Agent skill

Wp Abilities Audit

by gambitph in gambitph/Stackable

Audit a WordPress plugin's REST surface and produce a standardized audit document proposing Abilities API registrations.

GPL-3.0Auto-check passed

Install Wp Abilities Audit

skills CLI
$ npx skills add gambitph/Stackable --skill wp-abilities-audit -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install gambitph/Stackable wp-abilities-audit --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/gambitph/Stackable.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/wp-abilities-audit .claude/skills/wp-abilities-audit && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
wp-abilities-audit
GitHub stars
350
Used in
1 other repo
Token cost
~2.4k tokens
SKILL.md length
1,193 words
Files
4 (incl. references)
Skills in repo
18
Repo updated
First seen
Licence
GPL-3.0

At a glance

Audit a WordPress plugin's REST surface and produce a standardized audit document proposing Abilities API registrations.

  • Works in 7 steps: Enumerate REST controllers → For each controller, extract the backing… → Confirm capability gate(s) → …
  • SKILL.md covers When to use, Inputs required, Prerequisites and Procedure, plus 3 more sections
  • Instructions only: no scripts, shell commands, URLs or credentials in SKILL.md

What it does

Wp Abilities Audit is an agent skill from gambitph/Stackable. Audit a WordPress plugin's REST surface and produce a standardized audit document proposing Abilities API registrations. Produces a markdown doc with a YAML schema and prose sections that humans and agents can both consume when planning a registration rollout. Works on any WP plugin.

Its SKILL.md is about 2.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/audit-schema.md`, `references/capability-gate-tracing.md` and `references/controller-enumeration.md`). Compatibility notes: Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Requires access to the plugin checkout; some workflows benefit from WP-CLI but…

It works with WordPress. The repository describes itself as: Page Builder Blocks for WordPress. An Amazing Block Library for the new WordPress Block Editor (Gutenberg). The licence is GPL-3.0.

Example prompts

  • “/wp-abilities-audit”

Requirements

  • Compatibility (from SKILL.md): Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Requires access to the plugin checkout; some workflows benefit from WP-CLI but don't require it.

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. Enumerate REST controllers
  2. For each controller, extract the backing fields
  3. Confirm capability gate(s)
  4. Propose abilities using semantic-intent grouping
  5. Surface gaps and deferred items
  6. Write the audit doc
  7. (Optional) Designate a reference implementation ability

What it can do on your machine

Read from SKILL.md and the folder at commit 5c13d80. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    No scripts in the folder and no shell commands in SKILL.md.

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Requires access to the plugin checkout; some workflows benefit from WP-CLI but don't require it.

    From compatibility in the SKILL.md frontmatter.

Context cost

Wp Abilities Audit loads about 2.4k tokens when it runs, and up to ~10k if it reads all its reference files. Until then it costs about 76 tokens; SKILL.md has 1,193 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~2.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~10k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from gambitph/Stackable at commit 5c13d80, republished under its GPL-3.0 licence (© gambitph). 1,193 words, ~2,440 tokens.

Download SKILL.mdSave it as .claude/skills/wp-abilities-audit/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
wp-abilities-audit
description
Audit a WordPress plugin's REST surface and produce a standardized audit document proposing Abilities API registrations. Produces a markdown doc with a YAML schema and prose sections that humans and agents can both consume when planning a registration rollout. Works on any WP plugin.
compatibility
Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Requires access to the plugin checkout; some workflows benefit from WP-CLI but don't require it.

WP Abilities Audit

Produce a standardized audit document for a WordPress plugin's REST surface, proposing a set of Abilities API registrations grouped by semantic intent. The audit doc is a planning artifact for implementers — humans, agents, or both — that captures the controller inventory, capability gates, and proposed ability shapes in a structured form. A reviewer reading the doc can scope the work without re-deriving the survey.

This skill works on any plugin that exposes a REST surface. Plugin classification (for purposes of the optional plugin_family annotation) is the user's call; the workflow itself is plugin-agnostic.

When to use

  • The task is "register Abilities API abilities for a WP plugin" and no audit doc exists yet.
  • Planning participation in a multi-plugin abilities rollout and need a shareable, standardized audit artifact.
  • Pre-flight checking a plugin's agent-readiness before implementing abilities.
  • A PM or non-implementer wants to scope the work before engineering picks it up.

