Agent skill

Code Quality

by bonny in bonny/WordPress-Simple-History

Runs linting and static analysis on PHP/CSS/JS using phpcs, phpstan, and rector.

No licenceAuto-check: notesDevelopment

Install Code Quality

skills CLI
$ npx skills add bonny/WordPress-Simple-History --skill code-quality -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install bonny/WordPress-Simple-History code-quality --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/bonny/WordPress-Simple-History.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/code-quality .claude/skills/code-quality && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
code-quality
GitHub stars
317
Token cost
~519 tokens
SKILL.md length
128 words
Files
6
Skills in repo
21
Repo updated
First seen
Licence
None found

At a glance

Runs linting and static analysis on PHP/CSS/JS using phpcs, phpstan, and rector.

  • Works in 3 steps: Always escape output - Use WordPress… → Prefix everything - All hooks,… → Run tools after changes - phpcs/phpstan…
  • Checking code style
  • SKILL.md covers Quick Commands, Project-Specific Rules, Essential Principles and Detailed Guidelines, plus 1 more section
  • Calls npm and composer

What it does

Code Quality is an agent skill from bonny/WordPress-Simple-History. Runs linting and static analysis on PHP/CSS/JS using phpcs, phpstan, and rector. Use when checking code style, fixing lint errors, or running static analysis.

Its SKILL.md is about 520 tokens, which your agent loads only when the skill is triggered. The skill folder holds 5 other files (for example `css-standards.md`, `design-principles.md` and `js-standards.md`).

It sits in Development, covering Linting and formatting, Code quality and Static analysis and SAST. It works with PHP. The repository describes itself as: 🔍🕵️♀️ WordPress audit log that track user changes in WordPress admin using a nice activity feed.

When your agent uses it

  • Checking code style
  • Fixing lint errors
  • Running static analysis

Example prompts

  • “/code-quality”

Requirements

  • Docker
  • Pre-approved tools (allowed-tools): Read, Grep, Glob, Bash

Workflow steps

3 steps, taken from the first numbered list in SKILL.md.

  1. Always escape output - Use WordPress escaping functions
  2. Prefix everything - All hooks, functions, classes
  3. Run tools after changes - phpcs/phpstan before committing

What it can do on your machine

Read from SKILL.md and the folder at commit a634f97. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves these tools, so the agent can use them without asking each time:

    • Read
    • Grep
    • Glob
    • Bash

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • composer

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Code Quality loads about 519 tokens when it runs. Until then it costs about 43 tokens; SKILL.md has 128 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~43
When it runs · the whole SKILL.md, loaded when a task matches
~519

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check: notes

The automated check noted patterns worth knowing about, such as sudo or a known installer.

  • NotePre-approves every shell command (allowed-tools: Bash)SKILL.md
    allowed-tools: Read, Grep, Glob, Bash

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

Without a licence we can't republish the file, so here is its outline and opening line. It has 128 words (~519 tokens).

“Always run phpstan via npm run php:phpstan. Bare vendor/bin/phpstan analyse crashes a worker at the default 128M and still crashes at 1G; the npm script passes the 2048M that actually works.”

— opening of SKILL.md by bonny
name
code-quality
allowed-tools
Read, Grep, Glob, Bash

Read the full SKILL.md on GitHub

Files

SKILL.md and 5 other files in .claude/skills/code-quality of bonny/WordPress-Simple-History.

  • SKILL.md
  • css-standards.md
  • design-principles.md
  • js-standards.md
  • php-standards.md
  • tooling.md

Open the folder on GitHubat commit a634f97

Compare with similar skills

Code Quality next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Code Quality compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Code Quality this skillbonny/WordPress-Simple-History317—~519Automated safety check: NotesNone
DevAutomattic/wordpress-activitypub582—~1.1kAutomated safety check: PassMIT
Grails Violation Fixerapache/grails-core2.9k—~3.9kAutomated safety check: PassApache-2.0
Convex Doctorwaynesutton/markdown-site628—~1.9kAutomated safety check: PassMIT
Code QualityBlackBeltTechnology/pi-agent-dashboard316—~1.3kAutomated safety check: PassMIT
Dx Code Analyzer Runforcedotcom/sf-skills1.1k—~6.3kAutomated safety check: PassApache-2.0

Similar skills

  • Dev

    Automattic/wordpress-activitypub

    Development workflows for WordPress ActivityPub plugin including wp-env setup, testing commands, linting, and build processes.

    582 GitHub stars~1.1k tokensUpdated today
    DevelopmentAuto-check passed
  • Grails Violation Fixer

    apache/grails-core

    Guide to running, reading and fixing code style and analysis violations in grails-core with CodeNarc, Checkstyle, PMD, SpotBugs, Spotless and JaCoCo through Gradle.

    2.9k GitHub stars~3.9k tokensUpdated today
    DevelopmentAuto-check passed
  • Convex Doctor

    waynesutton/markdown-site

    Run convex-doctor static analysis, interpret findings, and fix issues across security, performance, correctness, schema, and architecture categories.

