007
無料Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
日本語の概要は準備中です。原文の説明を表示しています。
PSR-1 and PSR-12 coding standards knowledge base for PHP 8.5 projects. Provides quick reference for basic coding standard and extended coding style with detection patterns, examples, and antipattern identification. Use for code style audits and compliance reviews.
インストールする前に、エージェントに与えられる指示の中身を確認できます。
| Standard | Focus | Key Rules |
|---|---|---|
| PSR-1 | Basic Standard | Files, namespaces, class names |
| PSR-12 | Extended Style | Formatting, keywords, visibility |
| Rule | Requirement |
|---|---|
| Tags | MUST use <?php or <?= only |
| Encoding | MUST be UTF-8 without BOM |
| Side Effects | Files SHOULD declare symbols OR execute logic, not both |
| Rule | Requirement |
|---|---|
| Namespaces | MUST follow PSR-4 autoloading |
| Class Names | MUST be StudlyCaps (PascalCase) |
| Constants | MUST be UPPER_CASE_WITH_UNDERSCORES |
| Methods | MUST be camelCase |
// BAD: Mixing declarations and side effects
<?php
namespace App;
ini_set('display_errors', '1'); // Side effect!
class Logger { }
// GOOD: Separate files
// bootstrap.php
<?php
ini_set('display_errors', '1');
require 'vendor/autoload.php';
// Logger.php
<?php
declare(strict_types=1);
namespace App;
final readonly class Logger { }
| Rule | Requirement |
|---|---|
| PSR-1 | MUST follow PSR-1 |
| Indentation | MUST use 4 spaces (no tabs) |
| Line Length | SHOULD be ≤120 chars, MUST NOT hard wrap |
| Line Ending | MUST be Unix LF (\n) |
| Blank Line | MUST have one at end of file |
| Trailing Space | MUST NOT have trailing whitespace |
<?php
declare(strict_types=1);
namespace Vendor\Package;
use Vendor\Package\{ClassA as A, ClassB, ClassC as C};
use Vendor\Package\SomeNamespace\ClassD as D;
use function Vendor\Package\{functionA, functionB, functionC};
use const Vendor\Package\{ConstantA, ConstantB, ConstantC};
final readonly class ClassName extends ParentClass implements
InterfaceA,
InterfaceB,
InterfaceC
{
// class body
}
| Rule | Requirement |
|---|---|
| Keywords | MUST be lowercase (true, false, null) |
| Type Declarations | MUST be lowercase (int, string, bool) |
| Short Forms | MUST use bool, int (not boolean, integer) |
<?php
declare(strict_types=1);
namespace App\Domain\Entity;
use App\Domain\ValueObject\Email;
use App\Domain\ValueObject\UserId;
final readonly class User
{
public function __construct(
private UserId $id,
private Email $email,
private string $name,
private bool $isActive = true,
) {
}
public function getId(): UserId
{
return $this->id;
}
public function activate(): self
{
return new self(
$this->id,
$this->email,
$this->name,
true,
);
}
}
<?php
// if-elseif-else
if ($expr1) {
// if body
} elseif ($expr2) {
// elseif body
} else {
// else body
}
// switch
switch ($expr) {
case 0:
echo 'First case';
break;
case 1:
echo 'Second case';
// no break - intentional fall-through
default:
echo 'Default case';
break;
}
// match (PHP 8.0+)
$result = match ($expr) {
0 => 'First',
1, 2 => 'Second or third',
default => 'Other',
};
// while
while ($expr) {
// body
}
// for
for ($i = 0; $i < 10; $i++) {
// body
}
// foreach
foreach ($iterable as $key => $value) {
// body
}
// try-catch-finally
try {
// try body
} catch (FirstThrowableType $e) {
// catch body
} catch (OtherThrowableType | AnotherThrowableType $e) {
// multi-catch body
} finally {
// finally body
}
<?php
// Binary operators: space before and after
$sum = $a + $b;
$concat = $string1 . $string2;
$result = $condition ? $valueIfTrue : $valueIfFalse;
// Unary operators: no space
$i++;
--$j;
$negated = !$bool;
// Type casting: no space after cast
$intValue = (int) $floatValue;
$stringValue = (string) $intValue;
<?php
// Closure
$closure = function (int $arg1, int $arg2) use ($var1, $var2): int {
return $arg1 + $arg2 + $var1 + $var2;
};
// Long argument list
$longClosure = function (
int $argument1,
string $argument2,
bool $argument3,
) use (
$staticVar1,
$staticVar2,
): bool {
// body
};
// Arrow function (PHP 7.4+)
$multiply = fn(int $a, int $b): int => $a * $b;
<?php
$instance = new class extends ParentClass implements SomeInterface {
use SomeTrait;
public function __construct(
private readonly int $value,
) {
}
};
