Install
$ agentstack add skill-aliengiraffe-vigilante-vigilante-issue-implementation-on-php ✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.
Security review
✓ PassedNo issues found. Passed automated security review. · v0.1.0 How review works →
- ✓ Prompt-injection patterns
- ✓ Secret / credential exfiltration
- ✓ Dangerous shell & filesystem operations
- ✓ Untrusted network calls
- ✓ Known-malicious package signatures
What it can access
- ✓ Network access No
- ✓ Filesystem access No
- ✓ Shell / process execution No
- ✓ Environment & secrets No
- ✓ Dynamic code execution No
From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.
Verified badge
Passed review? Show it. Paste this badge into your README, it links to the public security report.
Reliability & compatibility
Declared compatibility
Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.
We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.
How agent discovery & health will work →About
Vigilante PHP Issue Implementation
Focus
- Read the prompt for detected tech stacks, process hints, and PHP security guidance before changing code.
- Follow repo-standard Composer, testing, formatting, and static-analysis workflows.
- Prefer repo-defined framework and tooling conventions over forcing a universal PHP stack.
- Keep changes scoped to the issue and do not broaden into unrelated style or lint fixes.
PHP Tooling Workflow
- Composer: use Composer-managed commands and dependency workflows. Run
composer installfor reproducible installs fromcomposer.lock. Runcomposer updateonly when intentionally upgrading dependencies. - Testing: run targeted tests for changed code first using
vendor/bin/phpunit --filter ClassNameor the framework-native test command (e.g.,php artisan test,vendor/bin/pest). Use broadervendor/bin/phpunitwhen changes cross module boundaries. Respect the repository's test configuration (phpunit.xml,phpunit.xml.dist). - Static analysis: use the repository's established static-analysis tools. When PHPStan is configured (
phpstan.neon,phpstan.neon.dist), runvendor/bin/phpstan analyse. When Psalm is configured (psalm.xml,psalm.xml.dist), runvendor/bin/psalm. Do not introduce a different analyzer unless the issue specifically requires it. - Formatting: use the repository's established code-style tool. When PHP CS Fixer is configured (
.php-cs-fixer.php,.php-cs-fixer.dist.php), runvendor/bin/php-cs-fixer fix. When PHP_CodeSniffer is configured (phpcs.xml,phpcs.xml.dist,.phpcs.xml), runvendor/bin/phpcsto check andvendor/bin/phpcbfto fix. Do not hand-format PHP code when an automated tool is available. - Dependencies: run
composer auditafter dependency changes to check for known vulnerabilities. Reviewcomposer.lockchanges for unexpected additions or version shifts.
Security
- Use
password_hash()withPASSWORD_DEFAULTorPASSWORD_BCRYPTfor password storage, andpassword_verify()to check passwords. Never usemd5(),sha1(), orcrypt()directly for passwords. - Use parameterized queries or the framework's query builder to prevent SQL injection — never interpolate user input into raw SQL.
- Use context-appropriate output encoding (
htmlspecialchars()withENT_QUOTES, framework template escaping) to prevent XSS. - Avoid
unserialize()on untrusted data — usejson_decode()andjson_encode()for data interchange. Whenunserialize()is unavoidable, restrict allowed classes with theallowed_classesoption. - Do not store secrets, tokens, or credentials in source files. Use environment variables or framework-native secret management.
- Use framework-provided CSRF protection for state-changing requests.
Mixed-Language Repositories
- A PHP repository may include a frontend layer such as a React, Vue, or other JavaScript framework colocated with the PHP backend.
- Scope PHP tooling (Composer, PHPUnit, PHPStan, Psalm, PHP CS Fixer) to PHP source files only. Do not run PHP tools against frontend code.
- When the repository also has a Node.js or TypeScript frontend, respect its own toolchain (package manager, bundler, linter, test runner) for frontend-scoped changes. Check the prompt for detected tech stacks and process hints.
- When an issue touches both PHP backend and frontend code, validate each side with its own toolchain rather than validating only one side.
- Do not assume a PHP repository is PHP-only. Read process hints and workspace signals in the prompt to understand the full repository structure.
Workflow
- Follow the base
vigilante-issue-implementationworkflow for issue comments, validation, push, and PR creation, including stacked base-branch detection (Base branch:directive in the issue body). - Use
vigilante commitfor all commit-producing operations. Do not usegit commitor GitHub CLI commit flows directly. - Any commit or amend must preserve the user's existing git author, committer, and signing configuration. Commit on behalf of the user and do not overwrite
git configwith a coding-agent identity. - Do not add
Co-authored by:trailers or any other agent attribution for Codex, Claude, Gemini, or similar coding-agent identities. - Repository-specific instructions (
AGENTS.md,README.md, CI config) remain authoritative when they are more specific than the generic PHP guidance in this skill.
Source & license
This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.
- Author: aliengiraffe
- Source: aliengiraffe/vigilante
- License: Apache-2.0
Install and usage instructions live in the source repository linked above.
Reviews
No reviews yet, be the first.
Write a review
Versions
- v0.1.0 Imported from the upstream source.