Agent skill

Gitattributes

by Automattic in Automattic/wordpress-activitypub

A skill your agent uses when auditing or updating .gitattributes export-ignore coverage so dev-only files (lint configs, CI, tests, docs, build tooling) don't ship in the WordPress.org plugin zip.

MITAuto-check passedDevelopment

Install Gitattributes

skills CLI
$ npx skills add Automattic/wordpress-activitypub --skill gitattributes -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Automattic/wordpress-activitypub gitattributes --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Automattic/wordpress-activitypub.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.agents/skills/gitattributes .claude/skills/gitattributes && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
gitattributes
GitHub stars
582
Token cost
~1.1k tokens
SKILL.md length
401 words
Files
1
Skills in repo
7
Repo updated
First seen
Licence
MIT

At a glance

A skill your agent uses when auditing or updating .gitattributes export-ignore coverage so dev-only files (lint configs, CI, tests, docs, build tooling) don't ship in the WordPress.org plugin zip.

  • Updating .gitattributes export-ignore coverage so dev-only files (lint configs
  • SKILL.md covers Why This Matters, Quick Audit (one command), Cross-Check Tracked vs Ignored and What Belongs in Each Bucket, plus 4 more sections
  • Calls git
  • Build tooling) dont ship in the WordPress.org plugin zip

What it does

Gitattributes is an agent skill from Automattic/wordpress-activitypub. Use when auditing or updating .gitattributes export-ignore coverage so dev-only files (lint configs, CI, tests, docs, build tooling) don't ship in the WordPress.org plugin zip. Run before a release, after adding a new top-level file or config, or when a tool is renamed (e.g. .eslintrc.js → eslint.config.cjs).

Its SKILL.md is about 1.1k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.

It sits in Development. It works with WordPress, ESLint, Git and PHP. The repository describes itself as: The ActivityPub plugin connects your WordPress site to the Fediverse. Your site becomes a profile people can follow from Mastodon, and every post you publish is automatically… The licence is MIT.

When your agent uses it

  • Updating .gitattributes export-ignore coverage so dev-only files (lint configs
  • Build tooling) dont ship in the WordPress.org plugin zip

Example prompts

  • “/gitattributes”

What it can do on your machine

Read from SKILL.md and the folder at commit 72d53bc. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • git

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use git, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Gitattributes loads about 1.1k tokens when it runs. Until then it costs about 81 tokens; SKILL.md has 401 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~81
When it runs · the whole SKILL.md, loaded when a task matches
~1.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from Automattic/wordpress-activitypub at commit 72d53bc, republished under its MIT licence (© Automattic). 401 words, ~1,123 tokens.

Download SKILL.mdSave it as .claude/skills/gitattributes/SKILL.md (or your agent's skills folder).
name
gitattributes
description
Use when auditing or updating .gitattributes export-ignore coverage so dev-only files (lint configs, CI, tests, docs, build tooling) don't ship in the WordPress.org plugin zip. Run before a release, after adding a new top-level file or config, or when a tool is renamed (e.g. .eslintrc.js → eslint.config.cjs).

.gitattributes Export-Ignore Audit

Ensure the WordPress.org release archive (git archive output) contains only runtime files. Dev tooling, tests, CI, and repo meta must be export-ignored.

Why This Matters

The WordPress.org zip is built via git archive. Anything without export-ignore ends up on every user's site, bloating the install and shipping dev-only code. Equally bad: stale export-ignore entries for files that no longer exist look tidy but protect nothing.

Quick Audit (one command)

bash
# Entries in the release archive at the repository root
git archive --format=tar HEAD | tar -t | awk -F/ '{print $1}' | sort -u

# Same, but uses the working-tree .gitattributes (use while iterating on edits)
git archive --worktree-attributes --format=tar HEAD | tar -t | awk -F/ '{print $1}' | sort -u

git archive HEAD reads .gitattributes from the commit, so uncommitted fixes won't show up. Use --worktree-attributes to preview a pending change before committing.

The output should contain ONLY runtime artifacts. For this plugin that's: LICENSE, readme.txt, activitypub.php, assets, build, includes, integration, patterns, templates.

Anything else in the list is a gap — add an export-ignore rule.

