Agent skill

Federation

by Automattic in Automattic/wordpress-activitypub

ActivityPub protocol specification and federation concepts. An agent skill from Automattic/wordpress-activitypub.

MITAuto-check passedDevelopment

Install Federation

skills CLI
$ npx skills add Automattic/wordpress-activitypub --skill federation -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Automattic/wordpress-activitypub federation --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Automattic/wordpress-activitypub.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/federation .claude/skills/federation && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
federation
GitHub stars
582
Token cost
~2.5k tokens
SKILL.md length
891 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

ActivityPub protocol specification and federation concepts. An agent skill from Automattic/wordpress-activitypub.

  • Works in 3 steps: Actors - Users/accounts in the system → Activities - Actions taken by actors → Objects - Content being acted upon
  • Working with ActivityPub activities
  • SKILL.md covers Core Concepts, Collections, Activity Types and Server-to-Server Federation, plus 5 more sections
  • Calls curl; reaches w3.org

What it does

Federation is an agent skill from Automattic/wordpress-activitypub. ActivityPub protocol specification and federation concepts. Use when working with ActivityPub activities, understanding federation mechanics, implementing protocol features, or debugging federation issues.

Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development, covering Email management. It works with WordPress. The repository describes itself as: The ActivityPub plugin connects your WordPress site to the Fediverse. Your site becomes a profile people can follow from Mastodon, and every post you publish is automatically… The licence is MIT.

When your agent uses it

  • Working with ActivityPub activities
  • Understanding federation mechanics
  • Implementing protocol features
  • Debugging federation issues

Example prompts

  • “/federation”

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Actors - Users/accounts in the system
  2. Activities - Actions taken by actors
  3. Objects - Content being acted upon

What it can do on your machine

Read from SKILL.md and the folder at commit 72d53bc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • curl

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    Hosts in commands or code, which the agent is likely to contact:

    • w3.org

    Also links to:

    • datatracker.ietf.org
    • codeberg.org

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Federation loads about 2.5k tokens when it runs. Until then it costs about 54 tokens; SKILL.md has 891 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~54
When it runs · the whole SKILL.md, loaded when a task matches
~2.5k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Automattic/wordpress-activitypub at commit 72d53bc, republished under its MIT licence (© Automattic). 891 words, ~2,479 tokens.

Download SKILL.mdSave it as .claude/skills/federation/SKILL.md (or your agent's skills folder).
name
federation
description
ActivityPub protocol specification and federation concepts. Use when working with ActivityPub activities, understanding federation mechanics, implementing protocol features, or debugging federation issues.

ActivityPub Federation Protocol

This skill provides understanding of the ActivityPub protocol specification and how federation works.

For supported features and compatibility: See FEDERATION.md for the complete list of implemented FEPs, supported standards, and federation compatibility details.

For implementation details: See AGENTS.md for transformers, handlers, and PHP code patterns.

Core Concepts

Three Building Blocks
  1. Actors - Users/accounts in the system

    • Each actor has a unique URI
    • Required: inbox, outbox
    • Optional: followers, following, liked
  2. Activities - Actions taken by actors

    • Create, Update, Delete, Follow, Like, Announce, Undo
    • Wrap objects to describe how they're shared
  3. Objects - Content being acted upon

    • Notes, Articles, Images, Videos, etc.
    • Can be embedded or referenced by URI
Actor Structure
json
{
  "@context": "https://www.w3.org/ns/activitystreams",
  "type": "Person",
  "id": "https://example.com/@alice",
  "inbox": "https://example.com/@alice/inbox",
  "outbox": "https://example.com/@alice/outbox",
  "followers": "https://example.com/@alice/followers",
  "following": "https://example.com/@alice/following",
  "preferredUsername": "alice",
  "name": "Alice Example",
  "summary": "Bio text here"
}

Collections

Standard Collections

Inbox - Receives incoming activities

  • De-duplicate by activity ID
  • Filter based on permissions
  • Process activities for side effects

Outbox - Publishes actor's activities

  • Public record of what actor has posted
  • Filtered based on viewer permissions
  • Used for profile activity displays

