WooCommerce Code Review
woocommerce/woocommerce
Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.
Audit a WordPress plugin's REST surface and produce a standardized audit document proposing Abilities API registrations.
$ npx skills add gambitph/Stackable --skill wp-abilities-audit -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install gambitph/Stackable wp-abilities-audit --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/gambitph/Stackable.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/wp-abilities-audit .claude/skills/wp-abilities-audit && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "wp-abilities-audit" agent skill from https://github.com/gambitph/Stackable/tree/develop/.cursor/skills/wp-abilities-audit into .claude/skills/wp-abilities-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-abilities-audit", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/gambitph/Stackable/tree/develop/.cursor/skills/wp-abilities-auditType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add gambitph/Stackable --skill wp-abilities-audit -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install gambitph/Stackable wp-abilities-audit --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gambitph/Stackable.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.cursor/skills/wp-abilities-audit .agents/skills/wp-abilities-audit && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "wp-abilities-audit" agent skill from https://github.com/gambitph/Stackable/tree/develop/.cursor/skills/wp-abilities-audit into .agents/skills/wp-abilities-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-abilities-audit", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add gambitph/Stackable --skill wp-abilities-audit -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install gambitph/Stackable wp-abilities-audit --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gambitph/Stackable.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.cursor/skills/wp-abilities-audit .cursor/skills/wp-abilities-audit && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "wp-abilities-audit" agent skill from https://github.com/gambitph/Stackable/tree/develop/.cursor/skills/wp-abilities-audit into .cursor/skills/wp-abilities-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-abilities-audit", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/gambitph/Stackable.git --path .cursor/skills/wp-abilities-audit--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add gambitph/Stackable --skill wp-abilities-audit -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install gambitph/Stackable wp-abilities-audit --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gambitph/Stackable.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.cursor/skills/wp-abilities-audit .gemini/skills/wp-abilities-audit && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "wp-abilities-audit" agent skill from https://github.com/gambitph/Stackable/tree/develop/.cursor/skills/wp-abilities-audit into .gemini/skills/wp-abilities-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-abilities-audit", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install gambitph/Stackable wp-abilities-auditInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add gambitph/Stackable --skill wp-abilities-audit -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/gambitph/Stackable.git skills-src && mkdir -p .github/skills && cp -r skills-src/.cursor/skills/wp-abilities-audit .github/skills/wp-abilities-audit && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "wp-abilities-audit" agent skill from https://github.com/gambitph/Stackable/tree/develop/.cursor/skills/wp-abilities-audit into .github/skills/wp-abilities-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-abilities-audit", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add gambitph/Stackable --skill wp-abilities-audit -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install gambitph/Stackable wp-abilities-audit --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gambitph/Stackable.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.cursor/skills/wp-abilities-audit .opencode/skills/wp-abilities-audit && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "wp-abilities-audit" agent skill from https://github.com/gambitph/Stackable/tree/develop/.cursor/skills/wp-abilities-audit into .opencode/skills/wp-abilities-audit/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-abilities-audit", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
wp-abilities-auditAudit a WordPress plugin's REST surface and produce a standardized audit document proposing Abilities API registrations.
Wp Abilities Audit is an agent skill from gambitph/Stackable. Audit a WordPress plugin's REST surface and produce a standardized audit document proposing Abilities API registrations. Produces a markdown doc with a YAML schema and prose sections that humans and agents can both consume when planning a registration rollout. Works on any WP plugin.
Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/audit-schema.md`, `references/capability-gate-tracing.md` and `references/controller-enumeration.md`). Compatibility notes: Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Requires access to the plugin checkout; some workflows benefit from WP-CLI but…
It works with WordPress. The repository describes itself as: Page Builder Blocks for WordPress. An Amazing Block Library for the new WordPress Block Editor (Gutenberg). The licence is GPL-3.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 5c13d80. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
No scripts in the folder and no shell commands in SKILL.md.
From the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Requires access to the plugin checkout; some workflows benefit from WP-CLI but don't require it.
From compatibility in the SKILL.md frontmatter.
Wp Abilities Audit loads about 2.4k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 76 tokens; SKILL.md has 1,193 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from gambitph/Stackable at commit 5c13d80, republished under its GPL-3.0 licence (© gambitph). 1,193 words, ~2,440 tokens.
.claude/skills/wp-abilities-audit/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.Produce a standardized audit document for a WordPress plugin's REST surface, proposing a set of Abilities API registrations grouped by semantic intent. The audit doc is a planning artifact for implementers — humans, agents, or both — that captures the controller inventory, capability gates, and proposed ability shapes in a structured form. A reviewer reading the doc can scope the work without re-deriving the survey.
