WooCommerce Code Review
woocommerce/woocommerce
Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.
How to write GTM4WP CHANGELOG.md / readme.txt entries. An agent skill from duracelltomi/gtm4wp.
$ npx skills add duracelltomi/gtm4wp --skill changelog -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install duracelltomi/gtm4wp changelog --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/duracelltomi/gtm4wp.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.claude/skills/changelog .claude/skills/changelog && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "changelog" agent skill from https://github.com/duracelltomi/gtm4wp/tree/master/.claude/skills/changelog into .claude/skills/changelog/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "changelog", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/duracelltomi/gtm4wp/tree/master/.claude/skills/changelogType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add duracelltomi/gtm4wp --skill changelog -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install duracelltomi/gtm4wp changelog --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/duracelltomi/gtm4wp.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.claude/skills/changelog .agents/skills/changelog && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "changelog" agent skill from https://github.com/duracelltomi/gtm4wp/tree/master/.claude/skills/changelog into .agents/skills/changelog/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "changelog", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add duracelltomi/gtm4wp --skill changelog -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install duracelltomi/gtm4wp changelog --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/duracelltomi/gtm4wp.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.claude/skills/changelog .cursor/skills/changelog && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "changelog" agent skill from https://github.com/duracelltomi/gtm4wp/tree/master/.claude/skills/changelog into .cursor/skills/changelog/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "changelog", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/duracelltomi/gtm4wp.git --path .claude/skills/changelog--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add duracelltomi/gtm4wp --skill changelog -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install duracelltomi/gtm4wp changelog --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/duracelltomi/gtm4wp.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.claude/skills/changelog .gemini/skills/changelog && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "changelog" agent skill from https://github.com/duracelltomi/gtm4wp/tree/master/.claude/skills/changelog into .gemini/skills/changelog/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "changelog", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install duracelltomi/gtm4wp changelogInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add duracelltomi/gtm4wp --skill changelog -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/duracelltomi/gtm4wp.git skills-src && mkdir -p .github/skills && cp -r skills-src/.claude/skills/changelog .github/skills/changelog && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "changelog" agent skill from https://github.com/duracelltomi/gtm4wp/tree/master/.claude/skills/changelog into .github/skills/changelog/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "changelog", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add duracelltomi/gtm4wp --skill changelog -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install duracelltomi/gtm4wp changelog --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/duracelltomi/gtm4wp.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.claude/skills/changelog .opencode/skills/changelog && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "changelog" agent skill from https://github.com/duracelltomi/gtm4wp/tree/master/.claude/skills/changelog into .opencode/skills/changelog/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "changelog", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
changelogHow to write GTM4WP CHANGELOG.md / readme.txt entries. An agent skill from duracelltomi/gtm4wp.
Changelog is an agent skill from duracelltomi/gtm4wp. How to write GTM4WP CHANGELOG.md / readme.txt entries. Follow when adding, editing, or grouping a changelog bullet for a production-code change, or when the require-changelog Stop/commit-msg hook blocks you. Covers the "last released stable version is the baseline" rule (drop back-ported fixes and dev-only regressions), the "write for the upgrading user" rule (edit an unreleased feature's existing bullet vs. add a new Fixed: bullet), the 2.0 theme grouping, the readme.txt mirror, and the [skip changelog] escape…
Its SKILL.md is about 2.5k tokens, which your agent loads only when the skill is triggered. It is a single SKILL.md file with no bundled scripts.
It sits in Development, covering Changelog and release notes. It works with WordPress, PHP and WooCommerce. The repository describes itself as: Google Tag Manager plugin for WordPress. The licence is GPL-2.0-or-later.
4 steps, taken from the first numbered list in SKILL.md.
Read from SKILL.md and the folder at commit faa97d2. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
gitbashFrom the folder's file list and the shell code blocks in SKILL.md.
Hosts in commands or code, which the agent is likely to contact:
gtm4wp.comFrom URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Changelog loads about 2.5k tokens when it runs. Until then it costs about 133 tokens; SKILL.md has 1,324 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from duracelltomi/gtm4wp at commit faa97d2, republished under its GPL-2.0-or-later licence (© duracelltomi). 1,324 words, ~2,513 tokens.
.claude/skills/changelog/SKILL.md (or your agent's skills folder).Every change to production code ships a matching bullet under the top unreleased
heading in CHANGELOG.md (* Added: / * Changed: / * Updated: / * Fixed:). The
heading is ## <development target> per .claude/RELEASE-STATE.md; when the top heading
is a released version (right after a release, before any new production change), the
change that needs a bullet opens the new heading above it in the same edit.
"Production code" = src/**.php, compat/**.php, js/frontend/**.js, js/admin/**.js,
the main plugin file and uninstall.php. Tests, docs and .security//.testing/
housekeeping are exempt.
## 2.0.5 (2026-10-01). The release skill adds it after the SVN push; never type
it from memory and never use the GitHub date (wordpress.org has followed days later).