Cross-Check Tracked vs Ignored

bash
# Top-level tracked entries
git ls-tree --name-only HEAD | sort > /tmp/tracked.txt

# Entries referenced in .gitattributes
grep export-ignore .gitattributes | awk '{print $1}' | sed 's|^/||; s|/$||' | sort > /tmp/ignored.txt

# Stale entries (in .gitattributes but no longer tracked)
comm -23 /tmp/ignored.txt /tmp/tracked.txt

Stale entries aren't dangerous, but they rot and mislead future readers. Delete them.

What Belongs in Each Bucket

CategoryExamplesRule
Runtime PHPactivitypub.php, includes/, integration/keep
Runtime assetsassets/, build/, patterns/, templates/keep
WordPress.org metareadme.txt, LICENSEkeep
Dev dotfiles.editorconfig, .prettierrc.js, .stylelintrc.json, eslint.config.cjs, .wp-env.jsonexport-ignore
Repo meta.github/, .githooks/, .gitignore, .gitattributes, .wordpress-org/export-ignore
Agent/AI tooling.agents/, .claude/, AGENTS.md, CLAUDE.mdexport-ignore
Build & package configspackage.json, package-lock.json, composer.json, webpack.config.js, tsconfig.json, jest.config.js, jest.setup.jsexport-ignore
QA configsphpcs.xml, phpunit.xml.distexport-ignore
Source (pre-build)src/export-ignore (shipping build/ instead)
Teststests/export-ignore
Docs for contributorsdocs/, snippets/, CHANGELOG.md, CODE_OF_CONDUCT.md, CONTRIBUTING.md, FEDERATION.md, README.md, SECURITY.mdexport-ignore
Scriptsbin/, local/export-ignore
Show full SKILL.md (166 more words)Show less

When to Run This Audit

  • Before tagging a release.
  • After adding or renaming any top-level file, dotfile, or config.
  • After adopting a new dev tool (lint, test runner, bundler).
  • When a linter flat-config migration renames files (e.g. .eslintrc.js → eslint.config.cjs).

Writing Rules

  • Use a leading / to anchor to the repo root: /phpcs.xml, not phpcs.xml.
  • Use a trailing / for directories: /tests/.
  • Keep grouping comments tidy (dotfiles, build configs, source/tests, docs, linguist).

Linguist Attributes (bonus)

Also used in .gitattributes to shape GitHub's language stats:

  • /build/** linguist-generated — hides machine-built output.
  • /docs/** linguist-documentation — keeps docs out of the language bar.
  • /package-lock.json linguist-generated — hides lockfile churn.

These don't affect the archive, but live in the same file, so keep them current too.

Red Flags

  • Release zip is larger than expected → something new is leaking in.
  • New dev dependency added, .gitattributes untouched → likely a gap.
  • Lint tool migrated to a new config filename → old entry is stale, new file is leaking.
  • Top-level file renamed → old export-ignore is dead weight, new one is missing.

© Automattic, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

Just SKILL.md in .agents/skills/gitattributes of Automattic/wordpress-activitypub.

Open the folder on GitHubat commit 72d53bc

Compare with similar skills

Gitattributes next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Gitattributes compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Gitattributes this skillAutomattic/wordpress-activitypub582—~1.1kAutomated safety check: PassMIT
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence
Merge Upsymfony/symfony31k—~4kAutomated safety check: PassMIT
Wp Interactivity APIAutomattic/agent-skills2112 repos~1.5kAutomated safety check: PassNone
Releasing Php Packageyansongda/pay5.4k—~1.6kAutomated safety check: PassMIT
WooCommerce Dev Cyclewoocommerce/woocommerce11k3 repos~431Automated safety check: PassCustom licence

Similar skills

  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Merge Up

    symfony/symfony

    Cascade-merge maintained Symfony branches from oldest to newest (e.g.

    31k GitHub stars~4k tokensUpdated today
    DevelopmentAuto-check passed
  • Wp Interactivity API

    Automattic/agent-skills

    A skill your agent uses when building or debugging WordPress Interactivity API features (data-wp- directives, @wordpress/interactivity store/state/actions, block viewScriptModule integration…

    211 GitHub starsUsed in 2 repos~1.5k tokens
    DevelopmentAuto-check passed
  • A skill your agent uses when preparing to publish a new version of a PHP Composer package and need to write or update CHANGELOG, upgrade guides, and documentation before tagging and releasing

    5.4k GitHub stars~1.6k tokensUpdated 9 days ago
    DevelopmentAuto-check passed
  • WooCommerce Dev Cycle

    woocommerce/woocommerce

    Workflow for WooCommerce development: run PHP and JavaScript tests, lint and fix code style on the current branch, and follow guides for i18n and markdown.

