Agent skill

Wp REST API Development

by jorgerosal in jorgerosal/wordpress-skills

WordPress REST API review and development guidance. An agent skill from jorgerosal/wordpress-skills.

MITAuto-check passedBackend & APIs

Install Wp REST API Development

skills CLI
$ npx skills add jorgerosal/wordpress-skills --skill wp-rest-api-development -a claude-code

Project install by default; add -g for ~/.claude/skills/.

GitHub CLI
$ gh skill install jorgerosal/wordpress-skills wp-rest-api-development --agent claude-code

Project scope by default; add --scope user for a personal install. Needs GitHub CLI 2.90.0 or later (public preview).

Manual copy
$ git clone --depth 1 https://github.com/jorgerosal/wordpress-skills.git skills-src && mkdir -p .claude/skills && cp -r skills-src/claude-skills/wp-rest-api-development .claude/skills/wp-rest-api-development && rm -rf skills-src

Use ~/.claude/skills/ instead of .claude/skills for a personal install. The folder must contain SKILL.md.

Claude Code skills documentation · loads skills from .claude/skills/

Facts

Skill name
wp-rest-api-development
GitHub stars
101
Token cost
~1.4k tokens
SKILL.md length
494 words
Files
3 (incl. references)
Skills in repo
35
Repo updated
First seen
Licence
MIT

At a glance

WordPress REST API review and development guidance. An agent skill from jorgerosal/wordpress-skills.

  • Works in 6 steps: Identify REST context → Check route registration first → Review request handling → …
  • Reviewing custom REST routes
  • SKILL.md covers Overview, When to Use, Code Review Workflow and File-Type Specific Checks, plus 3 more sections
  • Calls rg

What it does

Wp REST API Development is an agent skill from jorgerosal/wordpress-skills. WordPress REST API review and development guidance. Use when reviewing custom REST routes, permissioncallback logic, schema design, WPRESTRequest handling, response structure, versioning, controller classes, nonce or auth usage, or when user mentions "REST API review", "registerrestroute", "permissioncallback", "WPRESTRequest", "REST endpoint", "custom API", "API schema", "REST controller", "headless WordPress", or "API auth". Detects route registration issues, authorization mistakes, schema drift, input…

Its SKILL.md is about 1.4k tokens, which your agent loads only when the skill is triggered. The skill folder holds 3 other files, including reference files (for example `references/route-patterns.md` and `references/schema-and-auth-guide.md`).

It sits in Backend & APIs, covering REST APIs. It works with WordPress. The repository describes itself as: ✅ 🎉 Claude skills and Codex skills for Wordpress development❗️. The licence is MIT.

When your agent uses it

  • Reviewing custom REST routes
  • Permissioncallback logic
  • WPRESTRequest handling
  • Response structure

Example prompts

  • “REST API review”
  • “registerrestroute”
  • “permissioncallback”
  • “/wp-rest-api-development”

Workflow steps

6 steps, taken from the first numbered list in SKILL.md.

  1. Identify REST context
  2. Check route registration first
  3. Review request handling
  4. Review response design
  5. Check for CRITICAL/WARNING/INFO patterns
  6. Report with cross-references

What it can do on your machine

Read from SKILL.md and the folder at commit 8c96442. It shows what the files ask for, not the result of running them.

  • Tool permissions

    Pre-approves nothing: there is no allowed-tools line, so your agent's usual permission prompts apply.

    From allowed-tools in the SKILL.md frontmatter.

  • Runs code

    Shell commands in SKILL.md call:

    • rg

    From the folder's file list and the shell code blocks in SKILL.md.

  • Network

    No URLs in SKILL.md.

    From URLs in SKILL.md, links to its own repository left out.

  • Credentials

    Names no API keys, tokens, secrets or passwords.

    From names ending in _API_KEY, _TOKEN, _SECRET, _KEY or _PASSWORD in SKILL.md.

Context cost

Wp REST API Development loads about 1.4k tokens when it runs, and up to ~1.9k if it reads all its reference files. Until then it costs about 154 tokens; SKILL.md has 494 words of instructions outside code blocks.

Always · name and description, kept in context so the agent knows when to use it
~154
When it runs · the whole SKILL.md, loaded when a task matches
~1.4k
With references · SKILL.md plus every file in references/, read only if the agent opens them
~1.9k

Estimates: characters ÷ 4, the usual rule of thumb; real counts depend on the model's tokenizer. Scripts and assets cost tokens only if the agent reads them.

Safety

Auto-check passed

The automated check found no risky patterns in SKILL.md.

Automated static check — not a guarantee. Review scripts before installing. It scans the text of SKILL.md for risky patterns (piping downloads into a shell, reading credential files, hidden Unicode, destructive commands); files beside SKILL.md are not scanned.

