Agent skill

WordPress Code Guard

by amElnagdy in amElnagdy/guard-skills

Reviews WordPress plugin, theme and block code after an agent writes or edits it, catching missing escaping, nonces, capability checks and unprepared queries.

MITAuto-check passedDevelopment

Install WordPress Code Guard

skills CLI
$ npx skills add amElnagdy/guard-skills --skill wp-guard -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install amElnagdy/guard-skills wp-guard --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/amElnagdy/guard-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/wp-guard .claude/skills/wp-guard && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
wp-guard
GitHub stars
1.3k
Token cost
~2.4k tokens
SKILL.md length
1,118 words
Files
7 (incl. references)
Skills in repo
5
Repo updated
First seen
Licence
MIT

At a glance

Reviews WordPress plugin, theme and block code after an agent writes or edits it, catching missing escaping, nonces, capability checks and unprepared queries.

  • Works in 4 steps: Read the project's agent instructions… → Identify the established prefix… → Detect context: WooCommerce APIs in play… → …
  • Reviewing a WordPress plugin before release, to confirm it is safe to ship
  • SKILL.md covers How to use this skill, Adapt to the project first, The Rules and Self-check before delivery, plus 4 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

This skill acts as a quality gate for WordPress code that an agent has just generated or changed. It targets recurring failures in agent output: unescaped request data, AJAX handlers with no nonce or capability check, SQL built by string interpolation, hardcoded English strings, unbounded queries and hand-written replacements for functions core already provides.

It runs in three modes. Guard-pass applies the rules to the diff and runs a self-check before delivery, live mode applies them while code is being written, and review mode walks references/review-checklist.md and returns a structured findings report without editing anything. Before judging, the agent reads CLAUDE.md or AGENTS.md, phpcs.xml and composer.json, and matches the project's prefixes and supported WordPress and PHP versions.

Reference files cover security, internationalization, performance and sources. The skill sends WooCommerce order and checkout logic to woo-guard, generic code quality to clean-code-guard and test code to test-guard, and it is not meant for non-WordPress PHP or hosting configuration.

When your agent uses it

  • Reviewing a WordPress plugin before release, to confirm it is safe to ship
  • Checking an AJAX handler, REST route or shortcode an agent just wrote
  • Making a theme or plugin translatable after the first implementation pass
  • Speeding up a WP_Query or $wpdb call that loads too many posts

Example prompts

  • “Review the plugin in wp-content/plugins/event-list and tell me if it is safe to ship.”
  • “I just added an AJAX endpoint for saving settings; check the nonce and capability handling.”
  • “Make every user-facing string in this theme translatable.”
  • “This query uses posts_per_page set to -1 on a big site; rework it to be safe.”

Requirements

  • WordPress plugin, theme or block code to review

Workflow steps

4 steps, taken from the first numbered list in SKILL.md.

  1. Read the project's agent instructions (CLAUDE.md, AGENTS.md), phpcs.xml/WPCS config, and composer.json. Project conventions win on conflict.
  2. Identify the established prefix (functions, options, meta keys, handles) and the minimum supported WP/PHP versions. Match both.
  3. Detect context: WooCommerce APIs in play → apply woo-guard alongside this skill when it is installed; otherwise apply WooCommerce's HPOS…
  4. Read one neighboring file before writing. Mirror its error handling, hook registration style, and escaping habits — unless they violate…

What it can do on your machine

Read from SKILL.md and the folder at commit ffa2603. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

WordPress Code Guard loads about 2.4k tokens when it runs, and up to ~6.9k if it reads all its reference files. Until then it costs about 234 tokens; SKILL.md has 1,118 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~234
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~6.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from amElnagdy/guard-skills at commit ffa2603, republished under its MIT licence (© amElnagdy). 1,118 words, ~2,434 tokens.

Download SKILL.mdSave it as .claude/skills/wp-guard/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
wp-guard
description
Review generated or changed WordPress code — plugins, themes, and blocks — before it ships. Best used reactively after an agent writes, edits, or reviews code touching WordPress APIs: add_action/add_filter, shortcodes, meta boxes, AJAX handlers, REST routes, WP_Query or $wpdb, widgets, or WP-CLI commands. Use on 'review this plugin', 'is this safe to ship', 'make this translatable', 'speed up this query', or after tasks like 'write a plugin' or 'add an endpoint/shortcode/meta box'. Enforces escaping and sanitization, nonces plus capability checks, prepared database queries, core-API-first development, translation-ready strings, and query/caching discipline. DO NOT USE for WooCommerce-specific order, product, or checkout logic (use woo-guard), non-WordPress PHP, generic code quality review (use clean-code-guard), test code review (use test-guard), server or hosting configuration, or conceptual WordPress questions.