Inputs required

  1. Plugin checkout path — working tree of the plugin to audit.
  2. Triage output — run wp-project-triage first if not already done. The audit consumes signals.usesAbilitiesApi, versions.wordpress, and project.kind from the report.
  3. Auditor identity — name and team or context, recorded in the audit's auditor field.
  4. Output path — where the audit doc should land. Default explicit over implicit; ask if not provided rather than writing into the plugin worktree.

Prerequisites

  • wp-project-triage has run successfully and classified the plugin.
  • The plugin has at least one REST controller. If enumeration finds zero controllers, the audit doesn't apply — see "Failure modes" below.

Procedure

1. Enumerate REST controllers

Read references/controller-enumeration.md now — it covers the two observed enumeration paths (glob for standard layouts, grep as the universal fallback) and when to use each.

Record every controller class + file + REST base + routes in a "Controller Inventory" table. The inventory is exhaustive even though only a subset becomes proposed abilities.

2. For each controller, extract the backing fields

For every controller found, extract the fields the audit schema requires: class, file, HTTP method, route, route-registration line number, callback name, callback line number, permission callback, whether the callback takes a WP_REST_Request argument or is zero-arg, and the return type.

Read references/audit-schema.md now for the exact field list and the shape of proposed_abilities entries. Line-number fields may be null for inherited callbacks — the schema allows this and pairs it with an optional inherited_from field.

3. Confirm capability gate(s)

Trace each controller's permission_callback to its current_user_can() call (or to the post-type capability machinery if the controller extends a post-type-backed base).

Read references/capability-gate-tracing.md now — it documents the two common mechanisms (direct check_permission() vs post-type-backed wc_rest_check_post_permissions()) and how to represent each in the schema. Note explicitly whether read and write gates differ: compound gates are represented as a {read, write} object, not a single string.

4. Propose abilities using semantic-intent grouping

Do NOT atomize one ability per HTTP method. Apply the semantic-intent grouping heuristic — it's the only grouping rule this skill uses.

Read ../wp-abilities-api/references/grouping-heuristic.md now — do NOT re-derive the rules here. Short version: one ability per real-world question or state transition, with filter parameters in input_schema collapsing N variants into 1.

Apply the use-case sanity check before populating any candidate. Per ../wp-abilities-api/references/domain-vs-projection.md's use-case-contract test: would a human or agent intentionally perform this behavior through a supported plugin workflow? If yes, the candidate is a real ability — proceed to fill in fields. If no, the route is internal transport plumbing (cache invalidation, scheduler ticks, bookkeeping endpoints, debug introspection) — keep it in the Controller Inventory section for completeness, but do NOT promote it to proposed_abilities. The route may be useful to inventory; the proposed ability must represent a real user/operator question or action.

For each proposed ability that passes the sanity check, fill in every field in the proposed_abilities schema: name, intent, backing, permission, return_type, effort (S/M/L), annotations (readonly/destructive/idempotent), notes, risks, use_case_fit, side_effects, seed_data_needs.

The last three are the implementation-readiness facts the implementer and the verify-mode tooling both need: which human/agent workflow this ability serves (use_case_fit), what the backing path emits on every call (side_effects — empty array is a fact, not a missing value), and what representative data must exist in the test environment for the ability to execute through the public boundary (seed_data_needs).

Show full SKILL.md (500 more words)Show less
5. Surface gaps and deferred items

Three buckets:

  • excluded_from_mvp — candidates intentionally deferred for risk reasons (real-money writes, irreversible state changes, or prerequisite design work). Each entry gets a one-sentence reason.
  • surfaced_gaps — MVP candidates with no backing endpoint (ability with backing: null), plus high-value endpoints discovered during enumeration that aren't in the MVP list but would be easy future wins.
  • Risks per ability — anything about a backing endpoint that the implementer must handle (no idempotency key, two-phase behavior, state-transition caveats, zero-arg endpoints registered with permission_callback => '__return_true' that must NOT copy that into the ability registration).
6. Write the audit doc

Write to the explicit output path collected in "Inputs required". The document structure must match references/audit-schema.md exactly:

  1. Last updated: YYYY-MM-DD HH:MM header.
  2. YAML block with all required top-level metadata + proposed_abilities, excluded_from_mvp, surfaced_gaps.
  3. "Controller Inventory" table.
  4. "Notes and Surprises" prose section.

A copy-pasteable minimal example showing the full shape lives in references/audit-schema.md under "Minimal valid example" — start there when authoring a new audit.