SKILL.md

The full file from jorgerosal/wordpress-skills at commit 8c96442, republished under its MIT licence (© jorgerosal). 494 words, ~1,449 tokens.

Download SKILL.mdSave it as .claude/skills/wp-rest-api-development/SKILL.md (or your agent's skills folder). This skill also uses 2 other files; get the full folder from GitHub.
name
wp-rest-api-development
description
WordPress REST API review and development guidance. Use when reviewing custom REST routes, permission_callback logic, schema design, WP_REST_Request handling, response structure, versioning, controller classes, nonce or auth usage, or when user mentions "REST API review", "register_rest_route", "permission_callback", "WP_REST_Request", "REST endpoint", "custom API", "API schema", "REST controller", "headless WordPress", or "API auth". Detects route registration issues, authorization mistakes, schema drift, input validation gaps, and response design problems in WordPress REST API code.

WordPress REST API Development Skill

Overview

Systematic REST API review for WordPress plugins, themes, and custom code. Core principle: Every route needs a clear contract, explicit authorization, validated input, and predictable output. Review covers route registration, controller patterns, request parsing, schema and argument validation, response formatting, caching implications, and compatibility concerns. Report findings with line numbers, severity labels, and BAD/GOOD code pairs where helpful.

When to Use

Use when:

  • Reviewing register_rest_route() usage
  • Auditing custom API endpoints or controller classes
  • Checking permission_callback logic
  • Validating WP_REST_Request input handling
  • Reviewing response shape, status codes, and schema
  • Designing versioned endpoints for headless or block-driven apps

Don't use for:

  • General plugin architecture without REST focus (use wp-plugin-development)
  • Security-only review across the whole plugin (use wp-security-review)
  • Full WooCommerce endpoint review (use wp-woocommerce-dev when WC-specific)
  • GraphQL-specific guidance

Code Review Workflow

  1. Identify REST context

    • Route callbacks in plugin bootstrap
    • Controller classes extending WP_REST_Controller
    • Headless frontend integration
    • Internal admin-only API usage
  2. Check route registration first

    • Namespace and version format
    • HTTP methods match operation intent
    • permission_callback present and specific
    • args definitions for request validation
  3. Review request handling

    • Use $request->get_param() or typed getters instead of raw globals
    • Validate and sanitize all user input
    • Reject malformed input with meaningful WP_Error
  4. Review response design

    • Consistent response shape
    • Proper status codes
    • rest_ensure_response() where helpful
    • Avoid leaking internal details
  5. Check for CRITICAL/WARNING/INFO patterns

    • CRITICAL: Missing permission_callback, write routes with __return_true, raw globals, unsanitized DB queries
    • WARNING: Inconsistent schema, weak validation, mixed response shapes, missing pagination info
    • INFO: Could use controller class, schema reuse, versioning cleanup
  6. Report with cross-references

    • If auth or nonce issues dominate, suggest /wp-sec-review
    • If route logic is plugin-architecture-heavy, suggest /wp-plugin-review

File-Type Specific Checks

Route Registration (register_rest_route)
  • CRITICAL: Missing permission_callback
  • CRITICAL: 'permission_callback' => '__return_true' on write endpoints
  • WARNING: Namespace without version segment
  • WARNING: Route registered outside rest_api_init
  • INFO: Repeated inline callbacks that should use controller methods
Show full SKILL.md (186 more words)Show less
Permission Callbacks
  • CRITICAL: Capability checks missing on private data
  • WARNING: Callback always returns true for admin-like actions
  • WARNING: No ownership check for user-specific resources
  • INFO: Could centralize repeated permission logic
Request Args and Validation
  • CRITICAL: Raw $_GET/$_POST used inside endpoint callback
  • WARNING: Missing sanitize_callback or validate_callback
  • WARNING: Missing enum/format constraints for known values
  • INFO: Could define reusable item schema
Response Handling
  • WARNING: Mixed success response shape across routes
  • WARNING: wp_send_json() inside REST callbacks instead of returning response data
  • INFO: Could use WP_REST_Response for headers/status control

Search Patterns for Quick Detection (API-21)

Use these rg commands for quick REST API scanning. Organized by severity.

