Agent skill

Wp Abilities Verify

by gambitph in gambitph/Stackable

Verify a WordPress plugin's Abilities API registrations: enumerate abilities, check that callback behavior matches each annotation's claim (the adversarial readonly-but-writes detection), validate…

GPL-3.0Auto-check passedDevelopment

Install Wp Abilities Verify

skills CLI
$ npx skills add gambitph/Stackable --skill wp-abilities-verify -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install gambitph/Stackable wp-abilities-verify --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/gambitph/Stackable.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/wp-abilities-verify .claude/skills/wp-abilities-verify && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
wp-abilities-verify
GitHub stars
351
Used in
1 other repo
Token cost
~2.2k tokens
SKILL.md length
998 words
Files
7 (incl. references)
Skills in repo
18
Repo updated
First seen
Licence
GPL-3.0

At a glance

Verify a WordPress plugin's Abilities API registrations: enumerate abilities, check that callback behavior matches each annotation's claim (the adversarial readonly-but-writes detection), validate…

  • Works in 7 steps: (If audit provided) Validate the audit doc → Enumerate abilities statically → (Runtime only) Enumerate via REST + wp-cli → …
  • Development work in your project
  • SKILL.md covers When to use, Two modes, Inputs required and Prerequisites, plus 5 more sections
  • Calls npm and npx

What it does

Wp Abilities Verify is an agent skill from gambitph/Stackable. Verify a WordPress plugin's Abilities API registrations: enumerate abilities, check that callback behavior matches each annotation's claim (the adversarial readonly-but-writes detection), validate permissions and schemas, and validate audit documents produced by wp-abilities-audit.

Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/annotation-correctness.md`, `references/audit-schema-validation.md` and `references/permission-roundtrip.md`). Compatibility notes: Targets WordPress 7.0+ plugins (PHP 7.4.0+). Requires a runnable environment (wp-env, docker-based dev stack, or equivalent) for runtime mode; static mode…

It sits in Development. It works with WordPress. The repository describes itself as: Page Builder Blocks for WordPress. An Amazing Block Library for the new WordPress Block Editor (Gutenberg). The licence is GPL-3.0.

When your agent uses it

  • Development work in your project

Example prompts

  • “/wp-abilities-verify”

Requirements

  • Node.js
  • Docker
  • Compatibility (from SKILL.md): Targets WordPress 7.0+ plugins (PHP 7.4.0+). Requires a runnable environment (wp-env, docker-based dev stack, or equivalent) for runtime mode; static mode runs entirely from the plugin checkout with no env. Filesystem-based agent with bash + node.

Workflow steps

7 steps, taken from the step headings in SKILL.md.

  1. (If audit provided) Validate the audit doc
  2. Enumerate abilities statically
  3. (Runtime only) Enumerate via REST + wp-cli
  4. Annotation correctness (the adversarial core)
  5. Permission roundtrip
  6. Schema lints
  7. Error-code vocabulary

What it can do on your machine

Read from SKILL.md and the folder at commit 5c13d80. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • npm
    • npx

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm and npx, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

  • Compatibility

    Targets WordPress 7.0+ plugins (PHP 7.4.0+). Requires a runnable environment (wp-env, docker-based dev stack, or equivalent) for runtime mode; static mode runs entirely from the plugin checkout with no env. Filesystem-based agent with bash + node.

    From compatibility in the SKILL.md frontmatter.

Context cost

Wp Abilities Verify loads about 2.2k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 76 tokens; SKILL.md has 998 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~76
When it runs · the whole SKILL.md, loaded when a task matches
~2.2k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~14k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from gambitph/Stackable at commit 5c13d80, republished under its GPL-3.0 licence (© gambitph). 998 words, ~2,224 tokens.

Download SKILL.mdSave it as .claude/skills/wp-abilities-verify/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.
name
wp-abilities-verify
description
Verify a WordPress plugin's Abilities API registrations: enumerate abilities, check that callback behavior matches each annotation's claim (the adversarial readonly-but-writes detection), validate permissions and schemas, and validate audit documents produced by wp-abilities-audit.
compatibility
Targets WordPress 7.0+ plugins (PHP 7.4.0+). Requires a runnable environment (wp-env, docker-based dev stack, or equivalent) for runtime mode; static mode runs entirely from the plugin checkout with no env. Filesystem-based agent with bash + node.

WP Abilities Verify

Verify a WordPress plugin's Abilities API registrations. The centerpiece is the adversarial annotation correctness check: a readonly: true ability that actually writes (via $wpdb->update, update_option, a non-GET delegate, etc.) is a security and UX disaster because agents plan actions on the basis of the annotations they introspect. This skill catches those lies by reading the callback body and comparing what it does against what the annotation claims.

The skill also validates audit docs produced by wp-abilities-audit, checks permission gates and schema hygiene, and optionally executes each ability against a live environment.

