Agent skill

Wp CI CD And Release Engineering

by jorgerosal in jorgerosal/wordpress-skills

WordPress CI/CD and release engineering review guidance. An agent skill from jorgerosal/wordpress-skills.

MITAuto-check passedDevOps & Cloud

Install Wp CI CD And Release Engineering

skills CLI
$ npx skills add jorgerosal/wordpress-skills --skill wp-ci-cd-and-release-engineering -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jorgerosal/wordpress-skills wp-ci-cd-and-release-engineering --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jorgerosal/wordpress-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-skills/wp-ci-cd-and-release-engineering .claude/skills/wp-ci-cd-and-release-engineering && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
wp-ci-cd-and-release-engineering
GitHub stars
103
Token cost
~1.7k tokens
SKILL.md length
690 words
Files
4 (incl. references)
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

WordPress CI/CD and release engineering review guidance. An agent skill from jorgerosal/wordpress-skills.

  • Works in 6 steps: Identify the delivery surface → Check artifact boundaries first → Review environment and secret handling → …
  • Reviewing GitHub Actions
  • SKILL.md covers Overview, When to Use, Code Review Workflow and File-Type Specific Checks, plus 3 more sections
  • Calls rg, npm and rsync; needs GITHUB_TOKEN and SVN_PASSWORD

What it does

Wp CI CD And Release Engineering is an agent skill from jorgerosal/wordpress-skills. WordPress CI/CD and release engineering review guidance. Use when reviewing GitHub Actions, deployment pipelines, Composer/npm build steps, plugin/theme packaging, release automation, secrets handling, SVN deploy flows for WordPress.org, staged rollouts, rollback plans, or when user mentions CI, CD, release pipeline, GitHub Actions, deployment workflow, build artifact, plugin zip, or release engineering. Helps review build reproducibility, packaging correctness, secret boundaries, deployment safety, rollback…

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/github-actions-and-gating.md`, `references/packaging-and-artifacts.md` and `references/wordpress-org-and-rollbacks.md`).

It sits in DevOps & Cloud, covering CI/CD. It works with WordPress, GitHub Actions and npm. The repository describes itself as: ✅ 🎉 Claude skills and Codex skills for Wordpress development❗️. The licence is MIT.

When your agent uses it

  • Reviewing GitHub Actions
  • Deployment pipelines
  • Composer/npm build steps
  • Plugin/theme packaging

Example prompts

  • “/wp-ci-cd-and-release-engineering”

Requirements

  • Node.js
  • A credential in GITHUB_TOKEN
  • A credential in SSH_PRIVATE_KEY

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Identify the delivery surface
  2. Check artifact boundaries first
  3. Review environment and secret handling
  4. Review validation and reproducibility
  5. Review rollback and release operations
  6. Classify findings

What it can do on your machine

Read from SKILL.md and the folder at commit 8c96442. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg
    • npm
    • rsync
    • scp
    • ssh
    • composer

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md. Its commands use npm, rsync, scp and ssh, which can reach the network depending on how they are called.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names these keys or tokens, usually read from environment variables:

    • GITHUB_TOKEN
    • SVN_PASSWORD
    • SSH_PRIVATE_KEY

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Wp CI CD And Release Engineering loads about 1.7k tokens when it runs, and up to ~3.4k if it reads all its reference files. Until then it costs about 150 tokens; SKILL.md has 690 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~150
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~3.4k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jorgerosal/wordpress-skills at commit 8c96442, republished under its MIT licence (© jorgerosal). 690 words, ~1,727 tokens.

Download SKILL.mdSave it as .claude/skills/wp-ci-cd-and-release-engineering/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
wp-ci-cd-and-release-engineering
description
WordPress CI/CD and release engineering review guidance. Use when reviewing GitHub Actions, deployment pipelines, Composer/npm build steps, plugin/theme packaging, release automation, secrets handling, SVN deploy flows for WordPress.org, staged rollouts, rollback plans, or when user mentions CI, CD, release pipeline, GitHub Actions, deployment workflow, build artifact, plugin zip, or release engineering. Helps review build reproducibility, packaging correctness, secret boundaries, deployment safety, rollback readiness, and WordPress-specific release pitfalls.

WordPress CI/CD and Release Engineering Skill

Overview

Systematic review guidance for WordPress delivery pipelines. Core principle: releases should be reproducible, scoped to the real artifact being shipped, and explicit about which environment, credentials, and validation gates are involved before anything reaches users or production infrastructure.