CRITICAL Patterns
bash
# register_rest_route candidates
rg -n "register_rest_route\s*\(" . -g '*.php'

# permission_callback returning true
rg -n "permission_callback.*__return_true" . -g '*.php'

# Raw superglobals inside REST callbacks
rg -n "\$_GET|\$_POST|\$_REQUEST" . -g '*.php'
WARNING Patterns
bash
# WP_REST_Request usage without obvious validation helpers
rg -n "WP_REST_Request|get_param\s*\(" . -g '*.php'

# REST callbacks using wp_send_json
rg -n "wp_send_json|wp_send_json_success|wp_send_json_error" . -g '*.php'

# Route namespaces to inspect for versioning
rg -n "register_rest_route\s*\(\s*['\"][^'\"]+" . -g '*.php'
INFO Patterns
bash
# WP_REST_Controller classes
rg -n "extends\s+WP_REST_Controller" . -g '*.php'

# rest_ensure_response usage
rg -n "rest_ensure_response|new\s+WP_REST_Response" . -g '*.php'

Reference Files

  • references/route-patterns.md - Route registration, controller structure, and namespace design
  • references/schema-and-auth-guide.md - Args schema, permission callbacks, input validation, and response design

Output Format (API-23)

For each finding include:

  1. Severity: CRITICAL, WARNING, or INFO
  2. File and line number
  3. Issue summary
  4. Why it matters for WordPress REST API behavior
  5. Recommended fix

If no issues are found, say so clearly and mention any residual gaps such as missing tests, inconsistent schema documentation, or limited versioning strategy.

© jorgerosal, MIT. Rendered from Markdown: HTML in the file is shown as text, images as links, and headings moved down two levels. Raw file

Files

SKILL.md and 2 other files (references) in claude-skills/wp-rest-api-development of jorgerosal/wordpress-skills.

  • SKILL.md
  • references/route-patterns.md
  • references/schema-and-auth-guide.md

Open the folder on GitHubat commit 8c96442

Compare with similar skills

Wp REST API Development next to the 5 skills that share the most tags, products or categories with it. Stars are the repository's; “used in” counts other GitHub owners with a copy.

Wp REST API Development compared with similar skills
SkillStarsUsed inTokensAuto-checkLicenceRepo updated
Wp REST API Development this skilljorgerosal/wordpress-skills101—~1.4kAutomated safety check: PassMIT
Wp Performancegambitph/Stackable3503 repos~1.5kAutomated safety check: PassGPL-3.0
WooCommerce Store API Routeswoocommerce/woocommerce11k—~932Automated safety check: PassCustom licence
Blog TaxonomyAgriciDaniel/claude-blog2.3k1 repos~2.5kAutomated safety check: PassMIT
Wordpress Routergambitph/Stackable3503 repos~554Automated safety check: PassGPL-3.0
Wp REST APIgambitph/Stackable3502 repos~1.2kAutomated safety check: PassGPL-3.0

Similar skills

  • Wp Performance

    gambitph/Stackable

    A skill your agent uses when investigating or improving WordPress performance (backend-only agent): profiling and measurement (WP-CLI profile/doctor, Server-Timing, Query Monitor via REST headers)…

    350 GitHub starsUsed in 3 repos~1.5k tokens
    Backend & APIsAuto-check passed
  • WooCommerce Store API Routes

    woocommerce/woocommerce

    Guidelines for adding or changing routes in the WooCommerce Store API under /wc/store/v1, covering authentication, REST design, schemas and variations.

    11k GitHub stars~932 tokensUpdated today
    Backend & APIsAuto-check passed
  • Blog Taxonomy

    AgriciDaniel/claude-blog

    Extract, suggest, and sync tags and categories for blog posts across all major CMS platforms.

    2.3k GitHub starsUsed in 1 repo~2.5k tokens
    Backend & APIsAuto-check passed
  • Wordpress Router

    gambitph/Stackable

    A skill your agent uses when the user asks about WordPress codebases (plugins, themes, block themes, Gutenberg blocks, WP core checkouts) and you need to quickly classify the repo and route to the…

    350 GitHub starsUsed in 3 repos~554 tokens
    Backend & APIsAuto-check passed
  • Wp REST API

    gambitph/Stackable

    A skill your agent uses when building, extending, or debugging WordPress REST API endpoints/routes: registerrestroute, WPRESTController/controller classes, schema/argument validation…

    350 GitHub starsUsed in 2 repos~1.2k tokens
    Backend & APIsAuto-check passed
  • Wordpress Setup

    jezweb/claude-skills

    Connect to a WordPress site via WP-CLI over SSH or the REST API.

    1.1k GitHub stars~1.1k tokensUpdated 3 days ago
    Backend & APIsAuto-check: notes

More from jorgerosal/wordpress-skills

All 35 skills in this repo
  • Wp Accessibility Review

    jorgerosal/wordpress-skills

    WordPress accessibility review for themes, blocks, plugins, and admin interfaces.

    101 GitHub stars~1.1k tokensUpdated 4 mo ago
    Auto-check passed
  • Wp Acf And Content Modeling

    jorgerosal/wordpress-skills

    WordPress ACF and content modeling review. An agent skill from jorgerosal/wordpress-skills.

