WooCommerce Code Review
woocommerce/woocommerce
Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.
Verify a WordPress plugin's Abilities API registrations: enumerate abilities, check that callback behavior matches each annotation's claim (the adversarial readonly-but-writes detection), validate…
$ npx skills add gambitph/Stackable --skill wp-abilities-verify -a claude-codeProject install by default; add -g for ~/.claude/skills/.
$ gh skill install gambitph/Stackable wp-abilities-verify --agent claude-codeProject scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).
$ git clone --depth 1 https://github.com/gambitph/Stackable.git skills-src && mkdir -p .claude/skills && cp -r skills-src/.cursor/skills/wp-abilities-verify .claude/skills/wp-abilities-verify && rm -rf skills-srcUse ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.
Claude Code skills documentation · loads skills from .claude/skills/
Install the "wp-abilities-verify" agent skill from https://github.com/gambitph/Stackable/tree/develop/.cursor/skills/wp-abilities-verify into .claude/skills/wp-abilities-verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-abilities-verify", then confirm the skill loads.Claude Code copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$skill-installer install https://github.com/gambitph/Stackable/tree/develop/.cursor/skills/wp-abilities-verifyType this inside Codex. $skill-installer <name> installs a curated skill from openai/skills. The installer writes to $CODEX_HOME/skills (default ~/.codex/skills). Restart Codex if the skill does not show up.
$ npx skills add gambitph/Stackable --skill wp-abilities-verify -a codexProject install goes to .agents/skills/; add -g for ~/.codex/skills/.
$ gh skill install gambitph/Stackable wp-abilities-verify --agent codexProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gambitph/Stackable.git skills-src && mkdir -p .agents/skills && cp -r skills-src/.cursor/skills/wp-abilities-verify .agents/skills/wp-abilities-verify && rm -rf skills-srcUse ~/.agents/skills/ instead of .agents/skills for a personal install.
Codex skills documentation · loads skills from .agents/skills/
Install the "wp-abilities-verify" agent skill from https://github.com/gambitph/Stackable/tree/develop/.cursor/skills/wp-abilities-verify into .agents/skills/wp-abilities-verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-abilities-verify", then confirm the skill loads.Codex copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add gambitph/Stackable --skill wp-abilities-verify -a cursorProject install goes to .agents/skills/; add -g for ~/.cursor/skills/.
$ gh skill install gambitph/Stackable wp-abilities-verify --agent cursorProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gambitph/Stackable.git skills-src && mkdir -p .cursor/skills && cp -r skills-src/.cursor/skills/wp-abilities-verify .cursor/skills/wp-abilities-verify && rm -rf skills-srcUse ~/.cursor/skills/ instead of .cursor/skills for a personal install.
Cursor skills documentation · loads skills from .cursor/skills/, .agents/skills/, .claude/skills/, .codex/skills/
Install the "wp-abilities-verify" agent skill from https://github.com/gambitph/Stackable/tree/develop/.cursor/skills/wp-abilities-verify into .cursor/skills/wp-abilities-verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-abilities-verify", then confirm the skill loads.Cursor copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gemini skills install https://github.com/gambitph/Stackable.git --path .cursor/skills/wp-abilities-verify--scope user (default) or --scope workspace; --path is the subfolder of the repo that holds the skill; --consent skips the security confirmation prompt.
$ npx skills add gambitph/Stackable --skill wp-abilities-verify -a gemini-cliProject install goes to .agents/skills/; add -g for ~/.gemini/skills/.
$ gh skill install gambitph/Stackable wp-abilities-verify --agent gemini-cliProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gambitph/Stackable.git skills-src && mkdir -p .gemini/skills && cp -r skills-src/.cursor/skills/wp-abilities-verify .gemini/skills/wp-abilities-verify && rm -rf skills-srcUse ~/.gemini/skills/ instead of .gemini/skills for a personal install, then run /skills reload.
