Agent skill

Wp Headless And Wpgraphql

by jorgerosal in jorgerosal/wordpress-skills

Headless WordPress and WPGraphQL review guidance. An agent skill from jorgerosal/wordpress-skills.

MITAuto-check passedBackend & APIs

Install Wp Headless And Wpgraphql

skills CLI
$ npx skills add jorgerosal/wordpress-skills --skill wp-headless-and-wpgraphql -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jorgerosal/wordpress-skills wp-headless-and-wpgraphql --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jorgerosal/wordpress-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-skills/wp-headless-and-wpgraphql .claude/skills/wp-headless-and-wpgraphql && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
wp-headless-and-wpgraphql
GitHub stars
102
Token cost
~1.7k tokens
SKILL.md length
673 words
Files
4 (incl. references)
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

Headless WordPress and WPGraphQL review guidance. An agent skill from jorgerosal/wordpress-skills.

  • Works in 6 steps: Identify the integration surface → Check data-model boundaries first → Review auth and preview behavior → …
  • Reviewing decoupled WordPress architectures
  • SKILL.md covers Overview, When to Use, Code Review Workflow and File-Type Specific Checks, plus 3 more sections
  • Calls rg

What it does

Wp Headless And Wpgraphql is an agent skill from jorgerosal/wordpress-skills. Headless WordPress and WPGraphQL review guidance. Use when reviewing decoupled WordPress architectures, WPGraphQL schema design, registergraphqlfield, registergraphqlconnection, graphqlregistertypes, Next.js/Gatsby/Remix frontends, preview mode, auth flows, persisted queries, or build/revalidation pipelines. Helps review schema boundaries, resolver performance, preview/auth correctness, cache invalidation, and content modeling decisions for headless WordPress stacks.

Its SKILL.md is about 1.7k tokens, which your agent loads only when the skill is triggered. The skill folder holds 4 other files, including reference files (for example `references/auth-preview-and-drafts.md`, `references/caching-builds-and-webhooks.md` and `references/graphql-schema-and-modeling.md`).

It sits in Backend & APIs, covering GraphQL, Authentication and Caching. It works with WordPress, GraphQL and Next.js. The repository describes itself as: ✅ 🎉 Claude skills and Codex skills for Wordpress development❗️. The licence is MIT.

When your agent uses it

  • Reviewing decoupled WordPress architectures
  • WPGraphQL schema design
  • Registergraphqlfield
  • Registergraphqlconnection

Example prompts

  • “/wp-headless-and-wpgraphql”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Identify the integration surface
  2. Check data-model boundaries first
  3. Review auth and preview behavior
  4. Review query and resolver efficiency
  5. Review cache and build invalidation
  6. Classify findings

What it can do on your machine

Read from SKILL.md and the folder at commit 8c96442. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Wp Headless And Wpgraphql loads about 1.7k tokens when it runs, and up to ~4.1k if it reads all its reference files. Until then it costs about 127 tokens; SKILL.md has 673 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~127
When it runs · the whole SKILL.md, loaded when a task matches
~1.7k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~4.1k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jorgerosal/wordpress-skills at commit 8c96442, republished under its MIT licence (© jorgerosal). 673 words, ~1,711 tokens.

Download SKILL.mdSave it as .claude/skills/wp-headless-and-wpgraphql/SKILL.md (or your agent's skills folder). This skill also uses 3 other files; get the full folder from GitHub.
name
wp-headless-and-wpgraphql
description
Headless WordPress and WPGraphQL review guidance. Use when reviewing decoupled WordPress architectures, WPGraphQL schema design, `register_graphql_field`, `register_graphql_connection`, `graphql_register_types`, Next.js/Gatsby/Remix frontends, preview mode, auth flows, persisted queries, or build/revalidation pipelines. Helps review schema boundaries, resolver performance, preview/auth correctness, cache invalidation, and content modeling decisions for headless WordPress stacks.

WordPress Headless and WPGraphQL Skill

Overview

Systematic review guidance for headless WordPress projects that expose content through WPGraphQL or adjacent APIs. Core principle: the schema should reflect durable content boundaries and predictable frontend needs, while auth, preview, caching, and build pipelines must stay explicit about trust boundaries and invalidation rules.