    11k GitHub starsUsed in 3 repos~431 tokens
    DevelopmentAuto-check passed
  • Blueprint

    bonny/WordPress-Simple-History

    A skill your agent uses when the deliverable is WordPress Playground Blueprint JSON or a Blueprint bundle, including creating, editing, reviewing, validating schema keys, choosing steps/resources…

    317 GitHub starsUsed in 1 repo~4k tokens
    DevelopmentAuto-check passed

More from Automattic/wordpress-activitypub

  • Code Style

    Automattic/wordpress-activitypub

    PHP coding standards and WordPress patterns for ActivityPub plugin.

    582 GitHub stars~2.2k tokensUpdated today
    Auto-check passed
  • Dev

    Automattic/wordpress-activitypub

    Development workflows for WordPress ActivityPub plugin including wp-env setup, testing commands, linting, and build processes.

    582 GitHub stars~1.1k tokensUpdated today
    Auto-check passed
  • Federation

    Automattic/wordpress-activitypub

    ActivityPub protocol specification and federation concepts. An agent skill from Automattic/wordpress-activitypub.

    582 GitHub stars~2.5k tokensUpdated today
    Auto-check passed
  • Integrations

    Automattic/wordpress-activitypub

    Third-party WordPress plugin integration patterns. An agent skill from Automattic/wordpress-activitypub.

    582 GitHub stars~1.4k tokensUpdated today
    Auto-check passed
  • Release

    Automattic/wordpress-activitypub

    Version management and release processes using Jetpack Changelogger.

    582 GitHub stars~1.3k tokensUpdated today
    Auto-check passed
  • PR

    Automattic/wordpress-activitypub

    INVOKE THIS SKILL before creating any PR to ensure compliance with branch naming, changelog requirements, and reviewer assignment.

    582 GitHub stars~927 tokensUpdated today
    Auto-check passed

Categories

Questions about Gitattributes

What does Gitattributes do?

A skill your agent uses when auditing or updating .gitattributes export-ignore coverage so dev-only files (lint configs, CI, tests, docs, build tooling) don't ship in the WordPress.org plugin zip. Gitattributes is an agent skill from Automattic/wordpress-activitypub.org plugin zip.

When should I use Gitattributes?

Gitattributes fits situations like: updating .gitattributes export-ignore coverage so dev-only files (lint configs; build tooling) dont ship in the WordPress.org plugin zip.

How do I install Gitattributes in Claude Code?

Run `npx skills add Automattic/wordpress-activitypub --skill gitattributes -a claude-code`. Or copy the skill folder (.agents/skills/gitattributes in Automattic/wordpress-activitypub) into .claude/skills/gitattributes in your project. Claude Code loads it when a task matches its description.

How do I install Gitattributes in Codex?

Run `npx skills add Automattic/wordpress-activitypub --skill gitattributes -a codex`. Or copy the skill folder (.agents/skills/gitattributes in Automattic/wordpress-activitypub) into .agents/skills/gitattributes in your project. Codex loads it when a task matches its description.

Can I use Gitattributes in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Automattic/wordpress-activitypub --skill gitattributes -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/gitattributes, .gemini/skills/gitattributes, .github/skills/gitattributes and .opencode/skills/gitattributes in your project.

What does Gitattributes need to run?

Going by SKILL.md and its folder, Gitattributes needs the command-line tools its instructions call (git).

Does Gitattributes access the network?

SKILL.md contains no URLs. Its commands use git, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Gitattributes safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Gitattributes use?

Gitattributes is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Gitattributes use?

About 1.1k tokens (SKILL.md is roughly 4.5k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Gitattributes?

Skills that share tags, products or a category with Gitattributes: WooCommerce Code Review (woocommerce/woocommerce, 11k stars), Merge Up (symfony/symfony, 31k stars), Wp Interactivity API (Automattic/agent-skills, 211 stars) and Releasing Php Package (yansongda/pay, 5.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Gitattributes?

Automattic (a GitHub organization) maintains it in Automattic/wordpress-activitypub, which has 582 GitHub stars. The repository holds 7 skills in this directory. The repository was last updated on October 7, 2026.

Source: Automattic/wordpress-activitypub on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.