Followers - Actors following this actor

  • Updated when Follow activities are Accepted
  • Used for delivery targeting

Following - Actors this actor follows

  • Tracks subscriptions
  • Used for timeline building
Public Addressing

Special collection: https://www.w3.org/ns/activitystreams#Public

  • Makes content publicly accessible
  • Do not deliver to this URI - it's a marker, not a real inbox
  • Used in to, cc, bto, bcc fields for visibility

Activity Types

Create

Wraps newly published content:

json
{
  "type": "Create",
  "actor": "https://example.com/@alice",
  "object": {
    "type": "Note",
    "content": "Hello, Fediverse!"
  }
}
Follow

Initiates subscription:

json
{
  "type": "Follow",
  "actor": "https://example.com/@alice",
  "object": "https://other.example/@bob"
}
  • Recipient should respond with Accept or Reject
  • Only add to followers upon Accept
Like

Indicates appreciation:

json
{
  "type": "Like",
  "actor": "https://example.com/@alice",
  "object": "https://other.example/@bob/post/123"
}
Announce

Reshares/boosts content:

json
{
  "type": "Announce",
  "actor": "https://example.com/@alice",
  "object": "https://other.example/@bob/post/123"
}
Update

Modifies existing content:

  • Supplied properties replace existing
  • null values remove fields
  • Must include original object ID
Delete

Removes content:

  • May replace with Tombstone for referential integrity
  • Should cascade to related activities
Undo

Reverses previous activities:

json
{
  "type": "Undo",
  "actor": "https://example.com/@alice",
  "object": {
    "type": "Follow",
    "id": "https://example.com/@alice/follow/123"
  }
}

Server-to-Server Federation

Activity Delivery Process
  1. Resolve Recipients

    • Check to, bto, cc, bcc, audience fields
    • Dereference collections to find individual actors
    • De-duplicate recipient list
    • Exclude activity's own actor
  2. Discover Inboxes

    • Fetch actor profiles
    • Extract inbox property
    • Use sharedInbox if available for efficiency
  3. Deliver via HTTP POST

    • Content-Type: application/ld+json; profile="https://www.w3.org/ns/activitystreams"
    • Include HTTP Signatures for authentication
    • Handle delivery failures gracefully
Inbox Forwarding

Ghost Replies Problem: When Alice replies to Bob's post that Carol follows, Carol might not see the reply if she doesn't follow Alice.

Solution: Inbox forwarding

  • When receiving activity addressing a local collection
  • If activity references local objects
  • Forward to collection members
  • Ensures conversation participants see replies
Shared Inbox Optimization

For public posts with many recipients on same server:

  • Use sharedInbox endpoint instead of individual inboxes
  • Reduces number of HTTP requests
  • Server distributes internally

Addressing and Visibility

To/CC Fields
  • to - Primary recipients (public in UI)
  • cc - Secondary recipients (copied/mentioned)
  • bto - Blind primary (hidden in delivery)
  • bcc - Blind secondary (hidden in delivery)

Important: Remove bto and bcc before delivery to preserve privacy

Visibility Patterns

Public Post:

json
{
  "to": ["https://www.w3.org/ns/activitystreams#Public"],
  "cc": ["https://example.com/@alice/followers"]
}

Followers-Only:

json
{
  "to": ["https://example.com/@alice/followers"]
}

Direct Message:

json
{
  "to": ["https://other.example/@bob"],
  "cc": []
}

Content Verification

Security Considerations
  1. Verify Origins

    • Don't trust claimed sources without verification
    • Check HTTP Signatures
    • Validate actor owns referenced objects
  2. Prevent Spoofing

    • Mallory could claim Alice posted something
    • Always verify before processing side effects
  3. Rate Limiting

    • Limit recursive dereferencing
    • Protect against denial-of-service
    • Implement spam filtering
  4. Content Sanitization

    • Clean HTML before browser rendering
    • Validate media types
    • Check for malicious payloads

Protocol Extensions

Supported Standards

See FEDERATION.md for the complete list of implemented standards and FEPs, including:

  • WebFinger - Actor discovery.
  • HTTP Signatures - Request authentication.
  • NodeInfo - Server metadata.
  • Various FEPs (Fediverse Enhancement Proposals).
Show full SKILL.md (342 more words)Show less
FEPs (Fediverse Enhancement Proposals)

FEPs extend ActivityPub with additional features. Common FEP categories include:

  • Long-form text support.
  • Quote posts.
  • Activity intents.
  • Follower synchronization.
  • Actor metadata extensions.

