturn($user).
  • Verify: $mock->shouldHaveReceived('save')->once().
  • Use Mockery::close() in tearDown() or afterEach().
  • Use spy() to verify interactions without stubbing.

Laravel Testing

  • Use RefreshDatabase trait for database test isolation.
  • Use $this->actingAs($user) for authenticated request testing.
  • Use $this->getJson('/api/users')->assertOk()->assertJsonCount(3).
  • Use factories: User::factory()->create() for test data.
  • Use Bus::fake(), Event::fake(), Mail::fake() for side-effect assertion.

Best Practices

  • Test behavior, not implementation. Do not test private methods.
  • Use in-memory SQLite for fast database tests when schema is compatible.
  • Run php artisan test --parallel for faster Laravel test execution.
  • Use --coverage-html for visual coverage reports.
  • Keep tests fast: mock external HTTP calls with Http::fake().

© softspark, Apache-2.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in app/skills/php-rules of softspark/ai-toolkit.

Open the folder on GitHubat commit d64db2b

Compare with similar skills

Php Rules next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Php Rules compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Php Rules this skillsoftspark/ai-toolkit179—~3.8kAutomated safety check: NotesApache-2.0
Sentry Php SDKgetsentry/sentry-for-ai268—~3.7kAutomated safety check: NotesApache-2.0
PHP ProJeffallan/claude-skills12k—~1.6kAutomated safety check: NotesMIT
Php ProAratKruglik/claude-laravel155—~984Automated safety check: NotesNone
Php Framework Auditwgpsec/AboutSecurity1.8k—~767Automated safety check: NotesNone
Configuring Horizoncoollabsio/coolify63k4 repos~898Automated safety check: PassMIT

Similar skills

  • Sentry Php SDK

    getsentry/sentry-for-ai

    Official

    Full Sentry SDK setup for PHP. An agent skill from getsentry/sentry-for-ai.

    268 GitHub stars~3.7k tokensUpdated today
    Backend & APIsAuto-check: notes
  • PHP Pro

    Jeffallan/claude-skills

    Writes strictly typed modern PHP 8.3+ for Laravel, Symfony and plain projects, with PHPStan level 9, PHPUnit or Pest tests, typed DTOs and secure defaults.

    12k GitHub stars~1.6k tokensUpdated 4 days ago
    Backend & APIsAuto-check: notes
  • Php Pro

    AratKruglik/claude-laravel

    A skill your agent uses when building PHP applications with modern PHP 8.3+ features, Laravel, or Symfony frameworks.

    155 GitHub stars~984 tokensUpdated 5 mo ago
    Backend & APIsAuto-check: notes
  • Php Framework Audit

    wgpsec/AboutSecurity

    PHP 框架特定安全审计。当在 PHP 白盒审计中已识别目标使用特定框架、 需要检查框架特有安全机制和常见配置缺陷时触发。

    1.8k GitHub stars~767 tokensUpdated 4 days ago
    Backend & APIsAuto-check: notes
  • Configuring Horizon

    coollabsio/coolify

    A skill your agent uses whenever the user mentions Horizon by name in a Laravel context.

    63k GitHub starsUsed in 4 repos~898 tokens
    Backend & APIsAuto-check passed
  • Fortify Development

    coollabsio/coolify

    ACTIVATE when the user works on authentication in Laravel. An agent skill from coollabsio/coolify.

    63k GitHub starsUsed in 4 repos~1.9k tokens
    Backend & APIsAuto-check passed

More from softspark/ai-toolkit

All 112 skills in this repo
  • Prepare Test Env

    softspark/ai-toolkit

    Prepare or verify a project QA environment with source identity, readiness, browser access, evidence paths and owned cleanup.

    179 GitHub stars~1.8k tokensUpdated yesterday
    Auto-check: notes
  • A11y Validate

    softspark/ai-toolkit

    Accessibility validator: WCAG 2.1 AA, EN 301 549, EAA. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~3.8k tokensUpdated yesterday
    Auto-check: notes
  • Analyze

    softspark/ai-toolkit

    Analyzes code quality, complexity, patterns across codebase.

    179 GitHub stars~1k tokensUpdated yesterday
    Auto-check passed
  • Autonomous Dev

    softspark/ai-toolkit

    Drives a brief, specification, issue or existing PR through implementation, review, tests and QA to a ready PR.

    179 GitHub stars~2.6k tokensUpdated yesterday
    Auto-check: notes
  • Brand Voice

    softspark/ai-toolkit

    Direct technical voice for docs, README, user-facing text. An agent skill from softspark/ai-toolkit.

    179 GitHub stars~2.1k tokensUpdated yesterday
    Auto-check passed
  • CI

    softspark/ai-toolkit

    Detect/generate/debug CI pipeline config (GitHub Actions, GitLab CI).

    179 GitHub stars~1.1k tokensUpdated yesterday
    Auto-check: notes

Categories

Questions about Php Rules

What does Php Rules do?

PHP coding rules: style, patterns, security, testing. An agent skill from softspark/ai-toolkit. Php Rules is an agent skill from softspark/ai-toolkit. PHP coding rules: style, patterns, security, testing.

When should I use Php Rules?

Php Rules fits situations like: tasks that involve Backend development.

How do I install Php Rules in Claude Code?

Run `npx skills add softspark/ai-toolkit --skill php-rules -a claude-code`. Or copy the skill folder (app/skills/php-rules in softspark/ai-toolkit) into .claude/skills/php-rules in your project. Claude Code loads it when a task matches its description.

How do I install Php Rules in Codex?

Run `npx skills add softspark/ai-toolkit --skill php-rules -a codex`. Or copy the skill folder (app/skills/php-rules in softspark/ai-toolkit) into .agents/skills/php-rules in your project. Codex loads it when a task matches its description.

Can I use Php Rules in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add softspark/ai-toolkit --skill php-rules -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/php-rules, .gemini/skills/php-rules, .github/skills/php-rules and .opencode/skills/php-rules in your project.

What does Php Rules need to run?

Going by SKILL.md and its folder, Php Rules needs the command-line tools its instructions call (composer and php). Its frontmatter pre-approves these tools: Read.

Does Php Rules access the network?

SKILL.md names 2 domains. As links in the text: github.com and symfony.com. This is read from the text; nothing was executed.

Is Php Rules safe to install?

Our automated static check of SKILL.md found notes only (mentions a .env file), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Php Rules use?

Php Rules is published under the Apache-2.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Php Rules use?

About 3.8k tokens (SKILL.md is roughly 15k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Php Rules?

Skills that share tags, products or a category with Php Rules: Sentry Php SDK (getsentry/sentry-for-ai, 268 stars), PHP Pro (Jeffallan/claude-skills, 12k stars), Php Pro (AratKruglik/claude-laravel, 155 stars) and Php Framework Audit (wgpsec/AboutSecurity, 1.8k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Php Rules?

softspark (a GitHub user) maintains it in softspark/ai-toolkit, which has 179 GitHub stars. The repository holds 112 skills in this directory. The repository was last updated on October 7, 2026.

Source: softspark/ai-toolkit on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.