When to Use

Use when:

  • Reviewing GitHub Actions or other CI/CD workflows for WordPress plugins, themes, or headless projects
  • Auditing packaging/release scripts and deploy jobs
  • Checking WordPress.org SVN deploy flows, artifact generation, or release tagging
  • Reviewing environment-secret handling for deploys, build steps, or preview environments
  • Planning staged rollout, rollback, or pre-release verification workflows

Don't use for:

  • Pure code-level plugin architecture with no pipeline/release concerns (use wp-plugin-development)
  • Static analysis setup only (use wp-phpstan-review)
  • Operational runtime maintenance tasks centered on WP-CLI (use wp-wpcli-and-ops)
  • Headless cache/revalidation architecture without deployment pipeline focus (use wp-headless-and-wpgraphql)

Code Review Workflow

  1. Identify the delivery surface

    • GitHub Actions / CI config files
    • release scripts, shell helpers, Composer/npm build commands
    • packaging steps that create plugin/theme zips
    • deployment docs, release checklists, or WordPress.org publish automation
  2. Check artifact boundaries first

    • What exact files are shipped to production or to WordPress.org?
    • Is the deploy artifact built once and promoted, or rebuilt differently per environment?
    • Are dev-only files, tests, source maps, secrets, or local config leaking into release artifacts?
  3. Review environment and secret handling

    • Are secrets limited to the jobs that actually need them?
    • Are production deploys gated by branch/tag/environment protections?
    • Do preview/staging jobs use separate credentials and destinations?
  4. Review validation and reproducibility

    • Are lint/tests/build steps executed before packaging or deploy?
    • Are dependency installs pinned/locked enough for reproducible releases?
    • Is the generated artifact validated rather than assuming the repo tree equals the shipped code?
  5. Review rollback and release operations

    • Is there a documented rollback path?
    • Can operators identify which version/artifact is live?
    • Are releases idempotent or likely to partially deploy on rerun?
  6. Classify findings

    • CRITICAL: production deploy without protections, secret exposure, artifact mismatch, unreviewed direct-to-prod release, or non-reproducible rebuilds that can ship different code from what passed CI
    • WARNING: weak gating, missing artifact validation, fragile tag/version sync, no rollback notes, deploy steps coupled to local assumptions
    • INFO: could improve caching, matrix strategy, changelog automation, or release observability

File-Type Specific Checks

GitHub Actions / CI Workflows
  • CRITICAL: deploy job runs on every push to an unprotected branch
  • CRITICAL: secrets echoed, written to artifacts, or exposed to unnecessary jobs
  • WARNING: build/test/package/deploy concerns collapsed into one opaque job
  • WARNING: workflow uses floating tools/actions carelessly on security-sensitive paths
  • INFO: could split verification, packaging, and release into clearer stages
Show full SKILL.md (271 more words)Show less
Packaging and Build Scripts
  • CRITICAL: release zip built from a dirty working tree or from files different from the reviewed commit
  • WARNING: node_modules, tests, screenshots, or local config included unintentionally
  • WARNING: Composer/npm install mode differs between CI validation and release packaging in a way that changes the artifact
  • INFO: could add explicit artifact inspection or checksum reporting
WordPress.org / SVN Release Flows
  • CRITICAL: tag and stable-tag drift can publish the wrong version
  • WARNING: deploy script assumes local SVN state or manual copy steps without verification
  • WARNING: readme/version metadata not validated before publish
  • INFO: could document dry-run or preflight checks before SVN push
Environment Promotion and Rollback
  • CRITICAL: same credentials or target used for staging and production without clear guardrails
  • WARNING: no rollback script/runbook or no artifact retention
  • WARNING: production health verification absent after deploy
  • INFO: could surface release IDs, git SHAs, or artifact names in notifications/logs

Search Patterns for Quick Detection (RELEASE-21)

Use these rg commands to locate pipeline and release logic quickly.