The unreleased headings at the top carry no date.CHANGELOG.md is the source of the gtm4wp.com changelog pages
(tools/build-changelog-page.js); never edit those pages on the site. The generator
stops on a released heading without a date, a malformed heading, or markdown it does
not support: ###/####, * bullets with one tab-indented level, paragraphs, and
inline bold, italic, code and links.#v2-0-5) is linked from posts, social
posts and forum replies.Release post: [Title](https://gtm4wp.com/…). It renders as "Read more" and is not a
bullet, so it is outside the word budget.Every bullet in the unreleased block describes a delta against the last
released stable version — named in .claude/RELEASE-STATE.md, verifiable as
Stable tag: in readme.txt on the released stable branch. Not against the
previous major, and not against last week's working tree. Two consequences:
Before writing "previously…", "the last version did…", or "no longer…", confirm the
claim against the released code (git grep <symbol> 2.0 <!-- release-coupled: the
released stable branch -->). A bullet whose "previously" only ever existed on the
development branch describes nothing the reader lived through.
While a version is unreleased, a fix to a feature introduced in that same
version must edit that feature's existing bullet, not add a new * Fixed:
bullet. A user upgrading from the last release never ran the intermediate code,
so for them the feature plus its development fixes is a single * Added:. Add a
* Fixed: bullet only for a defect that shipped in a released version.
Corollaries:
CHANGELOG.md (e.g. refine the feature's wording) to
satisfy the hook.[skip changelog] in the commit message instead.CHANGELOG.md changed, not that a bullet was added.### theme headings (the ## 2.0
section used: Architecture, Settings screen, Container, Page variables,
WooCommerce, Media events, Consent, Contact Form 7, AMP, Removed). Where the
unreleased section has theme groups, put a new bullet in its group rather than
at the top of the section.readme.txt's matching = <version> = block mirrors the unreleased
section (flattened for WordPress.org: no nested lists, **bold** lead-ins
instead of ###). A user-visible change updates both files together, opening
the readme block alongside the changelog heading when it does not exist yet.Budget: 25–40 words, ceiling 60. A bullet is release notes for somebody
upgrading, not the investigation that produced the change. Measured 2026-09-23,
the unreleased 2.1 section ran to 280 words per bullet against 117 for 2.0 and 57
for 1.22.5, and readme.txt's changelog section stood at 6,928 words against the
5,000-word cap wordpress.org truncates at (U150 / drift row D21) — so length
here is a published defect, not a matter of taste.
What a bullet carries, in this order:
(#145), Thanks to @user for the report.Leave out: how the bug was found, what the code did internally, which class or hook was involved, how long it had been broken, what was measured or ruled out, and reassurance that unaffected setups are unaffected. An option's full explanation belongs in its field description and on gtm4wp.com, not here — link it instead of restating it.
readme.txt is the tighter of the two: it mirrors the entry, flattened, and the
whole == Changelog == section stays under 5,000 words (target ~4,000), so older
sections get summarised and linked to the gtm4wp.com changelog
(https://gtm4wp.com/changelog, 1.x: /changelog/1-x) rather than left in full.
The prose-budget Stop hook reports any bullet over 60 words that the working
tree added; bash .claude/hooks/prose-budget.sh check runs the same check by hand.
One shared script, .claude/hooks/require-changelog.sh, enforces this:
Stop hook (in .claude/settings.json) blocks wrapping up a turn
that left production code modified without a CHANGELOG.md change;commit-msg hook (.githooks/commit-msg) rejects a commit that stages
production code without staging CHANGELOG.md. Escape hatch for non-user-facing
commits: put [skip changelog] in the commit message (or git commit --no-verify).One-time setup after cloning (the git hook lives in a tracked dir, so it must be
activated once per clone): git config core.hooksPath .githooks.
That simple setup executes .githooks/commit-msg, which execs
.claude/hooks/require-changelog.sh — both resolved from the checked-out tree. So a
branch you are only reviewing supplies the shell code that runs as you on your next
commit, and on every Claude turn through the Stop hook, with no command typed
(.security finding #77, rated D0 → D1).
That matters only if untrusted branches get checked out in a clone. Where they do, run the check from a fixed ref instead, with the entry point outside the tree:
mkdir -p ~/.githooks/gtm4wp
# ~/.githooks/gtm4wp/gtm4wp-changelog-check - materialises the script from a fixed ref:
# git show-ref --verify -q refs/tags/master && exit 1 # a tag would shadow it
# C=$(git rev-parse --verify -q 'refs/heads/master^{commit}') || exit 1
# git show "$C:.claude/hooks/require-changelog.sh" > "$TMP" || exit 1 # fail CLOSED
# exec bash "$TMP" "$@"
# ~/.githooks/gtm4wp/commit-msg - exec .../gtm4wp-changelog-check commitmsg "$1"
git config core.hooksPath ~/.githooks/gtm4wpand point the Stop hook in .claude/settings.json at the same runner. The logic stays
here, versioned and reviewed; only the copy that executes is pinned.
