WordPress Pro
Jeffallan/claude-skills
Develops WordPress themes, plugins, Gutenberg blocks and WooCommerce features with nonce, escaping and capability checks, phpcs linting and caching tuned for speed.
Reviews WordPress plugin, theme and block code after an agent writes or edits it, catching missing escaping, nonces, capability checks and unprepared queries.
$ npx skills add amElnagdy/guard-skills --skill wp-guard -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install amElnagdy/guard-skills wp-guard --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/amElnagdy/guard-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/wp-guard .claude/skills/wp-guard && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "wp-guard" agent skill from https://github.com/amElnagdy/guard-skills/tree/master/skills/wp-guard into .claude/skills/wp-guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-guard", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/amElnagdy/guard-skills/tree/master/skills/wp-guardType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add amElnagdy/guard-skills --skill wp-guard -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install amElnagdy/guard-skills wp-guard --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/amElnagdy/guard-skills.git skills-src && mkdir -p .agents/skills && cp -r skills-src/skills/wp-guard .agents/skills/wp-guard && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "wp-guard" agent skill from https://github.com/amElnagdy/guard-skills/tree/master/skills/wp-guard into .agents/skills/wp-guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-guard", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add amElnagdy/guard-skills --skill wp-guard -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install amElnagdy/guard-skills wp-guard --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/amElnagdy/guard-skills.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/skills/wp-guard .cursor/skills/wp-guard && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "wp-guard" agent skill from https://github.com/amElnagdy/guard-skills/tree/master/skills/wp-guard into .cursor/skills/wp-guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-guard", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/amElnagdy/guard-skills.git --path skills/wp-guard--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add amElnagdy/guard-skills --skill wp-guard -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install amElnagdy/guard-skills wp-guard --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/amElnagdy/guard-skills.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/skills/wp-guard .gemini/skills/wp-guard && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "wp-guard" agent skill from https://github.com/amElnagdy/guard-skills/tree/master/skills/wp-guard into .gemini/skills/wp-guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-guard", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install amElnagdy/guard-skills wp-guardInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add amElnagdy/guard-skills --skill wp-guard -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/amElnagdy/guard-skills.git skills-src && mkdir -p .github/skills && cp -r skills-src/skills/wp-guard .github/skills/wp-guard && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "wp-guard" agent skill from https://github.com/amElnagdy/guard-skills/tree/master/skills/wp-guard into .github/skills/wp-guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-guard", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add amElnagdy/guard-skills --skill wp-guard -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install amElnagdy/guard-skills wp-guard --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/amElnagdy/guard-skills.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/skills/wp-guard .opencode/skills/wp-guard && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "wp-guard" agent skill from https://github.com/amElnagdy/guard-skills/tree/master/skills/wp-guard into .opencode/skills/wp-guard/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-guard", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
wp-guardReviews WordPress plugin, theme and block code after an agent writes or edits it, catching missing escaping, nonces, capability checks and unprepared queries.
This skill acts as a quality gate for WordPress code that an agent has just generated or changed. It targets recurring failures in agent output: unescaped request data, AJAX handlers with no nonce or capability check, SQL built by string interpolation, hardcoded English strings, unbounded queries and hand-written replacements for functions core already provides.
It runs in three modes. Guard-pass applies the rules to the diff and runs a self-check before delivery, live mode applies them while code is being written, and review mode walks references/review-checklist.md and returns a structured findings report without editing anything. Before judging, the agent reads CLAUDE.md or AGENTS.md, phpcs.xml and composer.json, and matches the project's prefixes and supported WordPress and PHP versions.
Reference files cover security, internationalization, performance and sources. The skill sends WooCommerce order and checkout logic to woo-guard, generic code quality to clean-code-guard and test code to test-guard, and it is not meant for non-WordPress PHP or hosting configuration.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit ffa2603. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
WordPress Code Guard loads about 2.4k tokens when it runs, and up to ~6.9k if it reads all its reference files. Until then it costs about 234 tokens; SKILL.md has 1,118 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from amElnagdy/guard-skills at commit ffa2603, republished under its MIT licence (© amElnagdy). 1,118 words, ~2,434 tokens.
.claude/skills/wp-guard/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.You are reviewing generated or changed WordPress code before it ships. Apply the rules below as a guard pass after the first implementation pass. Be a sharp reviewer, not a pedantic one: flag what creates vulnerabilities, breaks translations, or melts servers — ignore cosmetic preferences WPCS tooling already handles.