When to use

  • After abilities have been registered in a plugin but before a PR lands.
  • As a health-check on an already-shipped plugin (catch regressions where a refactor turned a readonly ability into a writing one).
  • To validate an audit document before handing it to an implementer.

Two modes

  • Static mode — runs from the plugin checkout. No env. Enumerates via source inspection, runs the adversarial correctness check, runs schema and permission lints, and validates audit docs.
  • Runtime mode — requires a running env. Does everything static does PLUS: wp_get_abilities() for authoritative enumeration, executes each ability with curated inputs, confirms permission roundtrip against real users, and runs a twin-invocation heuristic on idempotent: true abilities to flag candidates for review (return-value equality is a signal, not a verdict — core defines idempotent as "no additional effect on the environment").

Both modes produce the same structured report format.

A static-mode PASS means "no obvious-shape violations," not "verified write-free." For high-stakes plugins, run runtime mode before landing — it catches bootstrap-order, permission-roundtrip, and idempotency issues that static can't. See references/annotation-correctness.md for the static blind spots.

Inputs required

  1. Plugin checkout path — working tree to verify.
  2. Mode — static or runtime. Default to static if unspecified.
  3. (Runtime only) Env-up command — read the plugin's AGENTS.md. Common patterns: npm run wp-env start, npx wp-env start, or a composer-based bring-up. Plugin families with their own dev tooling will document their own command. Do NOT assume npm run wp-env works.
  4. (Optional) Audit doc path — enables cross-checks between the audit and the registered abilities, and validates the audit itself.
  5. Report output path — explicit path, typically the user's vault.

Prerequisites

  • wp-project-triage has been run on the plugin.
  • The plugin has at least one registered ability in source. Zero hits on wp_register_ability( → return a clear "no abilities registered" report, not an empty PASS.

Procedure

1. (If audit provided) Validate the audit doc

Read references/audit-schema-validation.md. Validate the audit against the canonical schema owned by wp-abilities-audit. Surface missing required fields, multiple reference_ability: true, and backing: null entries that aren't paired with a surfaced_gaps entry. backing: null alone is WARN (intentional gap output), not FAIL.

2. Enumerate abilities statically

Read references/static-enumeration.md. Find each wp_register_ability( call, extract the name, the annotation block, and the execute-callback location. Use a multi-line tool (rg --multiline --pcre2) — the canonical formatting splits the call across lines. Record each ability's source-file + line + annotations + callback byte range.

3. (Runtime only) Enumerate via REST + wp-cli

Read references/runtime-harness.md. Bring the env up using the command from AGENTS.md, then enumerate via wp_get_abilities() over wp-cli and cross-check against the static inventory. Source-only → FAIL (registration not firing). Runtime-only → WARN (dynamic registration path).

4. Annotation correctness (the adversarial core)

Read references/annotation-correctness.md. Read each callback body and verify it matches the annotation claim:

  • readonly: true → callback must not write to the database, the options table, post / user / term / comment data, the filesystem, cron, or via non-GET HTTP / REST delegates.
  • destructive: false → callback must not delete, refund, void, cancel, or trash.
  • idempotent: true → repeated calls with the same input have no additional effect on the environment (per the idempotent annotation's docblock in class-wp-ability.php). Static catches counter writes and per-call cron schedules; runtime adds a twin-invocation heuristic for visible state changes.

The reference lists common write patterns as a starting set, not a checklist — plugin vocabularies vary, and the agent extends with verbs specific to the plugin under verification.

False positives get suppressed via an inline // verify-ignore: <annotation> -- <reason> comment.

Show full SKILL.md (336 more words)Show less
5. Permission roundtrip

Read references/permission-roundtrip.md. Static: classify each permission_callback against the six shapes (preferred Shape A current_user_can(...); FAIL on Shape B-bad WP_REST_Request patterns or Shape E literal true). Runtime: anon and subscriber denied; admin allowed (unless deliberately public). When an audit was provided, cross-check the registered cap against the audit's declared gate.

6. Schema lints

Read references/schema-lints.md. Six small principles applied to each ability's input_schema: object schemas declare additionalProperties; required fields have descriptions; enums non-empty; no $ref; defaults are statically constant (including (object) array()); reference abilities have no required inputs.

Cross-reference ../wp-abilities-api/references/input-schema-gotchas.md for the four runtime gotchas (defaults not injected on the property-level path, pagination key drift, empty() on string IDs, direct vs indirect invocation strictness).

7. Error-code vocabulary

Cross-reference ../wp-abilities-api/references/error-code-vocabulary.md. Inspect each callback's WP_Error returns; non-vocabulary codes → WARN.