7. (Optional) Designate a reference implementation ability

Set reference_ability: true on the first ability an implementer should land — typically the smallest, safest, highest-leverage read. This gives downstream workflows a deterministic starting point.

Verification

  • The audit conforms to references/audit-schema.md (all required top-level fields present, at least one entry in proposed_abilities, annotations complete on every ability).
  • capability_gate is a string for single-cap plugins or a {read, write} object for post-type-backed plugins.
  • Every ability with backing: null also appears in surfaced_gaps.
  • The doc round-trips through the validator in audit-schema.md "Known limitations" without errors.

Failure modes / debugging

  • Plugin has no REST controllers — audit doesn't apply. Consider hooks/filters-based abilities (out of scope for this skill's current version) or skip abilities adoption for this plugin.
  • Plugin inherits controllers from another repo (common for plugins extending core post-type-backed controllers like WP_REST_Posts_Controller, or extension plugins built on a parent's REST classes) — capture with backing.inherited_from: "<parent FQCN>". Line-number fields may be null per the schema.
  • Compound capability gate (distinct read/write caps) — use the structured {read, write} form documented in references/capability-gate-tracing.md. Don't smuggle a /-separated string into a field typed as a single cap.
  • Ambiguous grouping — route to ../wp-abilities-api/references/grouping-heuristic.md. Do not invent alternative grouping rules in the audit doc.
  • Zero-arg endpoints with permission_callback => '__return_true' — legal at the REST layer, but the ability's own permission_callback must match the plugin's merchant gate. Never promote '__return_true' into an ability registration. Note this in the ability's risks.
  • Output path defaults to plugin worktree — always ask the user for an explicit output directory (e.g. their vault plans/). Writing the audit into the plugin's own git history pollutes the worktree and buries the artifact.

Escalation

  • If the plugin uses an enumeration convention not covered by references/controller-enumeration.md (neither the standard glob nor the grep fallback produces a complete inventory), update that reference with the new convention and open a PR so future audits cover it deterministically.
  • If capability tracing hits a mechanism not covered by references/capability-gate-tracing.md, extend that file rather than encoding the new case in the audit's "Notes and Surprises" only.

© gambitph, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in .cursor/skills/wp-abilities-audit of gambitph/Stackable.

  • SKILL.md
  • references/audit-schema.md
  • references/capability-gate-tracing.md
  • references/controller-enumeration.md

Open the folder on GitHubat commit 5c13d80

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in gambitph/Stackable, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Wp Abilities Audit next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Wp Abilities Audit compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Wp Abilities Audit this skillgambitph/Stackable3501 repos~2.4kAutomated safety check: PassGPL-3.0
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence
Postizgitroomhq/postiz-agent5052 repos~7.9kAutomated safety check: PassAGPL-3.0
Wp Performance Reviewelvismdev/claude-wordpress-skills2341 repos~4.5kAutomated safety check: PassMIT
Wp Interactivity APIAutomattic/agent-skills2112 repos~1.5kAutomated safety check: PassNone
Wp EnvWordPress/agent-skills2.2k—~2.2kAutomated safety check: PassCustom licence

Similar skills

  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Postiz

    gitroomhq/postiz-agent

    Postiz is a tool to schedule social media and chat posts to 28+ channels X, LinkedIn, LinkedIn Page, Reddit, Instagram, Facebook Page, Threads, YouTube, Google My Business, TikTok, Pinterest…

    505 GitHub starsUsed in 2 repos~7.9k tokens
    Writing & ContentAuto-check passed
  • Wp Performance Review

    elvismdev/claude-wordpress-skills

    WordPress performance code review and optimization analysis.

    234 GitHub starsUsed in 1 repo~4.5k tokens
    Business, Finance & HRAuto-check passed
  • Wp Interactivity API

    Automattic/agent-skills

    A skill your agent uses when building or debugging WordPress Interactivity API features (data-wp- directives, @wordpress/interactivity store/state/actions, block viewScriptModule integration…

    211 GitHub starsUsed in 2 repos~1.5k tokens
    DevelopmentAuto-check passed
  • Wp Env

    WordPress/agent-skills

    A skill your agent uses when setting up, configuring, or troubleshooting local WordPress development environments with @wordpress/env (wp-env).

    2.2k GitHub stars~2.2k tokensUpdated 2 days ago
    DevOps & CloudAuto-check passed
  • Run Jetpack Android App

    wordpress-mobile/WordPress-Android

    Builds the Jetpack debug app with Gradle and installs it on a connected Android device or an emulator started from an available AVD.