When to Use

Use when:

  • Reviewing WPGraphQL-powered themes, plugins, or headless integrations
  • Auditing custom schema extensions and resolver code
  • Reviewing frontend data-fetching patterns for WordPress content
  • Planning preview, draft, auth, or revalidation flows
  • Checking build pipelines, webhook invalidation, or persisted-query setups

Don't use for:

  • Classic REST-only WordPress integrations with no GraphQL surface (use wp-rest-api-development)
  • ACF field-group design with no headless frontend concerns (use wp-acf-and-content-modeling)
  • General plugin architecture review without a decoupled frontend (use wp-plugin-development)
  • Pure Playground demo setups (use wp-playground-development)

Code Review Workflow

  1. Identify the integration surface

    • WPGraphQL plugin usage and version assumptions
    • Custom schema registration (register_graphql_field, register_graphql_connection, register_graphql_object_type)
    • Frontend queries, fragments, and route/data loaders
    • Preview, auth, webhook, and cache invalidation flows
  2. Check data-model boundaries first

    • Does the GraphQL shape mirror the actual content model?
    • Are taxonomies/CPTs/options exposed intentionally rather than incidentally?
    • Are frontend needs being solved with durable schema design instead of ad hoc resolver logic?
  3. Review auth and preview behavior

    • Who can read drafts, revisions, private content, or preview tokens?
    • Are frontend preview endpoints explicit about capability checks and token validation?
    • Is the app leaking unpublished content through over-broad queries or caches?
  4. Review query and resolver efficiency

    • N+1 resolver patterns
    • Expensive meta lookups or unbounded connections
    • Missing field-level guards or pagination defaults
    • Over-fetching caused by schema or fragment design
  5. Review cache and build invalidation

    • Clear boundaries between origin cache, application cache, and CDN cache
    • Deterministic revalidation/webhook behavior
    • No build pipeline assumptions that require manual cache busting after every edit
  6. Classify findings

    • CRITICAL: unpublished content exposure, insecure preview/auth flow, unbounded resolver enabling data leakage or production instability
    • WARNING: fragile schema modeling, expensive resolvers, missing pagination, weak invalidation rules, frontend tightly coupled to unstable field shapes
    • INFO: could improve naming, fragments, schema docs, persisted-query discipline, or build observability

File-Type Specific Checks

WPGraphQL Schema Extensions
  • CRITICAL: schema exposes private/meta data without explicit permission checks
  • WARNING: resolver performs repeated get_post_meta() / WP_Query work per node without batching or caching
  • WARNING: field names or return types do not match the domain model and force frontend workarounds
  • INFO: could group related fields into object types or connections instead of one-off scalar sprawl
Show full SKILL.md (270 more words)Show less
Frontend Query Layers
  • WARNING: route/page queries fetch large trees when only a few fields are rendered
  • WARNING: fragments duplicated inconsistently across templates/routes
  • WARNING: preview mode and production mode share caches unsafely
  • INFO: could persist shared fragments or centralize query documents by content type
Preview and Auth Flows
  • CRITICAL: preview endpoint trusts only a slug or post ID without validating capability/token ownership
  • CRITICAL: draft/private content becomes cacheable at CDN or app layer
  • WARNING: no distinction between editor preview traffic and public traffic
  • INFO: could document preview lifecycle, token expiry, and cache bypass rules more clearly
Build / Revalidation / Webhooks
  • WARNING: every content change triggers a full rebuild with no scoping
  • WARNING: webhooks do not identify which routes/content depend on the mutation
  • WARNING: no retry/verification path for failed revalidation events
  • INFO: could add event logs or replayable webhook delivery for debugging

Search Patterns for Quick Detection (HEADLESS-21)

Use these rg commands to locate headless and WPGraphQL surfaces quickly.