For supported FEPs in this plugin: See FEDERATION.md for the authoritative list of implemented FEPs.

OAuth 2.0 Client-to-Server

When the ActivityPub API option is enabled, third-party clients can authenticate via OAuth 2.0 under activitypub/1.0/oauth/. The plugin supports RFC 7591 dynamic registration, RFC 7636 PKCE (S256 only, required by default for public clients), and the CIMD draft (URL-form client_id, HTTPS required).

RFC 8252 — Loopback Redirect URIs

Native apps receive the OAuth callback on a loopback port they opened locally. Per RFC 8252 §7.3 / §8.3, redirect URIs of the form http://127.0.0.1:{port}/{path} and http://[::1]:{port}/{path} are accepted with port flexibility (any port may be used at request time). localhost is also accepted for compatibility, although §8.3 marks it "NOT RECOMMENDED".

The loopback allowance applies only to redirect URI matching. Reserved-but-not-loopback addresses — 0.0.0.0, link-local 169.254.0.0/16, RFC1918 private ranges (10/8, 172.16/12, 192.168/16), and similar — are not treated as loopback and never bypass wp_safe_remote_get(). CIMD metadata URLs must use https://, and the metadata host is resolved and validated against private/reserved ranges before any fetch — loopback CIMD origins are not supported, even on dev installs.

For implementation details: See includes/oauth/class-client.php (especially the class docblock and is_loopback()) and the OAuth section of FEDERATION.md.

Implementation Notes

WordPress Plugin Specifics

This plugin implements:

  • Actor Types: User, Blog, Application
  • Transformers: Convert WordPress content to ActivityPub objects
  • Handlers: Process incoming activities

For implementation details, see:

Testing Federation
bash
# Test actor endpoint
curl -H "Accept: application/activity+json" \
  https://site.com/@username

# Test WebFinger
curl https://site.com/.well-known/webfinger?resource=acct:user@site.com

# Test NodeInfo
curl https://site.com/.well-known/nodeinfo

Common Issues

Activities Not Received
  • Check inbox URL is accessible
  • Verify HTTP signature validation
  • Ensure content-type headers correct
  • Check for firewall/security blocks
Replies Not Federated
  • Verify inbox forwarding enabled
  • Check addressing includes relevant actors
  • Ensure inReplyTo properly set
Follower Sync Issues
  • Check Accept activities sent for Follow
  • Verify followers collection updates
  • Ensure shared inbox used when available

Resources

© Automattic, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/federation of Automattic/wordpress-activitypub.

Open the folder on GitHubat commit 72d53bc

Compare with similar skills

Federation next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Federation compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Federation this skillAutomattic/wordpress-activitypub582—~2.5kAutomated safety check: PassMIT
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence
Wp Interactivity APIAutomattic/agent-skills2113 repos~1.5kAutomated safety check: PassNone
WooCommerce Dev Cyclewoocommerce/woocommerce11k3 repos~431Automated safety check: PassCustom licence
Wp PlaygroundAutomattic/agent-skills2112 repos~1.2kAutomated safety check: PassNone
ObservalObserval/Observal4.2k—~2.2kAutomated safety check: PassApache-2.0

Similar skills

  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Wp Interactivity API

    Automattic/agent-skills

    A skill your agent uses when building or debugging WordPress Interactivity API features (data-wp- directives, @wordpress/interactivity store/state/actions, block viewScriptModule integration…

    211 GitHub starsUsed in 3 repos~1.5k tokens
    DevelopmentAuto-check passed
  • WooCommerce Dev Cycle

    woocommerce/woocommerce

    Workflow for WooCommerce development: run PHP and JavaScript tests, lint and fix code style on the current branch, and follow guides for i18n and markdown.

