Agent skill

Wp Phpstan

by Automattic in Automattic/agent-skills

A skill your agent uses when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and…

No licenceAuto-check passedSecurity

Install Wp Phpstan

skills CLI
$ npx skills add Automattic/agent-skills --skill wp-phpstan -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install Automattic/agent-skills wp-phpstan --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/Automattic/agent-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/skills/wp-phpstan .claude/skills/wp-phpstan && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
wp-phpstan
GitHub stars
211
Used in
1 other repo
Token cost
~1k tokens
SKILL.md length
452 words
Files
5 (incl. scripts, references)
Skills in repo
5
Repo updated
First seen
Licence
None found

At a glance

A skill your agent uses when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and…

  • Works in 6 steps: Discover PHPStan entrypoints… → Ensure WordPress core stubs are loaded → Ensure a sane phpstan.neon for WordPress… → …
  • Fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup
  • SKILL.md covers When to use, Inputs required, Procedure and Verification, plus 2 more sections
  • Runs JavaScript scripts from its folder; calls composer and node

What it does

Wp Phpstan is an agent skill from Automattic/agent-skills. Use when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and handling third-party plugin classes.

Its SKILL.md is about 1k tokens, which your agent loads only when the skill is triggered. The skill folder holds 6 other files, including scripts and reference files (for example `references/configuration.md`, `references/third-party-classes.md` and `references/wordpress-annotations.md`). Compatibility notes: Targets WordPress 6.9+ (PHP 7.2.24+). Requires Composer-based PHPStan.

It sits in Security, covering Static analysis and SAST. It works with WordPress. The repository describes itself as: Agent Skills for WordPress - folders of instructions, scripts, and resources.

When your agent uses it

  • Fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup
  • WordPress-specific typing
  • Handling third-party plugin classes

Example prompts

  • “/wp-phpstan”

Requirements

  • Node.js
  • Compatibility (from SKILL.md): Targets WordPress 6.9+ (PHP 7.2.24+). Requires Composer-based PHPStan.

Workflow steps

6 steps, taken from the step headings in SKILL.md.

  1. Discover PHPStan entrypoints (deterministic)
  2. Ensure WordPress core stubs are loaded
  3. Ensure a sane phpstan.neon for WordPress projects
  4. Fix errors with WordPress-specific typing (preferred)
  5. Handle third-party plugin/theme classes (only when needed)
  6. Baseline management (use as a migration tool, not a trash bin)

What it can do on your machine

Read from SKILL.md and the folder at commit 48d4aa2. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Ships 1 file in scripts/ (JavaScript), which the agent can run.

    Shell commands in SKILL.md call:

    • composer
    • node

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Targets WordPress 6.9+ (PHP 7.2.24+). Requires Composer-based PHPStan.

    From compatibility in the SKILL.md frontmatter.

Context cost

Wp Phpstan loads about 1k tokens when it runs, and up to ~2.8k if it reads all its reference files. Until then it costs about 55 tokens; SKILL.md has 452 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~55
When it runs · the whole SKILL.md, loaded when a task matches
~1k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~2.8k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); the scripts in this folder are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 452 words (~1,022 tokens).

“Use this skill when working on PHPStan in a WordPress codebase, for example:”

— opening of SKILL.md by Automattic
name
wp-phpstan
compatibility
Targets WordPress 6.9+ (PHP 7.2.24+). Requires Composer-based PHPStan.

Read the full SKILL.md on GitHub

Files

SKILL.md and 4 other files (scripts, references) in skills/wp-phpstan of Automattic/agent-skills.

  • SKILL.md
  • references/configuration.md
  • references/third-party-classes.md
  • references/wordpress-annotations.md
  • scripts/phpstan_inspect.mjs

Open the folder on GitHubat commit 48d4aa2

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in Automattic/agent-skills, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Wp Phpstan next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Wp Phpstan compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Wp Phpstan this skillAutomattic/agent-skills2111 repos~1kAutomated safety check: PassNone
Wp Phpstan Reviewjorgerosal/wordpress-skills100—~1.2kAutomated safety check: PassMIT
Semgrepvigolium/piolium1381 repos~2.4kAutomated safety check: NotesMIT
C To AstNarwhal-Lab/MagicSkills316—~1.1kAutomated safety check: PassMIT
Semgrep Security Scantrailofbits/skills7.4k—~3.7kAutomated safety check: NotesCC-BY-SA-4.0
LLM Sast ScannerSunWeb3Sec/llm-sast-scanner286—~6.2kAutomated safety check: PassNone

Similar skills

  • Wp Phpstan Review

    jorgerosal/wordpress-skills

    WordPress PHPStan review and setup guidance. An agent skill from jorgerosal/wordpress-skills.

    100 GitHub stars~1.2k tokensUpdated 4 mo ago
    SecurityAuto-check passed
  • Semgrep

    vigolium/piolium

    Run Semgrep static analysis scan on a codebase using parallel subagents.

    138 GitHub starsUsed in 1 repo~2.4k tokens
    SecurityAuto-check: notes
  • C To Ast

    Narwhal-Lab/MagicSkills

    Parse C source code into an Abstract Syntax Tree (AST). An agent skill from Narwhal-Lab/MagicSkills.