Verification

The run produces a structured markdown report at the user-specified path:

---
Last updated: <YYYY-MM-DD HH:MM>
---

# <Plugin> Abilities Verification — <Static|Runtime> Mode

## Status: <PASS|WARN|FAIL>

## Audit doc validation (if provided)

## Static inventory

## Annotation correctness
| Ability | Claim | Result | Evidence |
|---|---|---|---|

## Permission gates

## Schema lints

## Error-code vocabulary

Every ability is OK, WARN, or FAIL. A single FAIL → top-line FAIL; WARNs without FAILs → WARN; otherwise PASS.

Failure modes / debugging

  • Env not reachable (runtime) — env-up failed or Docker isn't running. Re-run wp-project-triage, then fix the env. Don't fall back silently to static without noting it in the report.
  • No abilities in source — return a clear "nothing to verify" report.
  • Audit schema mismatch — point at references/audit-schema-validation.md; don't auto-fix the audit.
  • False positive on readonly-writes — see the // verify-ignore mechanism in references/annotation-correctness.md. Document why each suppression is legitimate.
  • Runtime enumeration smaller than static — registration hook isn't firing. Check init hook timing, activation state, autoloader order.

Escalation

  • Recurring legitimate pattern that trips the adversarial check across multiple plugins → propose adding it to the suppression guidance in annotation-correctness.md. Don't broaden the candidate-pattern list speculatively.
  • Audit-schema validator rejects a legitimate audit → the canonical schema in ../wp-abilities-audit/references/audit-schema.md has evolved. Update references/audit-schema-validation.md to match.

Out of scope

Token-budget measurement is a separate verification axis — an annotation-clean, schema-clean, runtime-passing ability set can still be unshippable if its tools/list form burns through an agent's context budget. That axis is tracked separately. Do not aggregate manual or external measurement into this skill's PASS / FAIL verdict.

© gambitph, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 6 other files (references) in .cursor/skills/wp-abilities-verify of gambitph/Stackable.

  • SKILL.md
  • references/annotation-correctness.md
  • references/audit-schema-validation.md
  • references/permission-roundtrip.md
  • references/runtime-harness.md
  • references/schema-lints.md
  • references/static-enumeration.md

Open the folder on GitHubat commit 5c13d80

Used in 1 other repository

We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in gambitph/Stackable, which our catalogue first saw on October 7, 2026.

Compare with similar skills

Wp Abilities Verify next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Wp Abilities Verify compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Wp Abilities Verify this skillgambitph/Stackable3511 repos~2.2kAutomated safety check: PassGPL-3.0
WooCommerce Code Reviewwoocommerce/woocommerce11k3 repos~1.1kAutomated safety check: PassCustom licence
Wp Interactivity APIAutomattic/agent-skills2112 repos~1.5kAutomated safety check: PassNone
WooCommerce Dev Cyclewoocommerce/woocommerce11k3 repos~431Automated safety check: PassCustom licence
Debug Php Wasm Main ModuleWordPress/wordpress-playground2k—~3.1kAutomated safety check: PassGPL-2.0
Blueprintbonny/WordPress-Simple-History3171 repos~4kAutomated safety check: PassNone

Similar skills

  • WooCommerce Code Review

    woocommerce/woocommerce

    Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.

    11k GitHub starsUsed in 3 repos~1.1k tokens
    DevelopmentAuto-check passed
  • Wp Interactivity API

    Automattic/agent-skills

    A skill your agent uses when building or debugging WordPress Interactivity API features (data-wp- directives, @wordpress/interactivity store/state/actions, block viewScriptModule integration…

    211 GitHub starsUsed in 2 repos~1.5k tokens
    DevelopmentAuto-check passed
  • WooCommerce Dev Cycle

    woocommerce/woocommerce

    Workflow for WooCommerce development: run PHP and JavaScript tests, lint and fix code style on the current branch, and follow guides for i18n and markdown.

    11k GitHub starsUsed in 3 repos~431 tokens
    DevelopmentAuto-check passed
  • Debug Php Wasm Main Module

    WordPress/wordpress-playground

    Debug PHP.wasm main module crashes including Asyncify errors (unreachable, memory access out of bounds), JSPI errors (SuspendError, trying to suspend JS frames), WASM memory growth bugs, and runtime…

    2k GitHub stars~3.1k tokensUpdated yesterday
    DevelopmentAuto-check passed
  • Blueprint

    bonny/WordPress-Simple-History

    A skill your agent uses when the deliverable is WordPress Playground Blueprint JSON or a Blueprint bundle, including creating, editing, reviewing, validating schema keys, choosing steps/resources…

    317 GitHub starsUsed in 1 repo~4k tokens
    DevelopmentAuto-check passed
  • Code Style

    Automattic/wordpress-activitypub

    PHP coding standards and WordPress patterns for ActivityPub plugin.

