yaf-php-audit
Installation
SKILL.md
Yaf PHP Audit
Audit a legacy PHP project with a focus on Yaf-style structure, PHP 7.3 compatibility, and practical risk discovery.
Overview
Use this skill to produce a structured audit report for a single PHP project or to apply the same audit dimensions across many similar projects. Prefer evidence from code over assumptions. Prefer small, realistic remediation advice over broad refactors.
Audit Workflow
- Confirm the target project directory.
- Identify the main entrypoints under
public. - Read the request flow from entrypoint to controller, then to library/model/config where relevant.
- Summarize the current structure before listing risks.
- Focus on security, performance, reliability, and maintainability issues that have operational impact.
- Distinguish confirmed issues from suspected risks.
- Use
references/checklist.mdas the audit checklist and report skeleton. - Use
scripts/scan_project.shto perform a first-pass static scan before deeper manual review.