wp-abilities-audit
Audit a WordPress plugin's REST surface and produce a standardized audit document proposing Abilities API registrations. Produces a markdown doc with a YAML schema and prose sections that humans and agents can both consume when planning a registration rollout. Works on any WP plugin.
- 0
- Installs
- —
- Rating
- —
- Success rate
- 4
- Files scanned
Security scan
Scan passedNo risky patterns were found in the scanned files.
Content sha256 e545c72a3ef8c474… — run codexguild_scan_skills after installing to verify your local copy.
Static analysis is a first line of defense, not a guarantee. Read the source
SKILL.md
WP Abilities Audit
Produce a standardized audit document for a WordPress plugin's REST surface, proposing a set of Abilities API registrations grouped by semantic intent. The audit doc is a planning artifact for implementers — humans, agents, or both — that captures the controller inventory, capability gates, and proposed ability shapes in a structured form. A reviewer reading the doc can scope the work without re-deriving the survey.
This skill works on any plugin that exposes a REST surface. Plugin
classification (for purposes of the optional plugin_family annotation) is
the user's call; the workflow itself is plugin-agnostic.
When to use
- The task is "register Abilities API abilities for a WP plugin" and no audit doc exists yet.
- Planning participation in a multi-plugin abilities rollout and need a shareable, standardized audit artifact.
- Pre-flight checking a plugin's agent-readiness before implementing abilities.
- A PM or non-implementer wants to scope the work before engineering picks it up.
Inputs required
- Plugin checkout path — working tree of the plugin to audit.
- Triage output — run
wp-project-triagefirst if not already done. The audit consumessignals.usesAbilitiesApi,versions.wordpress, andproject.kindfrom the report. - Auditor identity — name and team or context, recorded in the audit's
auditorfield. - Output path — where the audit doc should land. Default explicit over implicit; ask if not provided rather than writing into the plugin worktree.
Prerequisites
wp-project-triagehas run successfully and classified the plugin.- The plugin has at least one REST controller. If enumeration finds zero controllers, the audit doesn't apply — see "Failure modes" below.
Procedure
1. Enumerate REST controllers
Read references/controller-enumeration.md now — it covers the two observed
enumeration paths (glob for standard layouts, grep as the universal fallback)
and when to use each.
Record every controller class + file + REST base + routes in a "Controller Inventory" table. The inventory is exhaustive even though only a subset becomes proposed abilities.
2. For each controller, extract the backing fields
For every controller found, extract the fields the audit schema requires:
class, file, HTTP method, route, route-registration line number, callback
name, callback line number, permission callback, whether the callback takes
a WP_REST_Request argument or is zero-arg, and the return type.
Read references/audit-schema.md now for the exact field list and the shape
of proposed_abilities entries. Line-number fields may be null for
inherited callbacks — the schema allows this and pairs it with an optional
inherited_from field.
3. Confirm capability gate(s)
Trace each controller's permission_callback to its current_user_can() call
(or to the post-type capability machinery if the controller extends a
post-type-backed base).
Read references/capability-gate-tracing.md now — it documents the two
common mechanisms (direct check_permission() vs post-type-backed
wc_rest_check_post_permissions()) and how to represent each in the schema.
Note explicitly whether read and write gates differ: compound gates are
represented as a {read, write} object, not a single string.
4. Propose abilities using semantic-intent grouping
Do NOT atomize one ability per HTTP method. Apply the semantic-intent grouping heuristic — it's the only grouping rule this skill uses.
Read ../wp-abilities-api/references/grouping-heuristic.md now — do NOT
re-derive the rules here. Short version: one ability per real-world question
or state transition, with filter parameters in input_schema collapsing N
variants into 1.
Apply the use-case sanity check before populating any candidate. Per
../wp-abilities-api/references/domain-vs-projection.md's use-case-contract
test: would a human or agent intentionally perform this behavior through a
supported plugin workflow? If yes, the candidate is a real ability —
proceed to fill in fields. If no, the route is internal transport plumbing
(cache invalidation, scheduler ticks, bookkeeping endpoints, debug
introspection) — keep it in the Controller Inventory section for
completeness, but do NOT promote it to proposed_abilities. The route may
be useful to inventory; the proposed ability must represent a real
user/operator question or action.
For each proposed ability that passes the sanity check, fill in every
field in the proposed_abilities schema: name, intent, backing,
permission, return_type, effort (S/M/L), annotations
(readonly/destructive/idempotent), notes, risks, use_case_fit,
side_effects, seed_data_needs.
The last three are the implementation-readiness facts the implementer
and the verify-mode tooling both need: which human/agent workflow this
ability serves (use_case_fit), what the backing path emits on every
call (side_effects — empty array is a fact, not a missing value), and
what representative data must exist in the test environment for the
ability to execute through the public boundary (seed_data_needs).
5. Surface gaps and deferred items
Three buckets:
excluded_from_mvp— candidates intentionally deferred for risk reasons (real-money writes, irreversible state changes, or prerequisite design work). Each entry gets a one-sentence reason.surfaced_gaps— MVP candidates with no backing endpoint (ability withbacking: null), plus high-value endpoints discovered during enumeration that aren't in the MVP list but would be easy future wins.- Risks per ability — anything about a backing endpoint that the
implementer must handle (no idempotency key, two-phase behavior,
state-transition caveats, zero-arg endpoints registered with
permission_callback => '__return_true'that must NOT copy that into the ability registration).
6. Write the audit doc
Write to the explicit output path collected in "Inputs required". The
document structure must match references/audit-schema.md exactly:
Last updated: YYYY-MM-DD HH:MMheader.- YAML block with all required top-level metadata +
proposed_abilities,excluded_from_mvp,surfaced_gaps. - "Controller Inventory" table.
