Give StemCode durable repository instructions before asking it to edit.
Add an AGENTS.md file at the repository root for persistent project instructions. StemCode loads AGENTS.md or .agent/AGENTS.md from the workspace into the model context, so this is the right place for architecture boundaries, generated-file rules, coding conventions, validation expectations, and manual setup notes that should apply across sessions.
Prefer concrete rules the agent can act on: where important source lives, what it must not edit, which patterns it should preserve, and which checks it should run after a change.
# PHP Project Instructions
This is a PHP project.
Important source and configuration:
- composer.json and composer.lock
- app/ or src/
- tests/
- routes, configuration, migrations, and templates used by the framework
Follow these rules:
- Follow the repository's existing PHP style and Laravel, Symfony, or framework conventions.
- Do not modify vendor/, framework caches, generated files, or build output.
- Preserve validation, authorization, transaction, ORM, and queue boundaries when changing request flows.
- Reuse existing Composer packages and project abstractions before adding dependencies.
- Keep migrations and backwards compatibility in view when changing persisted data.
- Run focused PHPUnit or Pest tests plus the repository's static-analysis checks before broader validation.Commit the file with the project so the same instructions are reviewable and shared by everyone using StemCode in the repository.
Use AI across routes, services, data access, queues, and tests.
Modern PHP applications are rarely a collection of isolated scripts. Laravel and Symfony projects can include middleware, controllers, request validation, policies, services, ORM models, repositories, events, listeners, jobs, queues, notifications, static analysis, and deployment-sensitive database changes.
StemCode works directly with the repository that contains all of those pieces. It can inspect the codebase, use semantic language-server information, make tracked changes, run approved project commands, investigate failures, and review Git diffs.
Laravel, Symfony, Composer, PHPUnit, Pest, PHPStan, Psalm, Eloquent, Doctrine, queues, events, API projects, legacy modernization, and normal Git workflows can remain part of the same engineering loop.
Install StemCode and start it from your PHP project root.
Install the self-contained StemCode CLI with an npm-family package manager or the official shell installers.
npm install -g stemcodepnpm add -g stemcodeThen open the repository:
cd my-php-project
stemcodeInitialize project-specific StemCode files:
/initUse the resulting workspace configuration for reusable commands, architecture notes, project conventions, and test instructions that should stay visible and reviewable.
Use Intelephense or Phpactor for semantic navigation.
StemCode includes built-in PHP language-server definitions for Intelephense and Phpactor. That gives the agent a path to richer symbol information instead of relying entirely on text search.
Install Intelephense
npm install -g intelephenseThen refresh StemCode:
/lsp refreshInspect the detected servers:
/lspOr inspect one PHP file:
/lsp file app/Services/OrderService.phpPhpactor is also supported when the phpactor command is installed and available on PATH.
Framework conventions can hide relationships behind container bindings, interfaces, traits, inheritance, and generated code. Semantic symbol information gives StemCode another signal when tracing those relationships.
Trace a Laravel feature from route to side effects.
Before asking the agent to write code, ask it to build a map of the existing feature.
Trace order creation.
Trace the complete order creation workflow starting at the route. Include middleware, controller logic, FormRequest validation, policies, application services, Eloquent writes, events, listeners, queued jobs, and notifications.
Then ask focused follow-ups:
Find every place OrderStatus is updated and explain the allowed transitions.Show all listeners for OrderPlaced and explain which work is synchronous versus queued.When implementing a new feature, make discovery and validation part of the request:
Add an administrator action for resending an order confirmation.
Before editing:
- find existing admin authorization patterns
- inspect the order controller and service structure
- identify the existing notification
- find audit and logging conventions
- identify relevant tests
Then implement the feature, run the relevant tests, and review the Git diff.Use the same repository workflow with Symfony.
StemCode is framework-agnostic. In a Symfony repository, ask it to trace controllers, services, handlers, Doctrine repositories, event subscribers, Messenger handlers, and external integrations.
Understand service boundaries.
Trace this request from the route through the controller, services, Doctrine repositories, domain events, and external API calls.
Review background work.
Review this Messenger handler for idempotency, retry behavior, transaction boundaries, duplicate delivery, and failure handling.
Run the project's real PHP test suite after edits.
StemCode can run approved shell commands, so validation can use the same test entry points your team already has.
Framework test runner.
php artisan test
php artisan test --filter=OrderTestDirect project tooling.
vendor/bin/phpunit
vendor/bin/pestA useful instruction for large suites is to start narrow:
Implement the fix and run the smallest relevant test scope first. If it passes, run the broader suite.Add a reusable PHP validation command
Teams can turn Composer, tests, and static analysis into a project command under .stemcode/commands. After this file is committed, developers can run it in StemCode as /php-validate.
---
name: php-validate
description: Install PHP dependencies and run tests plus analysis
args: ["testScope"]
---
Validate the PHP workspace using Composer and project-local tools.