Four things worth knowing before adopting it:
bash <(git show "$REF:$SRC")
fails open — an unresolvable path yields an empty script, bash runs nothing, exits
0, and the commit sails through unchecked. Verified by measurement, not assumed.git show master:<path> resolves a tag
named master before the branch, and fetching from a fork can import one. Resolve
refs/heads/master to a commit id first. Passing refs/heads/master:<path> as one
argument does not work under Git Bash, which rewrites it as a path list.require-changelog.sh takes effect once it is committed to the ref, not
while it sits uncommitted in your tree.package.json prepare script: that script comes from
the worktree too, so a branch would supply the installer meant to defend against
branch-supplied code. An earlier attempt to make this the tracked default was declined
because it blocked every commit until an installer had been run — this version changes
no tracked file, so nothing breaks for anyone who keeps the simple setup.© duracelltomi, GPL-2.0-or-later. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
Just SKILL.md in .claude/skills/changelog of duracelltomi/gtm4wp.
Open the folder on GitHubat commit faa97d2
Changelog next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Changelog this skillduracelltomi/gtm4wp | 174 | — | ~2.5k | Automated safety check: Pass | GPL-2.0-or-later | |
| WooCommerce Code Reviewwoocommerce/woocommerce | 11k | 3 repos | ~1.1k | Automated safety check: Pass | Custom licence | |
| WooCommerce Dev Cyclewoocommerce/woocommerce | 11k | 3 repos | ~431 | Automated safety check: Pass | Custom licence | |
| WooCommerce Backend Conventionswoocommerce/woocommerce | 11k | 1 repos | ~614 | Automated safety check: Pass | Custom licence | |
| Add Changeloggambitph/Stackable | 351 | — | ~1.5k | Automated safety check: Pass | GPL-3.0 | |
| WordPress ProJeffallan/claude-skills | 12k | — | ~1.6k | Automated safety check: Pass | MIT |
woocommerce/woocommerce
Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.
woocommerce/woocommerce
Workflow for WooCommerce development: run PHP and JavaScript tests, lint and fix code style on the current branch, and follow guides for i18n and markdown.
woocommerce/woocommerce
Guides agents writing or changing WooCommerce backend PHP so new classes, hooks and unit tests follow the project's conventions.
gambitph/Stackable
Adds or updates a WordPress plugin changelog entry in readme.txt from the project's Release Roadmap for a confirmed plugin version.
Jeffallan/claude-skills
Develops WordPress themes, plugins, Gutenberg blocks and WooCommerce features with nonce, escaping and capability checks, phpcs linting and caching tuned for speed.
woocommerce/woocommerce
Sets up a local environment for the WooCommerce block email editor, with a watcher, Mailpit email capture and build and test commands for its PHP and JS packages.
duracelltomi/gtm4wp
Triage GTM4WP support topics and reviews on the wordpress.org forum — read a topic (or a batch), work out whether it is already fixed in a released version, classify it, screen for security…
duracelltomi/gtm4wp
Triage and manage GTM4WP GitHub issues — read an issue (or a batch), classify it, check for duplicates/already-fixed, screen for security disclosures, and draft a polite reply plus proposed labels.
duracelltomi/gtm4wp
Cut a GTM4WP release — pre-flight verification, the version bumps, tag, ZIP, GitHub release with post-upload verification, branch mechanics, and the propagation sweep that updates RELEASE-STATE.md…
duracelltomi/gtm4wp
Guide to create WooCommerce related WordPress plugins that extends WooCommerce functionality with a consistent and maintainable approach.
duracelltomi/gtm4wp
Guide to maintain creating modern and secure code while developing WordPress plugins.
Works with
Categories
How to write GTM4WP CHANGELOG.md / readme.txt entries. An agent skill from duracelltomi/gtm4wp. Changelog is an agent skill from duracelltomi/gtm4wp.txt entries.
Changelog fits situations like: tasks that involve Changelog and release notes.
Run `npx skills add duracelltomi/gtm4wp --skill changelog -a claude-code`. Or copy the skill folder (.claude/skills/changelog in duracelltomi/gtm4wp) into .claude/skills/changelog in your project. Claude Code loads it when a task matches its description.
Run `npx skills add duracelltomi/gtm4wp --skill changelog -a codex`. Or copy the skill folder (.claude/skills/changelog in duracelltomi/gtm4wp) into .agents/skills/changelog in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add duracelltomi/gtm4wp --skill changelog -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/changelog, .gemini/skills/changelog, .github/skills/changelog and .opencode/skills/changelog in your project.
Going by SKILL.md and its folder, Changelog needs the command-line tools its instructions call (git and bash).
SKILL.md names 1 domain. In commands or code: gtm4wp.com; the agent is likely to contact it when it follows the instructions. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Changelog is published under the GPL-2.0-or-later licence (declared in SKILL.md). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.5k tokens (SKILL.md is roughly 10k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full.
Skills that share tags, products or a category with Changelog: WooCommerce Code Review (woocommerce/woocommerce, 11k stars), WooCommerce Dev Cycle (woocommerce/woocommerce, 11k stars), WooCommerce Backend Conventions (woocommerce/woocommerce, 11k stars) and Add Changelog (gambitph/Stackable, 351 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
duracelltomi (a GitHub user) maintains it in duracelltomi/gtm4wp, which has 174 GitHub stars. The repository holds 6 skills in this directory. The repository was last updated on October 9, 2026.
Source: duracelltomi/gtm4wp on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.