Schema and Resolver Discovery
bash
rg -n "register_graphql_(field|fields|connection|object_type|interface_type|union_type|enum_type)|graphql_register_types" . -g '*.{php}'
rg -n "WPGraphQL|graphql" . -g '*.{php,js,jsx,ts,tsx,md,yml,yaml}'
Frontend Query Discovery
bash
rg -n "gql`|graphql`|useQuery\(|ApolloClient|@apollo/client|urql|graphql-request|getStaticProps|getServerSideProps|generateStaticParams" . -g '*.{js,jsx,ts,tsx}'
rg -n "preview|draftMode|draftMode\(|revalidate|revalidatePath|revalidateTag" . -g '*.{js,jsx,ts,tsx}'
Risky Data and Cache Patterns
bash
rg -n "get_post_meta\(|WP_Query\(|meta_query|posts_per_page\s*=>\s*-1" . -g '*.{php}'
rg -n "webhook|revalidation|x-vercel|x-signature|secret|persisted query|persistedQuery" . -g '*.{php,js,jsx,ts,tsx,yml,yaml}'

Reference Files

  • references/graphql-schema-and-modeling.md - Schema boundaries, CPT/taxonomy mapping, connection design, and resolver patterns
  • references/auth-preview-and-drafts.md - Preview mode, private content, auth boundaries, and cache bypass rules
  • references/caching-builds-and-webhooks.md - Persisted queries, caching layers, route revalidation, and webhook delivery design

Output Format (HEADLESS-23)

For each finding include:

  1. Severity: CRITICAL, WARNING, or INFO
  2. File and line number
  3. Headless/WPGraphQL risk summary
  4. Why it matters for schema design, frontend correctness, or production stability
  5. Recommended safer pattern

If no issues are found, say so clearly and mention any residual risks such as incomplete preview documentation, missing invalidation observability, or schema areas likely to drift as the frontend evolves.

© jorgerosal, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 3 other files (references) in claude-skills/wp-headless-and-wpgraphql of jorgerosal/wordpress-skills.

  • SKILL.md
  • references/auth-preview-and-drafts.md
  • references/caching-builds-and-webhooks.md
  • references/graphql-schema-and-modeling.md

Open the folder on GitHubat commit 8c96442

Compare with similar skills

Wp Headless And Wpgraphql next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Wp Headless And Wpgraphql compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Wp Headless And Wpgraphql this skilljorgerosal/wordpress-skills102—~1.7kAutomated safety check: PassMIT
Data Client Schemareactive/data-client2k—~2.3kAutomated safety check: PassApache-2.0
Apollo Clientapollographql/skills117—~1.9kAutomated safety check: PassMIT
Nestjsgiuseppe-trisciuoglio/developer-kit356—~1.4kAutomated safety check: NotesMIT
Apollo GraphqlKilo-Org/kilo-marketplace1901 repos~3.1kAutomated safety check: PassApache-2.0
Supabasecurvenote/curvenote1705 repos~2.2kAutomated safety check: PassCustom licence

Similar skills

  • Data Client Schema

    reactive/data-client

    Model data with @data-client schemas (Entity, EntityMixin, Collection, Union, Query, Values, All, Invalidate, Lazy, Scalar) for atomic, consistent, referentially-equal async data via normalization…

    2k GitHub stars~2.3k tokensUpdated today
    Backend & APIsAuto-check passed
  • Apollo Client

    apollographql/skills

    Guide for building React applications with Apollo Client 4.x.

    117 GitHub stars~1.9k tokensUpdated 2 days ago
    Backend & APIsAuto-check passed
  • Nestjs

    giuseppe-trisciuoglio/developer-kit

    Provides comprehensive NestJS framework patterns with Drizzle ORM integration for building scalable server-side applications.

    356 GitHub stars~1.4k tokensUpdated 29 days ago
    Backend & APIsAuto-check: notes
  • Apollo Graphql

    Kilo-Org/kilo-marketplace

    Guidelines for developing GraphQL APIs and React applications using Apollo Client for state management, data fetching, and caching

    190 GitHub starsUsed in 1 repo~3.1k tokens
    Backend & APIsAuto-check passed
  • Supabase

    curvenote/curvenote

    A skill your agent uses when doing ANY task involving Supabase.

    170 GitHub starsUsed in 5 repos~2.2k tokens
    Backend & APIsAuto-check passed
  • Ar Io Gateway Operator

    ar-io/ar-io-node

    Operate any AR.IO node deployment — architecture, daily ops, diagnostics, and recurring pitfalls that apply to every operator.