    3.2k GitHub stars~886 tokensUpdated today
    MobileAuto-check passed

More from gambitph/Stackable

All 18 skills in this repo
  • Wp Block Development

    gambitph/Stackable

    A skill your agent uses when developing WordPress (Gutenberg) blocks: block.json metadata, registerblocktype(frommetadata), attributes/serialization, supports, dynamic rendering…

    350 GitHub starsUsed in 3 repos~1.6k tokens
    Auto-check passed
  • Wp Block Themes

    gambitph/Stackable

    A skill your agent uses when developing WordPress block themes: theme.json (global settings/styles), templates and template parts, patterns, style variations, and Site Editor troubleshooting (style…

    350 GitHub starsUsed in 3 repos~985 tokens
    Auto-check passed
  • Wp Performance

    gambitph/Stackable

    A skill your agent uses when investigating or improving WordPress performance (backend-only agent): profiling and measurement (WP-CLI profile/doctor, Server-Timing, Query Monitor via REST headers)…

    350 GitHub starsUsed in 3 repos~1.5k tokens
    Auto-check passed
  • Wp Plugin Development

    gambitph/Stackable

    A skill your agent uses when developing WordPress plugins: architecture and hooks, activation/deactivation/uninstall, admin UI and Settings API, data storage, cron/tasks, security…

    350 GitHub starsUsed in 3 repos~999 tokens
    Auto-check passed
  • Wp Project Triage

    gambitph/Stackable

    A skill your agent uses when you need a deterministic inspection of a WordPress repository (plugin/theme/block theme/WP core/Gutenberg/full site) including tooling/tests/version hints, and a…

    350 GitHub starsUsed in 3 repos~371 tokens
    Auto-check passed
  • A skill your agent uses when reviewing WordPress plugins for GPL compliance, checking license headers or compatibility, evaluating upsell/freemium/trialware patterns, validating plugin naming or…

    350 GitHub starsUsed in 1 repo~1.6k tokens
    Auto-check passed

Works with

Questions about Wp Abilities Audit

What does Wp Abilities Audit do?

Audit a WordPress plugin's REST surface and produce a standardized audit document proposing Abilities API registrations. Wp Abilities Audit is an agent skill from gambitph/Stackable. Audit a WordPress plugin's REST surface and produce a standardized audit document proposing Abilities API registrations.

How do I install Wp Abilities Audit in Claude Code?

Run `npx skills add gambitph/Stackable --skill wp-abilities-audit -a claude-code`. Or copy the skill folder (.cursor/skills/wp-abilities-audit in gambitph/Stackable) into .claude/skills/wp-abilities-audit in your project. Claude Code loads it when a task matches its description.

How do I install Wp Abilities Audit in Codex?

Run `npx skills add gambitph/Stackable --skill wp-abilities-audit -a codex`. Or copy the skill folder (.cursor/skills/wp-abilities-audit in gambitph/Stackable) into .agents/skills/wp-abilities-audit in your project. Codex loads it when a task matches its description.

Can I use Wp Abilities Audit in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gambitph/Stackable --skill wp-abilities-audit -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wp-abilities-audit, .gemini/skills/wp-abilities-audit, .github/skills/wp-abilities-audit and .opencode/skills/wp-abilities-audit in your project.

What does Wp Abilities Audit need to run?

SKILL.md names no scripts, command-line tools or credentials: Wp Abilities Audit is instructions for the agent only. Compatibility (from SKILL.md): Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Requires access to the plugin checkout; some workflows benefit from WP-CLI but don't require it..

Does Wp Abilities Audit access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Wp Abilities Audit safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Wp Abilities Audit use?

Wp Abilities Audit is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Wp Abilities Audit use?

About 2.4k tokens (SKILL.md is roughly 9.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 7.8k tokens, read only when the agent opens those files.

What are the alternatives to Wp Abilities Audit?

Skills that share tags, products or a category with Wp Abilities Audit: WooCommerce Code Review (woocommerce/woocommerce, 11k stars), Postiz (gitroomhq/postiz-agent, 505 stars), Wp Performance Review (elvismdev/claude-wordpress-skills, 234 stars) and Wp Interactivity API (Automattic/agent-skills, 211 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Wp Abilities Audit?

gambitph (a GitHub organization) maintains it in gambitph/Stackable, which has 350 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 7, 2026.

Source: gambitph/Stackable on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.