Workflow Discovery
bash
rg -n "name:|on:|jobs:" .github/workflows -g '*.yml'
rg -n "deploy|release|publish|svn|wp.org|artifact|zip" . -g '*.{yml,yaml,sh,js,ts,json,md}'
Secret and Environment Risk
bash
rg -n "secrets\.|GITHUB_TOKEN|SVN_PASSWORD|SSH_PRIVATE_KEY|rsync|scp|ssh " . -g '*.{yml,yaml,sh,js,ts,md}'
rg -n "environment:|production|staging|preview|workflow_dispatch|tags:" .github/workflows -g '*.yml'
Packaging and Versioning
bash
rg -n "zip |tar |composer install|npm ci|npm run build|svn cp|svn commit|Stable tag|Version:" . -g '*.{yml,yaml,sh,php,txt,md,json}'
rg -n "readme.txt|plugin.php|style.css|package.json|composer.lock|package-lock.json|pnpm-lock.yaml|yarn.lock" . -g '*'

Reference Files

  • references/github-actions-and-gating.md - workflow structure, deploy protections, environment boundaries, and action hygiene
  • references/packaging-and-artifacts.md - plugin/theme artifact design, build outputs, excludes, and verification
  • references/wordpress-org-and-rollbacks.md - WordPress.org SVN release patterns, stable tag/version sync, rollback thinking, and post-deploy checks

Output Format (RELEASE-23)

For each finding include:

  1. Severity: CRITICAL, WARNING, or INFO
  2. File and line number
  3. CI/CD or release risk summary
  4. Why it matters for shipped artifacts, deploy safety, or operator confidence
  5. Recommended safer pattern

If no issues are found, say so clearly and mention any residual gaps such as missing rollback notes, weak artifact inspection, or unclear environment promotion rules.

© jorgerosal, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in claude-skills/wp-ci-cd-and-release-engineering of jorgerosal/wordpress-skills.

  • SKILL.md
  • references/github-actions-and-gating.md
  • references/packaging-and-artifacts.md
  • references/wordpress-org-and-rollbacks.md

Open the folder on GitHubat commit 8c96442

Compare with similar skills

Wp CI CD And Release Engineering next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Wp CI CD And Release Engineering compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Wp CI CD And Release Engineering this skilljorgerosal/wordpress-skills103—~1.7kAutomated safety check: PassMIT
Repo Hygiene Scan and FixQwenLM/qwen-code28k—~1.7kAutomated safety check: PassApache-2.0
CI Pipeline Synthesizerkajisho5/ffmpeg-skill1.9k1 repos~1.1kAutomated safety check: PassMIT
GitHub Actions Supply Chain Pinningasyncapi/generator1.1k—~1.9kAutomated safety check: PassApache-2.0
Releasechampionswimmer/pi-context-prune245—~907Automated safety check: PassNone
npm Release Via GitHub Actionsjmfederico/pi-web871—~2.9kAutomated safety check: PassMIT

Similar skills

  • Scheduled CI skill that scans a repository for small, certain docs, test and code hygiene issues and fixes them on one branch with a commit per finding.

    28k GitHub stars~1.7k tokensUpdated today
    DevOps & CloudAuto-check passed
  • CI Pipeline Synthesizer

    kajisho5/ffmpeg-skill

    Generate GitHub Actions CI/CD pipeline configurations for automated building and testing of library and package projects.

    1.9k GitHub starsUsed in 1 repo~1.1k tokens
    DevOps & CloudAuto-check passed
  • A skill your agent uses when editing, adding, or reviewing any file under .github/workflows/, or when a CI step installs a CLI tool (npm i -g, npx, pipx, uses: /setup-).

    1.1k GitHub stars~1.9k tokensUpdated today
    DevOps & CloudAuto-check passed
  • Release

    championswimmer/pi-context-prune

    Creates a repository release for this Pi package. An agent skill from championswimmer/pi-context-prune.

    245 GitHub stars~907 tokensUpdated 9 days ago
    DevOps & CloudAuto-check passed
  • A skill your agent uses whenever the user asks for a new npm version, npm release, package release, new release, version bump, publishing to npm, cutting a GitHub release, tagging a release, or…

    871 GitHub stars~2.9k tokensUpdated yesterday
    DevOps & CloudAuto-check passed
  • Publish Release

    molefrog/moi

    Release moi-computer to npm — verify locally, hand off to the gated GitHub Actions workflow, then verify the published package.

    183 GitHub stars~2.5k tokensUpdated today
    DevOps & CloudAuto-check passed

More from jorgerosal/wordpress-skills

All 35 skills in this repo
  • Wp Accessibility Review

    jorgerosal/wordpress-skills

    WordPress accessibility review for themes, blocks, plugins, and admin interfaces.

    103 GitHub stars~1.1k tokensUpdated 4 mo ago
    Auto-check passed
  • Wp Acf And Content Modeling

    jorgerosal/wordpress-skills

    WordPress ACF and content modeling review. An agent skill from jorgerosal/wordpress-skills.

