agentsclimarketplace

Drupal review

Skill hussainweb/skills/skills/drupal/drupal-review

Skills from hussainweb

Install
npx -y skills add hussainweb/skills --skill drupal-review

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

What its author says it does

Copied from the file, not written here

Review Drupal code against team standards for Drupal 11, PHP 8.4/8.5, and modern best practices. Use this skill whenever someone asks to review a Drupal module, check a PR, audit Drupal architecture, or validate that code follows standards.

SKILL.md

4.5 KB, ~1.0k tokens by cl100k_base, as published. Nobody here has run it

Drupal Code Review

You are reviewing Drupal code against this team's established coding standards. The goal is to catch issues before they reach production — security holes, stale cache metadata, outdated PHP patterns, and architectural problems are all fair game.

References library: references/

Start by reading README.md in that directory for a quick map, then read only the reference files relevant to what you're reviewing. Don't load all 15 files — be surgical.

Step 1: Understand what to review

If $ARGUMENTS contains file paths, read those files. If the user pasted code inline, work with that. If neither, ask: "What file or directory should I review?"

Scan the code quickly to identify which categories apply before loading reference files.

Step 2: Load relevant references

Code contains...Read this reference file
*.info.yml, module structure01-module-architecture.md
Services, *.services.yml, create() factory02-services-dependency-injection.md
#[Block], #[FieldType], #[QueueWorker], plugin classes03-plugins.md
Entity classes, base field definitions04-entities.md
*.routing.yml, controllers, AccessResult05-routing-access.md
FormBase, ConfigFormBase, #ajax06-forms.md
$this->database->, hook_schema, hook_update_N07-database.md
ConfigFactoryInterface, StateInterface, TempStoreFactory08-configuration.md
#cache, render arrays, CacheableMetadata09-caching.md
User input, permissions, CSRF tokens, file uploads10-security.md
Twig templates, *.theme, *.libraries.yml, SDC11-theming.md
Test classes, UnitTestCase, KernelTestBase12-testing.md
DrushCommands, composer.json, drush.services.yml13-deployment.md
#[Hook], *.module hook functions, src/Hook/14-oop-hooks.md

Always read 15-modern-php.md when reviewing any PHP code — PHP 8.4/8.5 patterns apply everywhere. Always read 10-security.md when there is user input, file handling, or permission checks.

Step 3: Produce the review

Structure your output exactly like this:


Drupal Code Review: [filename or module name]

Critical Issues

Security vulnerabilities, broken access control, data loss risks. Must fix before merge.

Standards Violations

Deviations from Drupal 11 / PHP 8.5 coding standards. Should fix.

Recommendations

Improvements that follow best practices but aren't blocking.

Confirmed Good Practices

Patterns done correctly — acknowledge briefly so the developer knows what to keep.


For each finding:

  • Cite the reference (e.g., "→ 10-security.md: Never concatenate user input into SQL")
  • Show the problematic snippet
  • Show a corrected version

If there are no issues in a section, write "None found." — don't omit the section.

High-value checks to run on every review

These catch the most common Drupal 11 mistakes — worth checking even before reading the full reference files:

PHP / OOP patterns

  • No \Drupal:: static calls inside service classes (use constructor injection instead — statics break testability and the service container)
  • PHP native attributes used, not Doctrine annotations: #[Block(...)] not /** @Block(...) */
  • Constructor property promotion: public function __construct(private readonly FooService $foo) — the verbose property-then-assign pattern is outdated
  • All parameters, return types, and properties have type declarations

Hooks

  • Hooks implemented as #[Hook] classes in src/Hook/ (Drupal 11.1+), not as procedural functions in .module
  • hooks_converted: true set in *.info.yml if all hooks are OOP

Caching

  • Every render array has #cache with tags and contexts — missing cache metadata causes stale content for users
  • Cache context is user.roles not user for role-based variations (the user context disables page caching)

Security

  • No user input concatenated into SQL strings (use DB API placeholders)
  • No |raw in Twig on user-supplied content (Twig auto-escapes; |raw bypasses it entirely)
  • Routes have explicit requirements: keys

Config

  • Config schemas defined in config/schema/ for every key the module introduces

Keep looking

Skills are one crate of 328,083. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.