    582 GitHub stars~2.2k tokensUpdated yesterday
    DevelopmentAuto-check passed

More from gambitph/Stackable

All 18 skills in this repo
  • Wp Block Development

    gambitph/Stackable

    A skill your agent uses when developing WordPress (Gutenberg) blocks: block.json metadata, registerblocktype(frommetadata), attributes/serialization, supports, dynamic rendering…

    351 GitHub starsUsed in 3 repos~1.6k tokens
    Auto-check passed
  • Wp Block Themes

    gambitph/Stackable

    A skill your agent uses when developing WordPress block themes: theme.json (global settings/styles), templates and template parts, patterns, style variations, and Site Editor troubleshooting (style…

    351 GitHub starsUsed in 3 repos~985 tokens
    Auto-check passed
  • Wp Performance

    gambitph/Stackable

    A skill your agent uses when investigating or improving WordPress performance (backend-only agent): profiling and measurement (WP-CLI profile/doctor, Server-Timing, Query Monitor via REST headers)…

    351 GitHub starsUsed in 3 repos~1.5k tokens
    Auto-check passed
  • Wp Plugin Development

    gambitph/Stackable

    A skill your agent uses when developing WordPress plugins: architecture and hooks, activation/deactivation/uninstall, admin UI and Settings API, data storage, cron/tasks, security…

    351 GitHub starsUsed in 3 repos~999 tokens
    Auto-check passed
  • Wp Project Triage

    gambitph/Stackable

    A skill your agent uses when you need a deterministic inspection of a WordPress repository (plugin/theme/block theme/WP core/Gutenberg/full site) including tooling/tests/version hints, and a…

    351 GitHub starsUsed in 3 repos~371 tokens
    Auto-check passed
  • A skill your agent uses when reviewing WordPress plugins for GPL compliance, checking license headers or compatibility, evaluating upsell/freemium/trialware patterns, validating plugin naming or…

    351 GitHub starsUsed in 1 repo~1.6k tokens
    Auto-check passed

Works with

Categories

Questions about Wp Abilities Verify

What does Wp Abilities Verify do?

Verify a WordPress plugin's Abilities API registrations: enumerate abilities, check that callback behavior matches each annotation's claim (the adversarial readonly-but-writes detection), validate…. Wp Abilities Verify is an agent skill from gambitph/Stackable. Verify a WordPress plugin's Abilities API registrations: enumerate abilities, check that callback behavior matches each annotation's claim (the adversarial readonly-but-writes detection), validate permissions and schemas, and validate audit documents produced by wp-abilities-audit.

When should I use Wp Abilities Verify?

Wp Abilities Verify fits situations like: development work in your project.

How do I install Wp Abilities Verify in Claude Code?

Run `npx skills add gambitph/Stackable --skill wp-abilities-verify -a claude-code`. Or copy the skill folder (.cursor/skills/wp-abilities-verify in gambitph/Stackable) into .claude/skills/wp-abilities-verify in your project. Claude Code loads it when a task matches its description.

How do I install Wp Abilities Verify in Codex?

Run `npx skills add gambitph/Stackable --skill wp-abilities-verify -a codex`. Or copy the skill folder (.cursor/skills/wp-abilities-verify in gambitph/Stackable) into .agents/skills/wp-abilities-verify in your project. Codex loads it when a task matches its description.

Can I use Wp Abilities Verify in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gambitph/Stackable --skill wp-abilities-verify -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wp-abilities-verify, .gemini/skills/wp-abilities-verify, .github/skills/wp-abilities-verify and .opencode/skills/wp-abilities-verify in your project.

What does Wp Abilities Verify need to run?

Going by SKILL.md and its folder, Wp Abilities Verify needs the command-line tools its instructions call (npm and npx). Our summary lists: Node.js; Docker. Compatibility (from SKILL.md): Targets WordPress 7.0+ plugins (PHP 7.4.0+). Requires a runnable environment (wp-env, docker-based dev stack, or equivalent) for runtime mode; static mode runs entirely from the plugin checkout with no env. Filesystem-based agent with bash + node..

Does Wp Abilities Verify access the network?

SKILL.md contains no URLs. Its commands use npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Wp Abilities Verify safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Wp Abilities Verify use?

Wp Abilities Verify is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Wp Abilities Verify use?

About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.

What are the alternatives to Wp Abilities Verify?

Skills that share tags, products or a category with Wp Abilities Verify: WooCommerce Code Review (woocommerce/woocommerce, 11k stars), Wp Interactivity API (Automattic/agent-skills, 211 stars), WooCommerce Dev Cycle (woocommerce/woocommerce, 11k stars) and Debug Php Wasm Main Module (WordPress/wordpress-playground, 2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Wp Abilities Verify?

gambitph (a GitHub organization) maintains it in gambitph/Stackable, which has 351 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 7, 2026.

Source: gambitph/Stackable on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.