    103 GitHub stars~3.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Wp Admin UI Development

    jorgerosal/wordpress-skills

    WordPress admin UI review and development guidance. An agent skill from jorgerosal/wordpress-skills.

    103 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Wp Headless And Wpgraphql

    jorgerosal/wordpress-skills

    Headless WordPress and WPGraphQL review guidance. An agent skill from jorgerosal/wordpress-skills.

    103 GitHub stars~1.7k tokensUpdated 4 mo ago
    Auto-check passed
  • Wp Migration Upgrade Review

    jorgerosal/wordpress-skills

    WordPress migration and upgrade review. An agent skill from jorgerosal/wordpress-skills.

    103 GitHub stars~1.1k tokensUpdated 4 mo ago
    Auto-check passed
  • Wp Phpstan Review

    jorgerosal/wordpress-skills

    WordPress PHPStan review and setup guidance. An agent skill from jorgerosal/wordpress-skills.

    103 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed

Categories

Questions about Wp CI CD And Release Engineering

What does Wp CI CD And Release Engineering do?

WordPress CI/CD and release engineering review guidance. An agent skill from jorgerosal/wordpress-skills. Wp CI CD And Release Engineering is an agent skill from jorgerosal/wordpress-skills. WordPress CI/CD and release engineering review guidance.

When should I use Wp CI CD And Release Engineering?

Wp CI CD And Release Engineering fits situations like: reviewing GitHub Actions; deployment pipelines; composer/npm build steps; plugin/theme packaging.

How do I install Wp CI CD And Release Engineering in Claude Code?

Run `npx skills add jorgerosal/wordpress-skills --skill wp-ci-cd-and-release-engineering -a claude-code`. Or copy the skill folder (claude-skills/wp-ci-cd-and-release-engineering in jorgerosal/wordpress-skills) into .claude/skills/wp-ci-cd-and-release-engineering in your project. Claude Code loads it when a task matches its description.

How do I install Wp CI CD And Release Engineering in Codex?

Run `npx skills add jorgerosal/wordpress-skills --skill wp-ci-cd-and-release-engineering -a codex`. Or copy the skill folder (claude-skills/wp-ci-cd-and-release-engineering in jorgerosal/wordpress-skills) into .agents/skills/wp-ci-cd-and-release-engineering in your project. Codex loads it when a task matches its description.

Can I use Wp CI CD And Release Engineering in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jorgerosal/wordpress-skills --skill wp-ci-cd-and-release-engineering -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wp-ci-cd-and-release-engineering, .gemini/skills/wp-ci-cd-and-release-engineering, .github/skills/wp-ci-cd-and-release-engineering and .opencode/skills/wp-ci-cd-and-release-engineering in your project.

What does Wp CI CD And Release Engineering need to run?

Going by SKILL.md and its folder, Wp CI CD And Release Engineering needs the command-line tools its instructions call (rg, npm, rsync, scp, ssh and composer) and credentials named GITHUB_TOKEN, SVN_PASSWORD and SSH_PRIVATE_KEY. Our summary lists: Node.js; A credential in GITHUB_TOKEN; A credential in SSH_PRIVATE_KEY.

Does Wp CI CD And Release Engineering access the network?

SKILL.md contains no URLs. Its commands use npm and ssh, which can reach the network depending on how they are called. This is read from the text; nothing was executed.

Is Wp CI CD And Release Engineering safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Wp CI CD And Release Engineering use?

Wp CI CD And Release Engineering is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Wp CI CD And Release Engineering use?

About 1.7k tokens (SKILL.md is roughly 6.9k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 1.6k tokens, read only when the agent opens those files.

What are the alternatives to Wp CI CD And Release Engineering?

Skills that share tags, products or a category with Wp CI CD And Release Engineering: Repo Hygiene Scan and Fix (QwenLM/qwen-code, 28k stars), CI Pipeline Synthesizer (kajisho5/ffmpeg-skill, 1.9k stars), GitHub Actions Supply Chain Pinning (asyncapi/generator, 1.1k stars) and Release (championswimmer/pi-context-prune, 245 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Wp CI CD And Release Engineering?

jorgerosal (a GitHub user) maintains it in jorgerosal/wordpress-skills, which has 103 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on June 7, 2026.

Source: jorgerosal/wordpress-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.