    11k GitHub starsUsed in 3 repos~431 tokens
    DevelopmentAuto-check passed
  • Wp Playground

    Automattic/agent-skills

    A skill your agent uses for WordPress Playground workflows: fast disposable WP instances in the browser or locally via @wp-playground/cli (server, run-blueprint, build-snapshot), auto-mounting…

    211 GitHub starsUsed in 2 repos~1.2k tokens
    DevelopmentAuto-check passed
  • Observal

    Observal/Observal

    A skill your agent uses when starting any task the organization may already have an approved skill, prompt, MCP server, or Agent for: reviewing code, a commit, a diff, or a pull request; writing…

    4.2k GitHub stars~2.2k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Debug Php Wasm Main Module

    WordPress/wordpress-playground

    Debug PHP.wasm main module crashes including Asyncify errors (unreachable, memory access out of bounds), JSPI errors (SuspendError, trying to suspend JS frames), WASM memory growth bugs, and runtime…

    2k GitHub stars~3.1k tokensUpdated today
    DevelopmentAuto-check passed

More from Automattic/wordpress-activitypub

  • Code Style

    Automattic/wordpress-activitypub

    PHP coding standards and WordPress patterns for ActivityPub plugin.

    582 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Dev

    Automattic/wordpress-activitypub

    Development workflows for WordPress ActivityPub plugin including wp-env setup, testing commands, linting, and build processes.

    582 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Gitattributes

    Automattic/wordpress-activitypub

    A skill your agent uses when auditing or updating .gitattributes export-ignore coverage so dev-only files (lint configs, CI, tests, docs, build tooling) don't ship in the WordPress.org plugin zip.

    582 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Integrations

    Automattic/wordpress-activitypub

    Third-party WordPress plugin integration patterns. An agent skill from Automattic/wordpress-activitypub.

    582 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Release

    Automattic/wordpress-activitypub

    Version management and release processes using Jetpack Changelogger.

    582 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • PR

    Automattic/wordpress-activitypub

    INVOKE THIS SKILL before creating any PR to ensure compliance with branch naming, changelog requirements, and reviewer assignment.

    582 GitHub stars~927 tokensUpdated today
    Auto-check passed

Works with

Categories

Questions about Federation

What does Federation do?

ActivityPub protocol specification and federation concepts. An agent skill from Automattic/wordpress-activitypub. Federation is an agent skill from Automattic/wordpress-activitypub. ActivityPub protocol specification and federation concepts.

When should I use Federation?

Federation fits situations like: working with ActivityPub activities; understanding federation mechanics; implementing protocol features; debugging federation issues.

How do I install Federation in Claude Code?

Run `npx skills add Automattic/wordpress-activitypub --skill federation -a claude-code`. Or copy the skill folder (.agents/skills/federation in Automattic/wordpress-activitypub) into .claude/skills/federation in your project. Claude Code loads it when a task matches its description.

How do I install Federation in Codex?

Run `npx skills add Automattic/wordpress-activitypub --skill federation -a codex`. Or copy the skill folder (.agents/skills/federation in Automattic/wordpress-activitypub) into .agents/skills/federation in your project. Codex loads it when a task matches its description.

Can I use Federation in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Automattic/wordpress-activitypub --skill federation -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/federation, .gemini/skills/federation, .github/skills/federation and .opencode/skills/federation in your project.

What does Federation need to run?

Going by SKILL.md and its folder, Federation needs the command-line tools its instructions call (curl).

Does Federation access the network?

SKILL.md names 3 domains. In commands or code: w3.org; the agent is likely to contact it when it follows the instructions. As links in the text: datatracker.ietf.org and codeberg.org. This is read from the text; nothing was executed.

Is Federation safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Federation use?

Federation is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Federation use?

About 2.5k tokens (SKILL.md is roughly 9.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Federation?

Skills that share tags, products or a category with Federation: WooCommerce Code Review (woocommerce/woocommerce, 11k stars), Wp Interactivity API (Automattic/agent-skills, 211 stars), WooCommerce Dev Cycle (woocommerce/woocommerce, 11k stars) and Wp Playground (Automattic/agent-skills, 211 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Federation?

Automattic (a GitHub organization) maintains it in Automattic/wordpress-activitypub, which has 582 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 7, 2026.

Source: Automattic/wordpress-activitypub on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.