Gemini CLI skills documentation · loads skills from .gemini/skills/, .agents/skills/
Install the "wp-abilities-verify" agent skill from https://github.com/gambitph/Stackable/tree/develop/.cursor/skills/wp-abilities-verify into .gemini/skills/wp-abilities-verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-abilities-verify", then confirm the skill loads.Gemini CLI copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ gh skill install gambitph/Stackable wp-abilities-verifyInstalls for Copilot at project scope by default; add --scope user for a personal install. Preview a skill first with gh skill preview. Needs GitHub CLI 2.90.0 or later (public preview).
$ npx skills add gambitph/Stackable --skill wp-abilities-verify -a github-copilotProject install goes to .agents/skills/; add -g for ~/.copilot/skills/.
$ git clone --depth 1 https://github.com/gambitph/Stackable.git skills-src && mkdir -p .github/skills && cp -r skills-src/.cursor/skills/wp-abilities-verify .github/skills/wp-abilities-verify && rm -rf skills-srcUse ~/.copilot/skills/ instead of .github/skills for a personal install. Commit .github/skills so cloud agent and code review can use it.
GitHub Copilot skills documentation · loads skills from .github/skills/, .claude/skills/, .agents/skills/
Install the "wp-abilities-verify" agent skill from https://github.com/gambitph/Stackable/tree/develop/.cursor/skills/wp-abilities-verify into .github/skills/wp-abilities-verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-abilities-verify", then confirm the skill loads.GitHub Copilot copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
$ npx skills add gambitph/Stackable --skill wp-abilities-verify -a opencodeOpenCode documents no install command of its own. Project install goes to .agents/skills/; add -g for ~/.config/opencode/skills/.
$ gh skill install gambitph/Stackable wp-abilities-verify --agent opencodeProject scope by default (.agents/skills/); add --scope user for a personal install.
$ git clone --depth 1 https://github.com/gambitph/Stackable.git skills-src && mkdir -p .opencode/skills && cp -r skills-src/.cursor/skills/wp-abilities-verify .opencode/skills/wp-abilities-verify && rm -rf skills-srcUse ~/.config/opencode/skills/ instead of .opencode/skills for a personal install.
OpenCode skills documentation · loads skills from .opencode/skills/, .claude/skills/, .agents/skills/
Install the "wp-abilities-verify" agent skill from https://github.com/gambitph/Stackable/tree/develop/.cursor/skills/wp-abilities-verify into .opencode/skills/wp-abilities-verify/ in this project. Copy the whole folder (SKILL.md and every file beside it), keep the folder name "wp-abilities-verify", then confirm the skill loads.OpenCode copies the folder itself, the same result as the manual copy. Check what it changed before you commit it.
wp-abilities-verifyVerify a WordPress plugin's Abilities API registrations: enumerate abilities, check that callback behavior matches each annotation's claim (the adversarial readonly-but-writes detection), validate…
Wp Abilities Verify is an agent skill from gambitph/Stackable. Verify a WordPress plugin's Abilities API registrations: enumerate abilities, check that callback behavior matches each annotation's claim (the adversarial readonly-but-writes detection), validate permissions and schemas, and validate audit documents produced by wp-abilities-audit.
Its SKILL.md is about 2.2k tokens, which your agent loads only when the skill is triggered. The skill folder holds 7 other files, including reference files (for example `references/annotation-correctness.md`, `references/audit-schema-validation.md` and `references/permission-roundtrip.md`). Compatibility notes: Targets WordPress 7.0+ plugins (PHP 7.4.0+). Requires a runnable environment (wp-env, docker-based dev stack, or equivalent) for runtime mode; static mode…
It sits in Development. It works with WordPress. The repository describes itself as: Page Builder Blocks for WordPress. An Amazing Block Library for the new WordPress Block Editor (Gutenberg). The licence is GPL-3.0.
7 steps, taken from the step headings in SKILL.md.
Read from SKILL.md and the folder at commit 5c13d80. It shows what the files ask for, not the result of running them.
Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.
From allowed-tools in the SKILL.md frontmatter.
Shell commands in SKILL.md call:
npmnpxFrom the folder's file list and the shell code blocks in SKILL.md.
No URLs in SKILL.md. Its commands use npm and npx, which can reach the network depending on how they are called.
From URLs in SKILL.md, links to its own repository left out.
Names no API keys, tokens, secrets or passwords.
From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.
