agentsclimarketplace

Drupal review

Skill hussainweb/skills/skills/drupal/drupal-review

Review Drupal code against team standards for Drupal 11, PHP 8.4/8.5, and modern best practices. Use this skill whenever someone asks to review a Drupal module, check a PR, audit Drupal architecture, or validate that code follows standards.From its SKILL.md

Install
npx -y skills add hussainweb/skills --skill drupal-review

Assembled from the repository path, not quoted from the project. Check it against their README if it does not work.

2 things to look at

  • no licenseNo license file was found in the repository. Code published without one is not open source by default, so using it at work is a question for whoever answers licensing questions where you are.
  • 0 stars0 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.

SKILL.md

4.5 KB, ~1.0k tokens by cl100k_base, as published. Nobody here has run it

Drupal Code Review

You are reviewing Drupal code against this team's established coding standards. The goal is to catch issues before they reach production — security holes, stale cache metadata, outdated PHP patterns, and architectural problems are all fair game.

References library: references/

Start by reading README.md in that directory for a quick map, then read only the reference files relevant to what you're reviewing. Don't load all 15 files — be surgical.

Step 1: Understand what to review

If $ARGUMENTS contains file paths, read those files. If the user pasted code inline, work with that. If neither, ask: "What file or directory should I review?"

Scan the code quickly to identify which categories apply before loading reference files.

Step 2: Load relevant references

Code contains...Read this reference file
*.info.yml, module structure01-module-architecture.md
Services, *.services.yml, create() factory02-services-dependency-injection.md
#[Block], #[FieldType], #[QueueWorker], plugin classes03-plugins.md
Entity classes, base field definitions04-entities.md
*.routing.yml, controllers, AccessResult05-routing-access.md
FormBase, ConfigFormBase, #ajax06-forms.md
$this->database->, hook_schema, hook_update_N07-database.md
ConfigFactoryInterface, StateInterface, TempStoreFactory08-configuration.md
#cache, render arrays, CacheableMetadata09-caching.md
User input, permissions, CSRF tokens, file uploads10-security.md
Twig templates, *.theme, *.libraries.yml, SDC11-theming.md
Test classes, UnitTestCase, KernelTestBase12-testing.md
DrushCommands, composer.json, drush.services.yml13-deployment.md
#[Hook], *.module hook functions, src/Hook/14-oop-hooks.md

Always read 15-modern-php.md when reviewing any PHP code — PHP 8.4/8.5 patterns apply everywhere. Always read 10-security.md when there is user input, file handling, or permission checks.

Step 3: Produce the review

Structure your output exactly like this:


Drupal Code Review: [filename or module name]

Critical Issues

Security vulnerabilities, broken access control, data loss risks. Must fix before merge.

Standards Violations

Deviations from Drupal 11 / PHP 8.5 coding standards. Should fix.

Recommendations

Improvements that follow best practices but aren't blocking.

Confirmed Good Practices

Patterns done correctly — acknowledge briefly so the developer knows what to keep.


For each finding:

  • Cite the reference (e.g., "→ 10-security.md: Never concatenate user input into SQL")
  • Show the problematic snippet
  • Show a corrected version

If there are no issues in a section, write "None found." — don't omit the section.

High-value checks to run on every review

These catch the most common Drupal 11 mistakes — worth checking even before reading the full reference files:

PHP / OOP patterns

  • No \Drupal:: static calls inside service classes (use constructor injection instead — statics break testability and the service container)
  • PHP native attributes used, not Doctrine annotations: #[Block(...)] not /** @Block(...) */
  • Constructor property promotion: public function __construct(private readonly FooService $foo) — the verbose property-then-assign pattern is outdated
  • All parameters, return types, and properties have type declarations

Hooks

  • Hooks implemented as #[Hook] classes in src/Hook/ (Drupal 11.1+), not as procedural functions in .module
  • hooks_converted: true set in *.info.yml if all hooks are OOP

Caching

  • Every render array has #cache with tags and contexts — missing cache metadata causes stale content for users
  • Cache context is user.roles not user for role-based variations (the user context disables page caching)

Security

  • No user input concatenated into SQL strings (use DB API placeholders)
  • No |raw in Twig on user-supplied content (Twig auto-escapes; |raw bypasses it entirely)
  • Routes have explicit requirements: keys

Config

  • Config schemas defined in config/schema/ for every key the module introduces

What ships with it: 17 files

149.5 KB alongside SKILL.md

evals/

Keep looking

Skills are one crate of 325,949. Ordering is by how many stacks a row turns up in, so the top of any crate is what has actually been picked rather than what has the most stars.