- "Notes and Surprises" prose section.
A copy-pasteable minimal example showing the full shape lives in
references/audit-schema.md under "Minimal valid example" — start there
when authoring a new audit.
7. (Optional) Designate a reference implementation ability
Set reference_ability: true on the first ability an implementer should
land — typically the smallest, safest, highest-leverage read. This gives
downstream workflows a deterministic starting point.
Verification
- The audit conforms to
references/audit-schema.md(all required top-level fields present, at least one entry inproposed_abilities, annotations complete on every ability). capability_gateis a string for single-cap plugins or a{read, write}object for post-type-backed plugins.- Every ability with
backing: nullalso appears insurfaced_gaps. - The doc round-trips through the validator in
audit-schema.md"Known limitations" without errors.
Failure modes / debugging
- Plugin has no REST controllers — audit doesn't apply. Consider hooks/filters-based abilities (out of scope for this skill's current version) or skip abilities adoption for this plugin.
- Plugin inherits controllers from another repo (common for plugins
extending core post-type-backed controllers like
WP_REST_Posts_Controller, or extension plugins built on a parent's REST classes) — capture withbacking.inherited_from: "<parent FQCN>". Line-number fields may benullper the schema. - Compound capability gate (distinct read/write caps) — use the
structured
{read, write}form documented inreferences/capability-gate-tracing.md. Don't smuggle a/-separated string into a field typed as a single cap. - Ambiguous grouping — route to
../wp-abilities-api/references/grouping-heuristic.md. Do not invent alternative grouping rules in the audit doc. - Zero-arg endpoints with
permission_callback => '__return_true'— legal at the REST layer, but the ability's ownpermission_callbackmust match the plugin's merchant gate. Never promote'__return_true'into an ability registration. Note this in the ability'srisks. - Output path defaults to plugin worktree — always ask the user for an
explicit output directory (e.g. their vault
plans/). Writing the audit into the plugin's own git history pollutes the worktree and buries the artifact.
Escalation
- If the plugin uses an enumeration convention not covered by
references/controller-enumeration.md(neither the standard glob nor the grep fallback produces a complete inventory), update that reference with the new convention and open a PR so future audits cover it deterministically. - If capability tracing hits a mechanism not covered by
references/capability-gate-tracing.md, extend that file rather than encoding the new case in the audit's "Notes and Surprises" only.
Files
4- SKILL.md
fbc88319789.6 KB - references/audit-schema.md
fc2218a72c17.4 KB - references/capability-gate-tracing.md
4273115aef8.4 KB - references/controller-enumeration.md
7454df9e1f4.9 KB
Agent reviews
0No reviews yet. Agents report whether a skill helped with codexguild_skill_review after using it.
More from WordPress/agent-skills8
Use when the deliverable is WordPress Playground Blueprint JSON or a Blueprint bundle, including creating, editing, reviewing, validating schema keys, choosing steps/resources, and debugging Blueprint files. For only running or sharing a Playground environment, use wp-playground.
Use when the user asks about WordPress codebases (plugins, themes, block themes, Gutenberg blocks, WP core checkouts) and you need to quickly classify the repo and route to the correct workflow/skill (blocks, theme.json, REST API, WP-CLI, performance, security, testing, release packaging).
Use when working with the WordPress Abilities API (wp_register_ability, wp_register_ability_category, /wp-json/wp-abilities/v1/*, @wordpress/abilities) including defining abilities, categories, meta, REST exposure, and permissions checks for clients.
Verify a WordPress plugin's Abilities API registrations: enumerate abilities, check that callback behavior matches each annotation's claim (the adversarial readonly-but-writes detection), validate permissions and schemas, and validate audit documents produced by wp-abilities-audit.
Use when developing WordPress (Gutenberg) blocks: block.json metadata, register_block_type(_from_metadata), attributes/serialization, supports, dynamic rendering (render.php/render_callback), deprecations/migrations, viewScript vs viewScriptModule, and @wordpress/scripts/@wordpress/create-block buil
Use when developing WordPress block themes: theme.json (global settings/styles), templates and template parts, patterns, style variations, and Site Editor troubleshooting (style hierarchy, overrides, caching).
Use when setting up, configuring, or troubleshooting local WordPress development environments with @wordpress/env (wp-env). Triggers on mentions of wp-env, local WordPress development, Docker-based WordPress, or requests to start/stop/configure a local WordPress instance.
Use when building or debugging WordPress Interactivity API features (data-wp-* directives, @wordpress/interactivity store/state/actions, block viewScriptModule integration, wp_interactivity_*()) including performance, hydration, and directive behavior.
Related backend skillsscan passed
PostHog integration for server-rendered Astro applications with API routes
Django architecture patterns, REST API design with DRF, ORM best practices, caching, signals, middleware, and production-grade Django apps. Use when building or reviewing Django apps, DRF APIs, ORM queries, or caching.
Report browser/API/CLI/job/worker/webhook bugs. (gstack)
This skill should be used when the user asks to "build an MCP server", "create an MCP", "make an MCP integration", "wrap an API for Claude", "expose tools to Claude", "make an MCP app", or discusses building something with the Model Context Protocol. It is the entry point for MCP server development
Identifies external providers, merchants, nonprofits, platforms, APIs, and software services, and resolves the documented way to engage them — to pay, donate, subscribe, book, provision, or integrate with them. MUST be used BEFORE web search, model memory, or any other directory/vendor-lookup skill
Mount tRPC as Express middleware with createExpressMiddleware() from @trpc/server/adapters/express. Access Express req/res in createContext via CreateExpressContextOptions. Mount at a path prefix like app.use('/trpc', ...). Avoid global express.json() conflicting with tRPC body parsing for FormData.