Targets WordPress 7.0+ plugins (PHP 7.4.0+). Requires a runnable environment (wp-env, docker-based dev stack, or equivalent) for runtime mode; static mode runs entirely from the plugin checkout with no env. Filesystem-based agent with bash + node.
From compatibility in the SKILL.md frontmatter.
Wp Abilities Verify loads about 2.2k tokens when it runs, and up to ~14k if it reads all its reference files. Until then it costs about 76 tokens; SKILL.md has 998 words of instructions outside code blocks.
Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.
The automated check found no risky patterns in SKILL.md.
Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.
The full file from gambitph/Stackable at commit 5c13d80, republished under its GPL-3.0 licence (© gambitph). 998 words, ~2,224 tokens.
.claude/skills/wp-abilities-verify/SKILL.md (or your agent's skills folder). This skill also uses 6 other files; get the full folder from GitHub.Verify a WordPress plugin's Abilities API registrations. The
centerpiece is the adversarial annotation correctness check: a
readonly: true ability that actually writes (via $wpdb->update,
update_option, a non-GET delegate, etc.) is a security and UX
disaster because agents plan actions on the basis of the annotations
they introspect. This skill catches those lies by reading the callback
body and comparing what it does against what the annotation claims.
The skill also validates audit docs produced by wp-abilities-audit,
checks permission gates and schema hygiene, and optionally executes
each ability against a live environment.
wp_get_abilities() for authoritative enumeration,
executes each ability with curated inputs, confirms permission
roundtrip against real users, and runs a twin-invocation heuristic
on idempotent: true abilities to flag candidates for review
(return-value equality is a signal, not a verdict — core defines
idempotent as "no additional effect on the environment").Both modes produce the same structured report format.
A static-mode PASS means "no obvious-shape violations," not "verified
write-free." For high-stakes plugins, run runtime mode before landing
— it catches bootstrap-order, permission-roundtrip, and idempotency
issues that static can't. See references/annotation-correctness.md
for the static blind spots.
static or runtime. Default to static if unspecified.AGENTS.md.
Common patterns: npm run wp-env start, npx wp-env start, or a
composer-based bring-up. Plugin families with their own dev tooling
will document their own command. Do NOT assume npm run wp-env
works.wp-project-triage has been run on the plugin.wp_register_ability( → return a clear "no abilities registered"
report, not an empty PASS.Read references/audit-schema-validation.md. Validate the audit
against the canonical schema owned by wp-abilities-audit. Surface
missing required fields, multiple reference_ability: true, and
backing: null entries that aren't paired with a surfaced_gaps
entry. backing: null alone is WARN (intentional gap output), not
FAIL.
Read references/static-enumeration.md. Find each
wp_register_ability( call, extract the name, the annotation block,
and the execute-callback location. Use a multi-line tool (rg --multiline --pcre2) — the canonical formatting splits the call
across lines. Record each ability's source-file + line + annotations +
callback byte range.
Read references/runtime-harness.md. Bring the env up using the
command from AGENTS.md, then enumerate via wp_get_abilities() over
wp-cli and cross-check against the static inventory. Source-only →
FAIL (registration not firing). Runtime-only → WARN (dynamic
registration path).
Read references/annotation-correctness.md. Read each callback body
and verify it matches the annotation claim:
readonly: true → callback must not write to the database, the
options table, post / user / term / comment data, the filesystem,
cron, or via non-GET HTTP / REST delegates.destructive: false → callback must not delete, refund, void,
cancel, or trash.idempotent: true → repeated calls with the same input have no
additional effect on the environment (per the idempotent
annotation's docblock in class-wp-ability.php). Static catches
counter writes and per-call cron schedules; runtime adds a
twin-invocation heuristic for visible state changes.The reference lists common write patterns as a starting set, not a checklist — plugin vocabularies vary, and the agent extends with verbs specific to the plugin under verification.
False positives get suppressed via an inline // verify-ignore: <annotation> -- <reason> comment.
Read references/permission-roundtrip.md. Static: classify each
permission_callback against the six shapes (preferred Shape A
current_user_can(...); FAIL on Shape B-bad WP_REST_Request
patterns or Shape E literal true). Runtime: anon and subscriber
denied; admin allowed (unless deliberately public). When an audit was
provided, cross-check the registered cap against the audit's declared
gate.