# Side effects in class files (functions like echo, print, header, etc.)
grep -rn "^[[:space:]]*\(echo\|print\|header\|session_start\|ini_set\)" --include="*.php" src/
# Non-StudlyCaps class names
grep -rn "^class [a-z]" --include="*.php" src/
grep -rn "^class [A-Z][a-z]*_" --include="*.php" src/
# Non-camelCase method names
grep -rn "function [A-Z]" --include="*.php" src/
grep -rn "function [a-z]*_[a-z]" --include="*.php" src/
# Tab characters instead of spaces
grep -rn $'\t' --include="*.php" src/
# Trailing whitespace
grep -rn "[[:space:]]$" --include="*.php" src/
# Long keywords (boolean instead of bool)
grep -rn "boolean\|integer" --include="*.php" src/
# Missing space after keywords
grep -rn "\(if\|for\|foreach\|while\|switch\|catch\)(" --include="*.php" src/
# Opening brace on wrong line for classes
grep -rn "^class.*{$" --include="*.php" src/
<?xml version="1.0"?>
<ruleset name="PSR-12">
<description>PSR-12 coding standard</description>
<rule ref="PSR12"/>
<file>src</file>
<file>tests</file>
<exclude-pattern>vendor/*</exclude-pattern>
<arg name="colors"/>
<arg value="sp"/>
</ruleset>
<?php
declare(strict_types=1);
use PhpCsFixer\Config;
use PhpCsFixer\Finder;
$finder = Finder::create()
->in([
__DIR__ . '/src',
__DIR__ . '/tests',
])
->name('*.php');
return (new Config())
->setRiskyAllowed(true)
->setRules([
'@PSR12' => true,
'@PHP84Migration' => true,
'declare_strict_types' => true,
'final_class' => true,
'class_attributes_separation' => [
'elements' => ['method' => 'one'],
],
'ordered_imports' => [
'sort_algorithm' => 'alpha',
'imports_order' => ['class', 'function', 'const'],
],
'no_unused_imports' => true,
'trailing_comma_in_multiline' => [
'elements' => ['arguments', 'arrays', 'parameters'],
],
])
->setFinder($finder);
| Violation | PSR | Severity | Fix |
|---|---|---|---|
| Mixed declarations and side effects | PSR-1 | CRITICAL | Separate into bootstrap file |
| snake_case class names | PSR-1 | CRITICAL | Rename to StudlyCaps |
| Tabs for indentation | PSR-12 | WARNING | Convert to 4 spaces |
| Boolean/integer type hints | PSR-12 | WARNING | Use bool/int |
| Missing strict_types | - | WARNING | Add declaration |
| Opening brace on same line | PSR-12 | INFO | Move to next line |
| Trailing whitespace | PSR-12 | INFO | Remove whitespace |
<?php
declare(strict_types=1);
namespace App\Domain\User\ValueObject;
// PSR-12 compliant Value Object
final readonly class Email
{
private function __construct(
private string $value,
) {
}
public static function fromString(string $email): self
{
if (!filter_var($email, FILTER_VALIDATE_EMAIL)) {
throw new InvalidEmailException($email);
}
return new self($email);
}
public function toString(): string
{
return $this->value;
}
}
<?php
declare(strict_types=1);
namespace App\Application\User\UseCase;
use App\Application\User\Command\CreateUserCommand;
use App\Domain\User\Entity\User;
use App\Domain\User\Repository\UserRepositoryInterface;
// PSR-12 compliant Use Case
final readonly class CreateUserHandler
{
public function __construct(
private UserRepositoryInterface $userRepository,
) {
}
public function __invoke(CreateUserCommand $command): void
{
$user = User::create(
$command->email,
$command->name,
);
$this->userRepository->save($user);
}
}
references/psr-1-basic.md - Full PSR-1 specificationreferences/psr-12-extended.md - Full PSR-12 specificationreferences/detection-patterns.md - Comprehensive detection patternsreferences/antipatterns.md - Common violations with fixesassets/report-template.md - Compliance report templateまだレビューはありません。使ってみた感想をお寄せください。
概要と使いどころ
Security audit, hardening, threat modeling (STRIDE/PASTA), Red/Blue Team, OWASP checks, code review, incident response, and infrastructure security for any project.
日本語の概要は準備中です。原文の説明を表示しています。
Guides the creation of agile user stories and Gherkin feature files. Use when the user wants to create a user story, write acceptance criteria, define Gherkin scenarios, or author BDD feature files. This should trigger for requests such as Create a user story; Write a user story; I need to write a user story. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。
Facilitates conversational discovery to create Architectural Decision Records (ADRs) for non-functional requirements using the ISO/IEC 25010:2023 quality model. Use when the user wants to document quality attributes, NFR decisions, security/performance/scalability architecture, or design systems with measurable quality criteria. This should trigger for requests such as Create ADR for Non-functional requirements; Document Non-functional requirements; Capture Non-functional requirements; Generate Non-functional requirements in an ADR. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。
Run a health check on an existing project: dependency audit, security scan, test runner detection, CI/CD evaluation, and missing configuration analysis. Maps the three execution gates (pre/in/post) from /10x-bootstrapper to an assessment framework for existing codebases. Reads optional context/foundation/stack-assessment.md from /10x-stack-assess to focus checks on identified gaps. Writes context/foundation/health-check.md with findings, prioritized fixes, and an agent-readiness verdict. Use when the user has an existing project and wants to verify its health before working with an agent. Trigger phrases: "health check", "check my project", "audit my project", "is my project healthy", "sprawdź projekt", "audyt projektu", "health-check", "project health". Use AFTER /10x-stack-assess (brownfield chain), BEFORE agent onboarding (m1-l4).
日本語の概要は準備中です。原文の説明を表示しています。
You MUST use this when building projects end-to-end. Orchestrates all 12 team roles — automatically switches between CTO, architect, PM, engineers, SRE, security, DBA, QA, and EM based on the current phase of work. Starts with brainstorming before any implementation.
日本語の概要は準備中です。原文の説明を表示しています。
Use when you need to add or configure Maven plugins in your pom.xml — including quality tools (enforcer, surefire, failsafe, jacoco, pitest, spotbugs, pmd), security scanning (OWASP), code formatting (Spotless), version management, container image build (Jib), build information tracking, and benchmarking (JMH) — through a consultative, modular step-by-step approach that only adds what you actually need. This should trigger for requests such as Add Maven plugins in pom.xml; Improve Maven plugins in pom.xml. Part of cursor-rules-java project
日本語の概要は準備中です。原文の説明を表示しています。