This skill works on any plugin that exposes a REST surface. Plugin
classification (for purposes of the optional plugin_family annotation) is
the user's call; the workflow itself is plugin-agnostic.
wp-project-triage first if not already done. The
audit consumes signals.usesAbilitiesApi, versions.wordpress, and
project.kind from the report.auditor field.wp-project-triage has run successfully and classified the plugin.Read references/controller-enumeration.md now — it covers the two observed
enumeration paths (glob for standard layouts, grep as the universal fallback)
and when to use each.
Record every controller class + file + REST base + routes in a "Controller Inventory" table. The inventory is exhaustive even though only a subset becomes proposed abilities.
For every controller found, extract the fields the audit schema requires:
class, file, HTTP method, route, route-registration line number, callback
name, callback line number, permission callback, whether the callback takes
a WP_REST_Request argument or is zero-arg, and the return type.
Read references/audit-schema.md now for the exact field list and the shape
of proposed_abilities entries. Line-number fields may be null for
inherited callbacks — the schema allows this and pairs it with an optional
inherited_from field.
Trace each controller's permission_callback to its current_user_can() call
(or to the post-type capability machinery if the controller extends a
post-type-backed base).
Read references/capability-gate-tracing.md now — it documents the two
common mechanisms (direct check_permission() vs post-type-backed
wc_rest_check_post_permissions()) and how to represent each in the schema.
Note explicitly whether read and write gates differ: compound gates are
represented as a {read, write} object, not a single string.
Do NOT atomize one ability per HTTP method. Apply the semantic-intent grouping heuristic — it's the only grouping rule this skill uses.
Read ../wp-abilities-api/references/grouping-heuristic.md now — do NOT
re-derive the rules here. Short version: one ability per real-world question
or state transition, with filter parameters in input_schema collapsing N
variants into 1.
Apply the use-case sanity check before populating any candidate. Per
../wp-abilities-api/references/domain-vs-projection.md's use-case-contract
test: would a human or agent intentionally perform this behavior through a
supported plugin workflow? If yes, the candidate is a real ability —
proceed to fill in fields. If no, the route is internal transport plumbing
(cache invalidation, scheduler ticks, bookkeeping endpoints, debug
introspection) — keep it in the Controller Inventory section for
completeness, but do NOT promote it to proposed_abilities. The route may
be useful to inventory; the proposed ability must represent a real
user/operator question or action.
For each proposed ability that passes the sanity check, fill in every
field in the proposed_abilities schema: name, intent, backing,
permission, return_type, effort (S/M/L), annotations
(readonly/destructive/idempotent), notes, risks, use_case_fit,
side_effects, seed_data_needs.
The last three are the implementation-readiness facts the implementer
and the verify-mode tooling both need: which human/agent workflow this
ability serves (use_case_fit), what the backing path emits on every
call (side_effects — empty array is a fact, not a missing value), and
what representative data must exist in the test environment for the
ability to execute through the public boundary (seed_data_needs).
Three buckets:
excluded_from_mvp — candidates intentionally deferred for risk reasons
(real-money writes, irreversible state changes, or prerequisite design
work). Each entry gets a one-sentence reason.surfaced_gaps — MVP candidates with no backing endpoint (ability with
backing: null), plus high-value endpoints discovered during enumeration
that aren't in the MVP list but would be easy future wins.permission_callback => '__return_true' that must NOT copy that into the
ability registration).Write to the explicit output path collected in "Inputs required". The
document structure must match references/audit-schema.md exactly:
Last updated: YYYY-MM-DD HH:MM header.proposed_abilities,
excluded_from_mvp, surfaced_gaps.A copy-pasteable minimal example showing the full shape lives in
references/audit-schema.md under "Minimal valid example" — start there
when authoring a new audit.
Set reference_ability: true on the first ability an implementer should
land — typically the smallest, safest, highest-leverage read. This gives
downstream workflows a deterministic starting point.
references/audit-schema.md (all required top-level
fields present, at least one entry in proposed_abilities, annotations
complete on every ability).capability_gate is a string for single-cap plugins or a {read, write}
object for post-type-backed plugins.backing: null also appears in surfaced_gaps.audit-schema.md "Known
limitations" without errors.WP_REST_Posts_Controller,
or extension plugins built on a parent's REST classes) — capture with
backing.inherited_from: "<parent FQCN>". Line-number fields may be
null per the schema.{read, write} form documented in
references/capability-gate-tracing.md. Don't smuggle a /-separated
string into a field typed as a single cap.../wp-abilities-api/references/grouping-heuristic.md. Do not invent
alternative grouping rules in the audit doc.permission_callback => '__return_true' —
legal at the REST layer, but the ability's own permission_callback must
match the plugin's merchant gate. Never promote '__return_true' into an
ability registration. Note this in the ability's risks.plans/). Writing the audit
into the plugin's own git history pollutes the worktree and buries the
artifact.references/controller-enumeration.md (neither the standard glob nor the
grep fallback produces a complete inventory), update that reference with
the new convention and open a PR so future audits cover it deterministically.references/capability-gate-tracing.md, extend that file rather than
encoding the new case in the audit's "Notes and Surprises" only.© gambitph, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 3 other files (references) in .cursor/skills/wp-abilities-audit of gambitph/Stackable.