    127 GitHub stars~8.8k tokensUpdated today
    Backend & APIsAuto-check: notes

More from jorgerosal/wordpress-skills

All 35 skills in this repo
  • Wp Accessibility Review

    jorgerosal/wordpress-skills

    WordPress accessibility review for themes, blocks, plugins, and admin interfaces.

    102 GitHub stars~1.1k tokensUpdated 4 mo ago
    Auto-check passed
  • Wp Acf And Content Modeling

    jorgerosal/wordpress-skills

    WordPress ACF and content modeling review. An agent skill from jorgerosal/wordpress-skills.

    102 GitHub stars~3.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Wp Admin UI Development

    jorgerosal/wordpress-skills

    WordPress admin UI review and development guidance. An agent skill from jorgerosal/wordpress-skills.

    102 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Wp CI CD And Release Engineering

    jorgerosal/wordpress-skills

    WordPress CI/CD and release engineering review guidance. An agent skill from jorgerosal/wordpress-skills.

    102 GitHub stars~1.7k tokensUpdated 4 mo ago
    Auto-check passed
  • Wp Migration Upgrade Review

    jorgerosal/wordpress-skills

    WordPress migration and upgrade review. An agent skill from jorgerosal/wordpress-skills.

    102 GitHub stars~1.1k tokensUpdated 4 mo ago
    Auto-check passed
  • Wp Phpstan Review

    jorgerosal/wordpress-skills

    WordPress PHPStan review and setup guidance. An agent skill from jorgerosal/wordpress-skills.

    102 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed

Categories

Questions about Wp Headless And Wpgraphql

What does Wp Headless And Wpgraphql do?

Headless WordPress and WPGraphQL review guidance. An agent skill from jorgerosal/wordpress-skills. Wp Headless And Wpgraphql is an agent skill from jorgerosal/wordpress-skills. Headless WordPress and WPGraphQL review guidance.

When should I use Wp Headless And Wpgraphql?

Wp Headless And Wpgraphql fits situations like: reviewing decoupled WordPress architectures; WPGraphQL schema design; registergraphqlfield; registergraphqlconnection.

How do I install Wp Headless And Wpgraphql in Claude Code?

Run `npx skills add jorgerosal/wordpress-skills --skill wp-headless-and-wpgraphql -a claude-code`. Or copy the skill folder (claude-skills/wp-headless-and-wpgraphql in jorgerosal/wordpress-skills) into .claude/skills/wp-headless-and-wpgraphql in your project. Claude Code loads it when a task matches its description.

How do I install Wp Headless And Wpgraphql in Codex?

Run `npx skills add jorgerosal/wordpress-skills --skill wp-headless-and-wpgraphql -a codex`. Or copy the skill folder (claude-skills/wp-headless-and-wpgraphql in jorgerosal/wordpress-skills) into .agents/skills/wp-headless-and-wpgraphql in your project. Codex loads it when a task matches its description.

Can I use Wp Headless And Wpgraphql in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jorgerosal/wordpress-skills --skill wp-headless-and-wpgraphql -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wp-headless-and-wpgraphql, .gemini/skills/wp-headless-and-wpgraphql, .github/skills/wp-headless-and-wpgraphql and .opencode/skills/wp-headless-and-wpgraphql in your project.

What does Wp Headless And Wpgraphql need to run?

Going by SKILL.md and its folder, Wp Headless And Wpgraphql needs the command-line tools its instructions call (rg).

Does Wp Headless And Wpgraphql access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Wp Headless And Wpgraphql safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Wp Headless And Wpgraphql use?

Wp Headless And Wpgraphql is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Wp Headless And Wpgraphql use?

About 1.7k tokens (SKILL.md is roughly 6.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 2.4k tokens, read only when the agent opens those files.

What are the alternatives to Wp Headless And Wpgraphql?

Skills that share tags, products or a category with Wp Headless And Wpgraphql: Data Client Schema (reactive/data-client, 2k stars), Apollo Client (apollographql/skills, 117 stars), Nestjs (giuseppe-trisciuoglio/developer-kit, 356 stars) and Apollo Graphql (Kilo-Org/kilo-marketplace, 190 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Wp Headless And Wpgraphql?

jorgerosal (a GitHub user) maintains it in jorgerosal/wordpress-skills, which has 102 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on June 7, 2026.

Source: jorgerosal/wordpress-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.