WP Guard

You are reviewing generated or changed WordPress code before it ships. Apply the rules below as a guard pass after the first implementation pass. Be a sharp reviewer, not a pedantic one: flag what creates vulnerabilities, breaks translations, or melts servers — ignore cosmetic preferences WPCS tooling already handles.

These rules exist because AI agents produce WordPress code with systematic failures: raw echo of request data, AJAX handlers with neither nonce nor capability check, SQL built by string interpolation, English hardcoded into user-facing strings, posts_per_page => -1 on sites with a million posts, and hand-rolled replacements for APIs core already ships. Each one looks fine in a demo and fails in production.

How to use this skill

Guard-pass mode (recommended): after WordPress code has been generated or edited, apply the rules to the diff or target files, then run the self-check before delivery. Fix violations before showing the user.

Live mode (explicit): when the user invokes this skill before writing WordPress code, apply the same rules while writing, then run the self-check before delivery.

Review mode (the user asks you to review, audit, or rate WordPress code): walk references/review-checklist.md against the target files and produce a structured findings report. Do not edit code in review mode unless asked.

Pair this skill with clean-code-guard when both are installed: clean-code-guard owns generic code quality; wp-guard owns the WordPress layer.

Adapt to the project first

  1. Read the project's agent instructions (CLAUDE.md, AGENTS.md), phpcs.xml/WPCS config, and composer.json. Project conventions win on conflict.
  2. Identify the established prefix (functions, options, meta keys, handles) and the minimum supported WP/PHP versions. Match both.
  3. Detect context: WooCommerce APIs in play → apply woo-guard alongside this skill when it is installed; otherwise apply WooCommerce's HPOS, CRUD, and checkout rules from its developer documentation. Multilingual site (WPML/Polylang/multisite) → i18n rules are blocking, not advisory.
  4. Read one neighboring file before writing. Mirror its error handling, hook registration style, and escaping habits — unless they violate the security rules below, which are non-negotiable.

The Rules

Security — must fix, no exceptions
  1. Escape late, escape everything. Every variable crossing into HTML output goes through the context-correct function: esc_html(), esc_attr(), esc_url(), or wp_kses()/wp_kses_post() for rich content. Data passed to inline JS goes through wp_json_encode() + wp_add_inline_script() — esc_js() is legacy, for single-quoted strings in inline attributes only. Escaping happens at output, not at storage. echo $anything; without an esc_* wrapper fails review.

  2. Sanitize early, and unslash first. Request data ($_POST, $_GET, $_REQUEST, $_SERVER) never touches logic raw: wp_unslash() first, then the type-correct sanitizer (sanitize_text_field(), sanitize_key(), absint(), sanitize_email(), …). Sanitization is not escaping; doing one never excuses the other.

  3. Every state change proves identity and intent. Form handlers, AJAX endpoints, and REST routes that change anything require BOTH a capability check (current_user_can()) AND a nonce (check_admin_referer(), check_ajax_referer(), or REST nonce handling). A nonce is not authorization. A REST permission_callback of __return_true on a writing route fails review.

  4. $wpdb->prepare() for every query containing a variable. Placeholders (%s, %d, %f, and %i for identifiers on WP ≥ 6.2), never interpolation or concatenation. Prefer WP_Query, the meta and options APIs over raw SQL when they can express the query.

Core API discipline
  1. Use the platform; don't reinvent it. Outbound HTTP via wp_remote_get()/wp_remote_post(), never curl. Assets via wp_enqueue_script()/wp_enqueue_style(), never echoed <script>/<style> tags. Scheduling via WP-Cron or Action Scheduler. Redirects via wp_safe_redirect() followed by exit. File writes via WP_Filesystem. Simple persistent data via options/transients, not a custom table.

  2. Verify every hook and function exists. Before add_action(), add_filter(), or calling a core/plugin function, confirm it exists in the supported versions — read the source or the project's installed code. Hallucinated hooks fail silently in WordPress: no error, no behavior. Also match the hook to the moment — front-end code does not load on admin_init, queries do not run before init expects them.

  3. Prefix or namespace everything public. Functions, classes, options, transients, meta keys, script handles, AJAX actions, REST namespaces — all carry the project prefix. Generic names (get_settings, data, api_key) are collisions waiting for the next active plugin.