Open the folder on GitHubat commit 5c13d80
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in gambitph/Stackable, which our catalogue first saw on October 7, 2026.
Wp Abilities Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Wp Abilities Audit this skillgambitph/Stackable | 350 | 1 repos | ~2.4k | Automated safety check: Pass | GPL-3.0 | |
| WooCommerce Code Reviewwoocommerce/woocommerce | 11k | 3 repos | ~1.1k | Automated safety check: Pass | Custom licence | |
| Postizgitroomhq/postiz-agent | 505 | 2 repos | ~7.9k | Automated safety check: Pass | AGPL-3.0 | |
| Wp Performance Reviewelvismdev/claude-wordpress-skills | 234 | 1 repos | ~4.5k | Automated safety check: Pass | MIT | |
| Wp Interactivity APIAutomattic/agent-skills | 211 | 2 repos | ~1.5k | Automated safety check: Pass | None | |
| Wp EnvWordPress/agent-skills | 2.2k | — | ~2.2k | Automated safety check: Pass | Custom licence |
woocommerce/woocommerce
Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.
gitroomhq/postiz-agent
Postiz is a tool to schedule social media and chat posts to 28+ channels X, LinkedIn, LinkedIn Page, Reddit, Instagram, Facebook Page, Threads, YouTube, Google My Business, TikTok, Pinterest…
elvismdev/claude-wordpress-skills
WordPress performance code review and optimization analysis.
Automattic/agent-skills
A skill your agent uses when building or debugging WordPress Interactivity API features (data-wp- directives, @wordpress/interactivity store/state/actions, block viewScriptModule integration…
WordPress/agent-skills
A skill your agent uses when setting up, configuring, or troubleshooting local WordPress development environments with @wordpress/env (wp-env).
wordpress-mobile/WordPress-Android
Builds the Jetpack debug app with Gradle and installs it on a connected Android device or an emulator started from an available AVD.
gambitph/Stackable
A skill your agent uses when developing WordPress (Gutenberg) blocks: block.json metadata, registerblocktype(frommetadata), attributes/serialization, supports, dynamic rendering…
gambitph/Stackable
A skill your agent uses when developing WordPress block themes: theme.json (global settings/styles), templates and template parts, patterns, style variations, and Site Editor troubleshooting (style…
gambitph/Stackable
A skill your agent uses when investigating or improving WordPress performance (backend-only agent): profiling and measurement (WP-CLI profile/doctor, Server-Timing, Query Monitor via REST headers)…
gambitph/Stackable
A skill your agent uses when developing WordPress plugins: architecture and hooks, activation/deactivation/uninstall, admin UI and Settings API, data storage, cron/tasks, security…
gambitph/Stackable
A skill your agent uses when you need a deterministic inspection of a WordPress repository (plugin/theme/block theme/WP core/Gutenberg/full site) including tooling/tests/version hints, and a…
gambitph/Stackable
A skill your agent uses when reviewing WordPress plugins for GPL compliance, checking license headers or compatibility, evaluating upsell/freemium/trialware patterns, validating plugin naming or…
Works with
Audit a WordPress plugin's REST surface and produce a standardized audit document proposing Abilities API registrations. Wp Abilities Audit is an agent skill from gambitph/Stackable. Audit a WordPress plugin's REST surface and produce a standardized audit document proposing Abilities API registrations.
Run `npx skills add gambitph/Stackable --skill wp-abilities-audit -a claude-code`. Or copy the skill folder (.cursor/skills/wp-abilities-audit in gambitph/Stackable) into .claude/skills/wp-abilities-audit in your project. Claude Code loads it when a task matches its description.
Run `npx skills add gambitph/Stackable --skill wp-abilities-audit -a codex`. Or copy the skill folder (.cursor/skills/wp-abilities-audit in gambitph/Stackable) into .agents/skills/wp-abilities-audit in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gambitph/Stackable --skill wp-abilities-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wp-abilities-audit, .gemini/skills/wp-abilities-audit, .github/skills/wp-abilities-audit and .opencode/skills/wp-abilities-audit in your project.
SKILL.md names no scripts, command-line tools or credentials: Wp Abilities Audit is instructions for the agent only. Compatibility (from SKILL.md): Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Requires access to the plugin checkout; some workflows benefit from WP-CLI but don't require it..
SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Wp Abilities Audit is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.8k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Wp Abilities Audit: WooCommerce Code Review (woocommerce/woocommerce, 11k stars), Postiz (gitroomhq/postiz-agent, 505 stars), Wp Performance Review (elvismdev/claude-wordpress-skills, 234 stars) and Wp Interactivity API (Automattic/agent-skills, 211 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
gambitph (a GitHub organization) maintains it in gambitph/Stackable, which has 350 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 7, 2026.
Source: gambitph/Stackable on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.