Read references/schema-lints.md. Six small principles applied to
each ability's input_schema: object schemas declare
additionalProperties; required fields have descriptions; enums
non-empty; no $ref; defaults are statically constant (including
(object) array()); reference abilities have no required inputs.
Cross-reference ../wp-abilities-api/references/input-schema-gotchas.md
for the four runtime gotchas (defaults not injected on the
property-level path, pagination key drift, empty() on string IDs,
direct vs indirect invocation strictness).
Cross-reference ../wp-abilities-api/references/error-code-vocabulary.md.
Inspect each callback's WP_Error returns; non-vocabulary codes →
WARN.
The run produces a structured markdown report at the user-specified path:
---
Last updated: <YYYY-MM-DD HH:MM>
---
# <Plugin> Abilities Verification — <Static|Runtime> Mode
## Status: <PASS|WARN|FAIL>
## Audit doc validation (if provided)
## Static inventory
## Annotation correctness
| Ability | Claim | Result | Evidence |
|---|---|---|---|
## Permission gates
## Schema lints
## Error-code vocabularyEvery ability is OK, WARN, or FAIL. A single FAIL → top-line FAIL; WARNs without FAILs → WARN; otherwise PASS.
wp-project-triage, then fix the env. Don't fall
back silently to static without noting it in the report.references/audit-schema-validation.md; don't auto-fix the audit.// verify-ignore
mechanism in references/annotation-correctness.md. Document why
each suppression is legitimate.annotation-correctness.md. Don't broaden the candidate-pattern
list speculatively.../wp-abilities-audit/references/audit-schema.md has
evolved. Update references/audit-schema-validation.md to match.Token-budget measurement is a separate verification axis — an
annotation-clean, schema-clean, runtime-passing ability set can still
be unshippable if its tools/list form burns through an agent's
context budget. That axis is tracked separately. Do not aggregate
manual or external measurement into this skill's PASS / FAIL verdict.
© gambitph, GPL-3.0. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file
SKILL.md and 6 other files (references) in .cursor/skills/wp-abilities-verify of gambitph/Stackable.
Open the folder on GitHubat commit 5c13d80
We found 1 copy of this SKILL.md (exact, near-identical or edited) in other folders, from 1 other GitHub owner. This page covers the copy in gambitph/Stackable, which our catalogue first saw on October 7, 2026.
Wp Abilities Verify next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.
| Skill | Stars | Used in | Tokens | Auto-check | Licence | Repo updated |
|---|---|---|---|---|---|---|
| Wp Abilities Verify this skillgambitph/Stackable | 351 | 1 repos | ~2.2k | Automated safety check: Pass | GPL-3.0 | |
| WooCommerce Code Reviewwoocommerce/woocommerce | 11k | 3 repos | ~1.1k | Automated safety check: Pass | Custom licence | |
| Wp Interactivity APIAutomattic/agent-skills | 211 | 2 repos | ~1.5k | Automated safety check: Pass | None | |
| WooCommerce Dev Cyclewoocommerce/woocommerce | 11k | 3 repos | ~431 | Automated safety check: Pass | Custom licence | |
| Debug Php Wasm Main ModuleWordPress/wordpress-playground | 2k | — | ~3.1k | Automated safety check: Pass | GPL-2.0 | |
| Blueprintbonny/WordPress-Simple-History | 317 | 1 repos | ~4k | Automated safety check: Pass | None |
woocommerce/woocommerce
Reviews WooCommerce code changes against the project's standards, flagging backend PHP architecture, naming, documentation, data integrity and testing violations.
Automattic/agent-skills
A skill your agent uses when building or debugging WordPress Interactivity API features (data-wp- directives, @wordpress/interactivity store/state/actions, block viewScriptModule integration…
woocommerce/woocommerce
Workflow for WooCommerce development: run PHP and JavaScript tests, lint and fix code style on the current branch, and follow guides for i18n and markdown.