    628 GitHub stars~1.9k tokensUpdated 4 mo ago
    DevelopmentAuto-check passed
  • Code Quality

    BlackBeltTechnology/pi-agent-dashboard

    Drive static-analysis code quality in pi-agent-dashboard with Biome (analyze → fix → test), in changed-files or whole-repo mode.

    316 GitHub stars~1.3k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Dx Code Analyzer Run

    forcedotcom/sf-skills

    Run Salesforce Code Analyzer to scan code for security, performance, best practice, and code style violations.

    1.1k GitHub stars~6.3k tokensUpdated 5 days ago
    DevelopmentAuto-check passed
  • Quality Checks

    dev-toolings/superpowers-symfony

    Run code quality tools: PHP-CS-Fixer for style, PHPStan for static analysis, and type safety checks

    222 GitHub stars~381 tokensUpdated 2 days ago
    DevelopmentAuto-check: notes

More from bonny/WordPress-Simple-History

All 21 skills in this repo
  • Blueprint

    bonny/WordPress-Simple-History

    A skill your agent uses when the deliverable is WordPress Playground Blueprint JSON or a Blueprint bundle, including creating, editing, reviewing, validating schema keys, choosing steps/resources…

    317 GitHub starsUsed in 1 repo~4k tokens
    Auto-check passed
  • Action Links

    bonny/WordPress-Simple-History

    Guides implementation of structured action links on log events.

    317 GitHub stars~3.7k tokensUpdated 3 days ago
    Auto-check passed
  • Changelog

    bonny/WordPress-Simple-History

    Adds changelog entries to readme.txt following keepachangelog format.

    317 GitHub stars~2.9k tokensUpdated 3 days ago
    Auto-check passed
  • Create Logger

    bonny/WordPress-Simple-History

    Guides creation of custom loggers for Simple History. An agent skill from bonny/WordPress-Simple-History.

    317 GitHub stars~3.7k tokensUpdated 3 days ago
    Auto-check: notes
  • Logger Messages

    bonny/WordPress-Simple-History

    Enforces active voice for logger messages and the Event Details API.

    317 GitHub stars~2k tokensUpdated 3 days ago
    Auto-check passed
  • Og Share Images

    bonny/WordPress-Simple-History

    Creates Open Graph / social share images (1200x630) for blog posts and announcements by rendering HTML in a headless browser.

    317 GitHub stars~1.6k tokensUpdated 3 days ago
    Auto-check: notes

Works with

Categories

Questions about Code Quality

What does Code Quality do?

Runs linting and static analysis on PHP/CSS/JS using phpcs, phpstan, and rector. Code Quality is an agent skill from bonny/WordPress-Simple-History. Runs linting and static analysis on PHP/CSS/JS using phpcs, phpstan, and rector.

When should I use Code Quality?

Code Quality fits situations like: checking code style; fixing lint errors; running static analysis.

How do I install Code Quality in Claude Code?

Run `npx skills add bonny/WordPress-Simple-History --skill code-quality -a claude-code`. Or copy the skill folder (.claude/skills/code-quality in bonny/WordPress-Simple-History) into .claude/skills/code-quality in your project. Claude Code loads it when a task matches its description.

How do I install Code Quality in Codex?

Run `npx skills add bonny/WordPress-Simple-History --skill code-quality -a codex`. Or copy the skill folder (.claude/skills/code-quality in bonny/WordPress-Simple-History) into .agents/skills/code-quality in your project. Codex loads it when a task matches its description.

Can I use Code Quality in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add bonny/WordPress-Simple-History --skill code-quality -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/code-quality, .gemini/skills/code-quality, .github/skills/code-quality and .opencode/skills/code-quality in your project.

What does Code Quality need to run?

Going by SKILL.md and its folder, Code Quality needs the command-line tools its instructions call (npm and composer). Our summary lists: Docker. Its frontmatter pre-approves these tools: Read, Grep, Glob, Bash.

Does Code Quality access the network?

SKILL.md contains no URLs. Its commands use npm, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Code Quality safe to install?

Our automated static check of SKILL.md found notes only (pre-approves every shell command (allowed-tools: bash)), nothing it rates as a warning. It is not a guarantee. Review the folder before installing.

What licence does Code Quality use?

No licence was found for Code Quality or its repository. Without one, default copyright applies: ask the author before reusing or redistributing it.

How many tokens does Code Quality use?

About 519 tokens (SKILL.md is roughly 2.1k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.

What are the alternatives to Code Quality?

Skills that share tags, products or a category with Code Quality: Dev (Automattic/wordpress-activitypub, 582 stars), Grails Violation Fixer (apache/grails-core, 2.9k stars), Convex Doctor (waynesutton/markdown-site, 628 stars) and Code Quality (BlackBeltTechnology/pi-agent-dashboard, 316 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Code Quality?

bonny (a GitHub user) maintains it in bonny/WordPress-Simple-History, which has 317 GitHub stars. The repository holds 21 skills in this directory. The repository was last updated on October 4, 2026.

Source: bonny/WordPress-Simple-History on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.