  4. Guard direct access. Every PHP file that does work starts with the ABSPATH check (or equivalent project convention).

Show full SKILL.md (433 more words)Show less
Internationalization
  1. Every user-facing string is translation-ready. The correct wrapper for the context (__(), _e(), _x(), _n(), or the escaping combos esc_html__(), esc_attr__()), a literal text domain matching the plugin slug — never a variable or constant — translator comments on every placeholder, _n() for plurals (never sprintf with a hardcoded singular/plural choice), and no sentence assembly by concatenation. Dates and numbers through date_i18n()/wp_date() and number_format_i18n(). Details and JS i18n: references/i18n.md.
Performance
  1. Query discipline. No posts_per_page => -1 and no query_posts(), ever. Use 'fields' => 'ids' when only IDs are needed, 'no_found_rows' => true when not paginating, and never query inside a loop what could be primed once (meta/term caches). Details: references/performance.md.

  2. Cache expensive work, load assets where used. Remote calls and heavy computations go behind transients or the object cache with a deliberate TTL. Options that are large or rarely read register with autoload => false. Scripts and styles enqueue only on the screens that use them.

Self-check before delivery

  1. Grep your diff for echo, print, <?=: is every variable output escaped with the context-correct function?
  2. Grep for $_POST, $_GET, $_REQUEST: unslashed? sanitized? nonce-verified? capability-checked?
  3. Grep for $wpdb->: every variable behind a placeholder?
  4. Any user-facing string outside an i18n wrapper? Any non-literal text domain?
  5. Any hook or function you did not verify exists?
  6. Any unbounded query, uncached remote call, or unconditional enqueue?
  7. Does every new public name carry the project prefix?
  8. Would this survive WPCS (WordPress-Extra + WordPress-Security) without warnings you cannot justify?

If any answer is wrong, fix it before showing the user.

Reporting format (review mode)

**Rule N violation** in `path/file.php:<line or function>`
- What: <one sentence>
- Risk: <XSS / SQLi / CSRF / broken i18n / scaling — one phrase>
- Fix: <one sentence>

Group by file, lead with security findings. If a file is clean, don't mention it.

Severity guide

  • Must fix: Rules 1–4 — these are exploitable (XSS, SQLi, CSRF, privilege escalation)
  • Should fix: Rules 5–9 — conflicts, silent failures, untranslatable releases
  • Worth noting: Rules 10–11 — they decide whether the code survives traffic; block on them for code that runs on every request

References

What this skill does not do

  • Run PHPCS, PHPStan, or Plugin Check — use the project's tooling for mechanical verification; this skill is the judgment layer above it.
  • Decide plugin architecture or business logic — it guards how WordPress code ships, not what it does.
  • Replace clean-code-guard or test-guard — generic code quality and test quality remain their jurisdiction.

© amElnagdy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in skills/wp-guard of amElnagdy/guard-skills.

  • SKILL.md
  • agents/openai.yaml
  • references/i18n.md
  • references/performance.md
  • references/review-checklist.md
  • references/security.md
  • references/sources.md

Open the folder on GitHubat commit ffa2603

Compare with similar skills

WordPress Code Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

WordPress Code Guard compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
WordPress Code Guard this skillamElnagdy/guard-skills1.3k—~2.4kAutomated safety check: PassMIT
WordPress ProJeffallan/claude-skills12k—~1.6kAutomated safety check: PassMIT
Wp Performance Reviewelvismdev/claude-wordpress-skills2351 repos~4.5kAutomated safety check: PassMIT
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence
Performance CheckZeroDeng01/sublinkPro1.7k—~1.8kAutomated safety check: PassMIT
Wp Theme Developmentjorgerosal/wordpress-skills102—~12kAutomated safety check: PassMIT

Similar skills

  • WordPress Pro

    Jeffallan/claude-skills

    Develops WordPress themes, plugins, Gutenberg blocks and WooCommerce features with nonce, escaping and capability checks, phpcs linting and caching tuned for speed.

    12k GitHub stars~1.6k tokensUpdated 6 days ago
    DevelopmentAuto-check passed
  • Wp Performance Review

    elvismdev/claude-wordpress-skills

    WordPress performance code review and optimization analysis.

    235 GitHub starsUsed in 1 repo~4.5k tokens
    Business, Finance & HRAuto-check passed
  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Performance Check

    ZeroDeng01/sublinkPro

    Checklist for reviewing code changes that touch queries, APIs, rendering, caching or algorithms for performance, scalability and resource-usage problems.