Run these commands in order:
1. composer install
2. php artisan test $testScope
3. vendor/bin/phpstan analyse
If this is not a Laravel project, replace step 2 with vendor/bin/phpunit
or vendor/bin/pest. If a command fails, stop, summarize the failure,
identify the most relevant files, and explain the next fix before editing.Important allow-list checks
Composer and framework test runners can write dependency directories, caches, logs, and generated files, so keep shell permissions explicit:
/permissions
/rules
/allow shell "composer *"
/allow shell "php artisan test *"
/allow shell "vendor/bin/phpunit *"
/allow shell "vendor/bin/pest *"
/allow shell "vendor/bin/phpstan *"The important tool categories are repository file read/search, PHP language-server inspection, shell execution for Composer, tests, and analysis, and file writes only when you ask StemCode to implement a fix.
Use failing tests as an investigation starting point
Run the failing test and identify the root cause before editing code. Check production behavior, fixtures, database setup, container bindings, and mocks.Make PHPStan and Psalm part of the AI feedback loop.
Static analysis is one of the best guardrails for AI-assisted PHP changes because it catches type and contract problems before runtime.
Analyze affected code.
vendor/bin/phpstan analyseAsk StemCode to fix only issues introduced by the current change and avoid unrelated cleanup.
Separate new issues from old ones.
vendor/bin/psalmHave the agent distinguish new warnings from pre-existing project debt before making additional edits.
Formatting
Laravel projects can keep Pint in the same validation workflow:
vendor/bin/pintReview data access across serialization and service boundaries.
ORM performance problems often appear outside the query itself. API resources, accessors, loops, lazy relationships, service methods, and transaction boundaries can all affect behavior.
Look for N+1 queries.
Review the order listing flow for N+1 queries. Check controllers, resources, service code, relationships, accessors, and serialization.
Inspect entity loading.
Review repository queries for excessive joins, unexpected lazy loading, large entity graphs, and transaction-boundary mistakes.
For database migrations, ask specifically about destructive operations, lock duration, backwards compatibility, and staged deployment.
Use planning mode before modernizing legacy PHP.
A large controller or service is easier to refactor when the agent first identifies responsibilities, callers, framework bindings, tests, and externally visible behavior.
Analyze this controller and separate HTTP responsibilities from business rules. Show me a refactoring plan without modifying files.Switch to planning mode for the design pass:
/profile planThen ask for a safe migration sequence:
Propose a staged migration toward an application service while preserving current behavior and tests.The same approach works for Symfony service extraction, Doctrine repository changes, and gradual modernization of legacy PHP codebases.
Keep Laravel and Symfony conventions with the codebase.
StemCode workspace memory can store rules that your team wants the agent to apply consistently.
Example Laravel conventions
Controllers contain HTTP orchestration only.
Use FormRequest classes for complex request validation.
Use policies for resource authorization.
Business workflows belong in application services.
Queued jobs must be idempotent.
Multi-write database workflows require explicit transactions.Example test strategy
Unit tests: php artisan test --testsuite=Unit
Feature tests: php artisan test --testsuite=Feature
Static analysis: vendor/bin/phpstan analyse
Formatting: vendor/bin/pintRun a PHP-specific review before opening the pull request.
Review the current Git diff as a senior PHP reviewer.
Focus on:
- correctness and regressions
- authorization and validation
- Eloquent or Doctrine query behavior
- transaction boundaries
- queue and retry behavior
- error handling
- backward compatibility
- static-analysis impact
- missing testsOr pipe the diff directly:
git diff | stemcode --stdin --profile reviewUnderstand → plan → implement → test → analyze → review. PHPUnit, Pest, PHPStan, Psalm, Composer, framework tooling, Git, and human review stay part of the validation process.
StemCode for PHP developers: common questions.
Does StemCode work with Laravel?
Yes. StemCode works against the repository and can use the project's existing Laravel, Composer, test, static-analysis, and formatting commands.
Does StemCode work with Symfony?
Yes. It can inspect Symfony services, controllers, Doctrine code, Messenger handlers, configuration, and the surrounding project structure.
Can StemCode run PHPUnit or Pest?
Yes. Approved shell commands can invoke vendor/bin/phpunit, vendor/bin/pest, php artisan test, or repository-specific Composer scripts.
Does StemCode support PHP code intelligence?
Yes. Its built-in language-server registry includes Intelephense and Phpactor support for PHP files.
Can StemCode run PHPStan?
Yes. You can include PHPStan or Psalm in the validation steps for a change and ask StemCode to focus on newly introduced issues.
Put StemCode to work in a real repository.
Install StemCode, open the project you already work in, and begin with a repository-understanding task before asking the agent to change code. That gives the model better context and keeps the workflow reviewable.
Start with the CLI.
npm install -g stemcode
cd your-project
stemcodeGo deeper.
Read the full StemCode documentation for providers, permissions, LSP integrations, memory, MCP, CI review, and advanced workspace configuration.
READ THE DOCS →