These rules exist because AI agents produce WordPress code with systematic failures: raw echo of request data, AJAX handlers with neither nonce nor capability check, SQL built by string interpolation, English hardcoded into user-facing strings, posts_per_page => -1 on sites with a million posts, and hand-rolled replacements for APIs core already ships. Each one looks fine in a demo and fails in production.
Guard-pass mode (recommended): after WordPress code has been generated or edited, apply the rules to the diff or target files, then run the self-check before delivery. Fix violations before showing the user.
Live mode (explicit): when the user invokes this skill before writing WordPress code, apply the same rules while writing, then run the self-check before delivery.
Review mode (the user asks you to review, audit, or rate WordPress code): walk references/review-checklist.md against the target files and produce a structured findings report. Do not edit code in review mode unless asked.
Pair this skill with clean-code-guard when both are installed: clean-code-guard owns generic code quality; wp-guard owns the WordPress layer.
phpcs.xml/WPCS config, and composer.json. Project conventions win on conflict.Escape late, escape everything. Every variable crossing into HTML output goes through the context-correct function: esc_html(), esc_attr(), esc_url(), or wp_kses()/wp_kses_post() for rich content. Data passed to inline JS goes through wp_json_encode() + wp_add_inline_script() — esc_js() is legacy, for single-quoted strings in inline attributes only. Escaping happens at output, not at storage. echo $anything; without an esc_* wrapper fails review.
Sanitize early, and unslash first. Request data ($_POST, $_GET, $_REQUEST, $_SERVER) never touches logic raw: wp_unslash() first, then the type-correct sanitizer (sanitize_text_field(), sanitize_key(), absint(), sanitize_email(), …). Sanitization is not escaping; doing one never excuses the other.
Every state change proves identity and intent. Form handlers, AJAX endpoints, and REST routes that change anything require BOTH a capability check (current_user_can()) AND a nonce (check_admin_referer(), check_ajax_referer(), or REST nonce handling). A nonce is not authorization. A REST permission_callback of __return_true on a writing route fails review.
$wpdb->prepare() for every query containing a variable. Placeholders (%s, %d, %f, and %i for identifiers on WP ≥ 6.2), never interpolation or concatenation. Prefer WP_Query, the meta and options APIs over raw SQL when they can express the query.
Use the platform; don't reinvent it. Outbound HTTP via wp_remote_get()/wp_remote_post(), never curl. Assets via wp_enqueue_script()/wp_enqueue_style(), never echoed <script>/<style> tags. Scheduling via WP-Cron or Action Scheduler. Redirects via wp_safe_redirect() followed by exit. File writes via WP_Filesystem. Simple persistent data via options/transients, not a custom table.
Verify every hook and function exists. Before add_action(), add_filter(), or calling a core/plugin function, confirm it exists in the supported versions — read the source or the project's installed code. Hallucinated hooks fail silently in WordPress: no error, no behavior. Also match the hook to the moment — front-end code does not load on admin_init, queries do not run before init expects them.
Prefix or namespace everything public. Functions, classes, options, transients, meta keys, script handles, AJAX actions, REST namespaces — all carry the project prefix. Generic names (get_settings, data, api_key) are collisions waiting for the next active plugin.
Guard direct access. Every PHP file that does work starts with the ABSPATH check (or equivalent project convention).
__(), _e(), _x(), _n(), or the escaping combos esc_html__(), esc_attr__()), a literal text domain matching the plugin slug — never a variable or constant — translator comments on every placeholder, _n() for plurals (never sprintf with a hardcoded singular/plural choice), and no sentence assembly by concatenation. Dates and numbers through date_i18n()/wp_date() and number_format_i18n(). Details and JS i18n: references/i18n.md.Query discipline. No posts_per_page => -1 and no query_posts(), ever. Use 'fields' => 'ids' when only IDs are needed, 'no_found_rows' => true when not paginating, and never query inside a loop what could be primed once (meta/term caches). Details: references/performance.md.
Cache expensive work, load assets where used. Remote calls and heavy computations go behind transients or the object cache with a deliberate TTL. Options that are large or rarely read register with autoload => false. Scripts and styles enqueue only on the screens that use them.
echo, print, <?=: is every variable output escaped with the context-correct function?$_POST, $_GET, $_REQUEST: unslashed? sanitized? nonce-verified? capability-checked?$wpdb->: every variable behind a placeholder?WordPress-Extra + WordPress-Security) without warnings you cannot justify?If any answer is wrong, fix it before showing the user.
**Rule N violation** in `path/file.php:<line or function>`
- What: <one sentence>
- Risk: <XSS / SQLi / CSRF / broken i18n / scaling — one phrase>
- Fix: <one sentence>Group by file, lead with security findings. If a file is clean, don't mention it.