    1.7k GitHub stars~1.8k tokensUpdated today
    DevelopmentAuto-check passed
  • Wp Theme Development

    jorgerosal/wordpress-skills

    WordPress theme code review and block theme development patterns for WordPress 6.6+.

    102 GitHub stars~12k tokensUpdated 4 mo ago
    DevelopmentAuto-check passed
  • Wp Block Development

    jorgerosal/wordpress-skills

    WordPress block editor code review and Gutenberg block development patterns for WordPress 6.x+.

    102 GitHub stars~12k tokensUpdated 4 mo ago
    Frontend & DesignAuto-check passed

More from amElnagdy/guard-skills

  • Clean Code Guard

    amElnagdy/guard-skills

    Reviews generated or changed production code against Clean Code, SOLID, DRY, KISS, YAGNI and LLM-specific failure modes before it ships, in any language.

    1.3k GitHub starsUsed in 2 repos~4.3k tokens
    Auto-check passed
  • Test Guard

    amElnagdy/guard-skills

    Reviews newly written or edited tests against nine rules that cut test bloat, such as mock-heavy checks and near-duplicate cases, before they are committed.

    1.3k GitHub starsUsed in 2 repos~2.1k tokens
    Auto-check passed
  • Docs Guard

    amElnagdy/guard-skills

    Checks generated or edited documentation against the source code, flagging invented symbols, outdated samples and unverifiable claims before publishing.

    1.3k GitHub stars~2.1k tokensUpdated 3 mo ago
    Auto-check passed
  • WooCommerce Code Guard

    amElnagdy/guard-skills

    Reviews generated or changed WooCommerce code for HPOS safety, CRUD use, checkout validation and money handling before it ships.

    1.3k GitHub stars~2.2k tokensUpdated 3 mo ago
    Auto-check passed

Works with

Questions about WordPress Code Guard

What does WordPress Code Guard do?

Reviews WordPress plugin, theme and block code after an agent writes or edits it, catching missing escaping, nonces, capability checks and unprepared queries. This skill acts as a quality gate for WordPress code that an agent has just generated or changed. It targets recurring failures in agent output: unescaped request data, AJAX handlers with no nonce or capability check, SQL built by string interpolation, hardcoded English strings, unbounded queries and hand-written replacements for functions core already provides.

When should I use WordPress Code Guard?

WordPress Code Guard fits situations like: reviewing a WordPress plugin before release, to confirm it is safe to ship; checking an AJAX handler, REST route or shortcode an agent just wrote; making a theme or plugin translatable after the first implementation pass; speeding up a WP_Query or $wpdb call that loads too many posts.

How do I install WordPress Code Guard in Claude Code?

Run `npx skills add amElnagdy/guard-skills --skill wp-guard -a claude-code`. Or copy the skill folder (skills/wp-guard in amElnagdy/guard-skills) into .claude/skills/wp-guard in your project. Claude Code loads it when a task matches its description.

How do I install WordPress Code Guard in Codex?

Run `npx skills add amElnagdy/guard-skills --skill wp-guard -a codex`. Or copy the skill folder (skills/wp-guard in amElnagdy/guard-skills) into .agents/skills/wp-guard in your project. Codex loads it when a task matches its description.

Can I use WordPress Code Guard in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add amElnagdy/guard-skills --skill wp-guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wp-guard, .gemini/skills/wp-guard, .github/skills/wp-guard and .opencode/skills/wp-guard in your project.

What does WordPress Code Guard need to run?

SKILL.md names no scripts, command-line tools or credentials: WordPress Code Guard is instructions for the agent only. Our summary lists: WordPress plugin, theme or block code to review.

Does WordPress Code Guard access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is WordPress Code Guard safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does WordPress Code Guard use?

WordPress Code Guard is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does WordPress Code Guard use?

About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.5k tokens, read only when the agent opens those files.

What are the alternatives to WordPress Code Guard?

Skills that share tags, products or a category with WordPress Code Guard: WordPress Pro (Jeffallan/claude-skills, 12k stars), Wp Performance Review (elvismdev/claude-wordpress-skills, 235 stars), WooCommerce Code Review (woocommerce/woocommerce, 11k stars) and Performance Check (ZeroDeng01/sublinkPro, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains WordPress Code Guard?

amElnagdy (a GitHub user) maintains it in amElnagdy/guard-skills, which has 1,260 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on July 4, 2026.

Source: amElnagdy/guard-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.