    316 GitHub stars~1.1k tokensUpdated 6 mo ago
    SecurityAuto-check passed
  • Semgrep Security Scan

    trailofbits/skills

    Official

    Detects languages, proposes rulesets for approval, then runs the approved Semgrep scan across a codebase and merges the output into one SARIF file.

    7.4k GitHub stars~3.7k tokensUpdated 5 days ago
    SecurityAuto-check: notes
  • LLM Sast Scanner

    SunWeb3Sec/llm-sast-scanner

    General-purpose Static Application Security Testing (SAST) skill for code vulnerability analysis.

    286 GitHub stars~6.2k tokensUpdated 1 mo ago
    SecurityAuto-check passed
  • Sast Semgrep

    AgentSecOps/SecOpsAgentKit

    Static application security testing (SAST) using Semgrep for vulnerability detection, security code review, and secure coding guidance with OWASP and CWE framework mapping.

    219 GitHub starsUsed in 2 repos~2.4k tokens
    SecurityAuto-check passed

More from Automattic/agent-skills

  • Wp Interactivity API

    Automattic/agent-skills

    A skill your agent uses when building or debugging WordPress Interactivity API features (data-wp- directives, @wordpress/interactivity store/state/actions, block viewScriptModule integration…

    211 GitHub starsUsed in 2 repos~1.5k tokens
    Auto-check passed
  • Wp Wpcli And Ops

    Automattic/agent-skills

    A skill your agent uses when working with WP-CLI (wp) for WordPress operations: safe search-replace, db export/import, plugin/theme/user/content management, cron, cache flushing, multisite, and…

    211 GitHub starsUsed in 2 repos~988 tokens
    Auto-check passed
  • Wp Playground

    Automattic/agent-skills

    A skill your agent uses for WordPress Playground workflows: fast disposable WP instances in the browser or locally via @wp-playground/cli (server, run-blueprint, build-snapshot), auto-mounting…

    211 GitHub starsUsed in 1 repo~1.2k tokens
    Auto-check passed
  • Wpds

    Automattic/agent-skills

    A skill your agent uses when building UIs leveraging the WordPress Design System (WPDS) and its components, tokens, patterns, etc.

    211 GitHub starsUsed in 1 repo~704 tokens
    Auto-check passed

Works with

Categories

Questions about Wp Phpstan

What does Wp Phpstan do?

A skill your agent uses when configuring, running, or fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup, baselines, WordPress-specific typing, and…. Wp Phpstan is an agent skill from Automattic/agent-skills.neon setup, baselines, WordPress-specific typing, and handling third-party plugin classes.

When should I use Wp Phpstan?

Wp Phpstan fits situations like: fixing PHPStan static analysis in WordPress projects (plugins/themes/sites): phpstan.neon setup; wordPress-specific typing; handling third-party plugin classes.

How do I install Wp Phpstan in Claude Code?

Run `npx skills add Automattic/agent-skills --skill wp-phpstan -a claude-code`. Or copy the skill folder (skills/wp-phpstan in Automattic/agent-skills) into .claude/skills/wp-phpstan in your project. Claude Code loads it when a task matches its description.

How do I install Wp Phpstan in Codex?

Run `npx skills add Automattic/agent-skills --skill wp-phpstan -a codex`. Or copy the skill folder (skills/wp-phpstan in Automattic/agent-skills) into .agents/skills/wp-phpstan in your project. Codex loads it when a task matches its description.

Can I use Wp Phpstan in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add Automattic/agent-skills --skill wp-phpstan -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wp-phpstan, .gemini/skills/wp-phpstan, .github/skills/wp-phpstan and .opencode/skills/wp-phpstan in your project.

What does Wp Phpstan need to run?

Going by SKILL.md and its folder, Wp Phpstan needs JavaScript for the scripts in its folder and the command-line tools its instructions call (composer and node). Our summary lists: Node.js. Compatibility (from SKILL.md): Targets WordPress 6.9+ (PHP 7.2.24+). Requires Composer-based PHPStan..

Does Wp Phpstan access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Wp Phpstan safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. The check reads SKILL.md only: the scripts in the folder are not scanned, so read them before running anything.

What licence does Wp Phpstan use?

No licence was found for Wp Phpstan or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Wp Phpstan use?

About 1k tokens (SKILL.md is roughly 4.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.8k tokens, read only when the agent opens those files.

What are the alternatives to Wp Phpstan?

Skills that share tags, products or a category with Wp Phpstan: Wp Phpstan Review (jorgerosal/wordpress-skills, 100 stars), Semgrep (vigolium/piolium, 138 stars), C To Ast (Narwhal-Lab/MagicSkills, 316 stars) and Semgrep Security Scan (trailofbits/skills, 7.4k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Wp Phpstan?

Automattic (a GitHub organization) maintains it in Automattic/agent-skills, which has 211 GitHub stars. The repository holds 5 skills in this directory. The repository was last updated on February 1, 2026.

Source: Automattic/agent-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.