$wpdb->prepare details, file uploads© amElnagdy, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (references) in skills/wp-guard of amElnagdy/guard-skills.
Open the folder on GitHubat commit ffa2603
WordPress Code Guard next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| WordPress Code Guard this skillamElnagdy/guard-skills | 1.3k | — | ~2.4k | Automated safety check: Pass | MIT | |
| WordPress ProJeffallan/claude-skills | 12k | — | ~1.6k | Automated safety check: Pass | MIT | |
| Wp Performance Reviewelvismdev/claude-wordpress-skills | 235 | 1 repos | ~4.5k | Automated safety check: Pass | MIT | |
| WooCommerce Code Reviewwoocommerce/woocommerce | 11k | 3 repos | ~1.1k | Automated safety check: Pass | Custom licence | |
| Performance CheckZeroDeng01/sublinkPro | 1.7k | — | ~1.8k | Automated safety check: Pass | MIT | |
| Wp Theme Developmentjorgerosal/wordpress-skills | 102 | — | ~12k | Automated safety check: Pass | MIT |
Jeffallan/claude-skills
Develops WordPress themes, plugins, Gutenberg blocks and WooCommerce features with nonce, escaping and capability checks, phpcs linting and caching tuned for speed.
elvismdev/claude-wordpress-skills
WordPress performance code review and optimization analysis.
woocommerce/woocommerce
Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.
ZeroDeng01/sublinkPro
Checklist for reviewing code changes that touch queries, APIs, rendering, caching or algorithms for performance, scalability and resource-usage problems.
jorgerosal/wordpress-skills
WordPress theme code review and block theme development patterns for WordPress 6.6+.
jorgerosal/wordpress-skills
WordPress block editor code review and Gutenberg block development patterns for WordPress 6.x+.
amElnagdy/guard-skills
Reviews generated or changed production code against Clean Code, SOLID, DRY, KISS, YAGNI and LLM-specific failure modes before it ships, in any language.
amElnagdy/guard-skills
Reviews newly written or edited tests against nine rules that cut test bloat, such as mock-heavy checks and near-duplicate cases, before they are committed.
amElnagdy/guard-skills
Checks generated or edited documentation against the source code, flagging invented symbols, outdated samples and unverifiable claims before publishing.
amElnagdy/guard-skills
Reviews generated or changed WooCommerce code for HPOS safety, CRUD use, checkout validation and money handling before it ships.
Categories
Reviews WordPress plugin, theme and block code after an agent writes or edits it, catching missing escaping, nonces, capability checks and unprepared queries. This skill acts as a quality gate for WordPress code that an agent has just generated or changed. It targets recurring failures in agent output: unescaped request data, AJAX handlers with no nonce or capability check, SQL built by string interpolation, hardcoded English strings, unbounded queries and hand-written replacements for functions core already provides.
WordPress Code Guard fits situations like: reviewing a WordPress plugin before release, to confirm it is safe to ship; checking an AJAX handler, REST route or shortcode an agent just wrote; making a theme or plugin translatable after the first implementation pass; speeding up a WP_Query or $wpdb call that loads too many posts.
Run `npx skills add amElnagdy/guard-skills --skill wp-guard -a claude-code`. Or copy the skill folder (skills/wp-guard in amElnagdy/guard-skills) into .claude/skills/wp-guard in your project. Claude Code loads it when a task matches its description.
Run `npx skills add amElnagdy/guard-skills --skill wp-guard -a codex`. Or copy the skill folder (skills/wp-guard in amElnagdy/guard-skills) into .agents/skills/wp-guard in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add amElnagdy/guard-skills --skill wp-guard -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wp-guard, .gemini/skills/wp-guard, .github/skills/wp-guard and .opencode/skills/wp-guard in your project.
SKILL.md names no scripts, command-line tools or credentials: WordPress Code Guard is instructions for the agent only. Our summary lists: WordPress plugin, theme or block code to review.
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
WordPress Code Guard is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.7k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 4.5k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with WordPress Code Guard: WordPress Pro (Jeffallan/claude-skills, 12k stars), Wp Performance Review (elvismdev/claude-wordpress-skills, 235 stars), WooCommerce Code Review (woocommerce/woocommerce, 11k stars) and Performance Check (ZeroDeng01/sublinkPro, 1.7k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
amElnagdy (a GitHub user) maintains it in amElnagdy/guard-skills, which has 1,260 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on July 4, 2026.
Source: amElnagdy/guard-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.