    101 GitHub stars~3.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Wp Admin UI Development

    jorgerosal/wordpress-skills

    WordPress admin UI review and development guidance. An agent skill from jorgerosal/wordpress-skills.

    101 GitHub stars~1.2k tokensUpdated 4 mo ago
    Auto-check passed
  • Wp CI CD And Release Engineering

    jorgerosal/wordpress-skills

    WordPress CI/CD and release engineering review guidance. An agent skill from jorgerosal/wordpress-skills.

    101 GitHub stars~1.7k tokensUpdated 4 mo ago
    Auto-check passed
  • Wp Headless And Wpgraphql

    jorgerosal/wordpress-skills

    Headless WordPress and WPGraphQL review guidance. An agent skill from jorgerosal/wordpress-skills.

    101 GitHub stars~1.7k tokensUpdated 4 mo ago
    Auto-check passed
  • Wp Migration Upgrade Review

    jorgerosal/wordpress-skills

    WordPress migration and upgrade review. An agent skill from jorgerosal/wordpress-skills.

    101 GitHub stars~1.1k tokensUpdated 4 mo ago
    Auto-check passed

Works with

Categories

Questions about Wp REST API Development

What does Wp REST API Development do?

WordPress REST API review and development guidance. An agent skill from jorgerosal/wordpress-skills. Wp REST API Development is an agent skill from jorgerosal/wordpress-skills. WordPress REST API review and development guidance.

When should I use Wp REST API Development?

Wp REST API Development fits situations like: reviewing custom REST routes; permissioncallback logic; WPRESTRequest handling; response structure.

How do I install Wp REST API Development in Claude Code?

Run `npx skills add jorgerosal/wordpress-skills --skill wp-rest-api-development -a claude-code`. Or copy the skill folder (claude-skills/wp-rest-api-development in jorgerosal/wordpress-skills) into .claude/skills/wp-rest-api-development in your project. Claude Code loads it when a task matches its description.

How do I install Wp REST API Development in Codex?

Run `npx skills add jorgerosal/wordpress-skills --skill wp-rest-api-development -a codex`. Or copy the skill folder (claude-skills/wp-rest-api-development in jorgerosal/wordpress-skills) into .agents/skills/wp-rest-api-development in your project. Codex loads it when a task matches its description.

Can I use Wp REST API Development in Cursor, Gemini CLI or GitHub Copilot?

Cursor, Gemini CLI, GitHub Copilot and OpenCode also load SKILL.md folders. With the skills CLI, run `npx skills add jorgerosal/wordpress-skills --skill wp-rest-api-development -a cursor` (or -a gemini-cli, github-copilot or opencode for the others). To copy it by hand, put the folder in .cursor/skills/wp-rest-api-development, .gemini/skills/wp-rest-api-development, .github/skills/wp-rest-api-development and .opencode/skills/wp-rest-api-development in your project.

What does Wp REST API Development need to run?

Going by SKILL.md and its folder, Wp REST API Development needs the command-line tools its instructions call (rg).

Does Wp REST API Development access the network?

SKILL.md contains no URLs. Any network use would come from the scripts or tools the agent runs. This is read from the text; nothing was executed.

Is Wp REST API Development safe to install?

Our automated static check of SKILL.md found no risky patterns, such as piping downloads into a shell, reading credential files or hidden Unicode. It is not a guarantee. Review the folder before installing.

What licence does Wp REST API Development use?

Wp REST API Development is published under the MIT licence (the repository's licence). It allows redistribution, so the full SKILL.md is shown on this page.

How many tokens does Wp REST API Development use?

About 1.4k tokens (SKILL.md is roughly 5.8k characters). Agents keep only the skill's name and description in context until a task matches; then they load SKILL.md in full. Its references folder adds about 473 tokens, read only when the agent opens those files.

What are the alternatives to Wp REST API Development?

Skills that share tags, products or a category with Wp REST API Development: Wp Performance (gambitph/Stackable, 350 stars), WooCommerce Store API Routes (woocommerce/woocommerce, 11k stars), Blog Taxonomy (AgriciDaniel/claude-blog, 2.3k stars) and Wordpress Router (gambitph/Stackable, 350 stars). The comparison table on this page puts their stars, adoption, token cost, safety result and licence side by side.

Who maintains Wp REST API Development?

jorgerosal (a GitHub user) maintains it in jorgerosal/wordpress-skills, which has 101 GitHub stars. The repository holds 35 skills in this directory. The repository was last updated on June 7, 2026.

Source: jorgerosal/wordpress-skills on GitHub. Facts on this page come from the repository at the commit we read; the author's words are quoted as theirs.