WordPress/wordpress-playground
Debug PHP.wasm main module crashes including Asyncify errors (unreachable, memory access out of bounds), JSPI errors (SuspendError, trying to suspend JS frames), WASM memory growth bugs, and runtime…
bonny/WordPress-Simple-History
A skill your agent uses when the deliverable is WordPress Playground Blueprint JSON or a Blueprint bundle, including creating, editing, reviewing, validating schema keys, choosing steps/resources…
Automattic/wordpress-activitypub
PHP coding standards and WordPress patterns for ActivityPub plugin.
gambitph/Stackable
A skill your agent uses when developing WordPress (Gutenberg) blocks: block.json metadata, registerblocktype(frommetadata), attributes/serialization, supports, dynamic rendering…
gambitph/Stackable
A skill your agent uses when developing WordPress block themes: theme.json (global settings/styles), templates and template parts, patterns, style variations, and Site Editor troubleshooting (style…
gambitph/Stackable
A skill your agent uses when investigating or improving WordPress performance (backend-only agent): profiling and measurement (WP-CLI profile/doctor, Server-Timing, Query Monitor via REST headers)…
gambitph/Stackable
A skill your agent uses when developing WordPress plugins: architecture and hooks, activation/deactivation/uninstall, admin UI and Settings API, data storage, cron/tasks, security…
gambitph/Stackable
A skill your agent uses when you need a deterministic inspection of a WordPress repository (plugin/theme/block theme/WP core/Gutenberg/full site) including tooling/tests/version hints, and a…
gambitph/Stackable
A skill your agent uses when reviewing WordPress plugins for GPL compliance, checking license headers or compatibility, evaluating upsell/freemium/trialware patterns, validating plugin naming or…
Works with
Categories
Verify a WordPress plugin's Abilities API registrations: enumerate abilities, check that callback behavior matches each annotation's claim (the adversarial readonly-but-writes detection), validate…. Wp Abilities Verify is an agent skill from gambitph/Stackable. Verify a WordPress plugin's Abilities API registrations: enumerate abilities, check that callback behavior matches each annotation's claim (the adversarial readonly-but-writes detection), validate permissions and schemas, and validate audit documents produced by wp-abilities-audit.
Wp Abilities Verify fits situations like: development work in your project.
Run `npx skills add gambitph/Stackable --skill wp-abilities-verify -a claude-code`. Or copy the skill folder (.cursor/skills/wp-abilities-verify in gambitph/Stackable) into .claude/skills/wp-abilities-verify in your project. Claude Code loads it when a task matches its description.
Run `npx skills add gambitph/Stackable --skill wp-abilities-verify -a codex`. Or copy the skill folder (.cursor/skills/wp-abilities-verify in gambitph/Stackable) into .agents/skills/wp-abilities-verify in your project. Codex loads it when a task matches its description.
Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add gambitph/Stackable --skill wp-abilities-verify -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wp-abilities-verify, .gemini/skills/wp-abilities-verify, .github/skills/wp-abilities-verify and .opencode/skills/wp-abilities-verify in your project.
Going by SKILL.md and its folder, Wp Abilities Verify needs the command-line tools its instructions call (npm and npx). Our summary lists: Node.js; Docker. Compatibility (from SKILL.md): Targets WordPress 7.0+ plugins (PHP 7.4.0+). Requires a runnable environment (wp-env, docker-based dev stack, or equivalent) for runtime mode; static mode runs entirely from the plugin checkout with no env. Filesystem-based agent with bash + node..
SKILL.md contains no URLs. Its commands use npm and npx, which can reach the network depending on how they are called. This is read from the text; nothing was executed.
Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.
Wp Abilities Verify is published under the GPL-3.0 licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.
About 2.2k tokens (SKILL.md is roughly 8.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 12k tokens, read only when the agent opens those files.
Skills that share tags, products or a category with Wp Abilities Verify: WooCommerce Code Review (woocommerce/woocommerce, 11k stars), Wp Interactivity API (Automattic/agent-skills, 211 stars), WooCommerce Dev Cycle (woocommerce/woocommerce, 11k stars) and Debug Php Wasm Main Module (WordPress/wordpress-playground, 2k stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.
gambitph (a GitHub organization) maintains it in gambitph/Stackable, which has 351 GitHub stars. The repository holds 18 skills in this directory. The repository was last updated on October 7, 2026.
Source: gambitph/Stackable on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.