All skills
automattic avatar

/wp-abilities-api

@95e374f official
by automatticautomattic/agent-skills211 stars
37

Use when working with the WordPress Abilities API (wp_register_ability, wp_register_ability_category, /wp-json/wp-abilities/v1/*, @wordpress/abilities) including defining abilities, categories, meta, REST exposure, and permissions checks for clients.

Use this Skill: https://skilld.dev/gh/automattic/agent-skills/wp-abilities-api

This session only. Nothing lands on disk.

SKILL.md

≈67 tokens always: the name and description. ≈807 when used: this file. ≈730 more on demand in 2 files.

WP Abilities API

When to use

Use this skill when the task involves:

  • registering abilities or ability categories in PHP,
  • exposing abilities to clients via REST (wp-abilities/v1),
  • consuming abilities in JS (notably @wordpress/abilities),
  • diagnosing “ability doesn’t show up” / “client can’t see ability” / “REST returns empty”.

Inputs required

  • Repo root (run wp-project-triage first if you haven’t).
  • Target WordPress version(s) and whether this is WP core or a plugin/theme.
  • Where the change should live (plugin vs theme vs mu-plugin).

Procedure

1) Confirm availability and version constraints

  • If this is WP core work, check signals.isWpCoreCheckout and versions.wordpress.core.
  • If the project targets WP < 6.9, you may need the Abilities API plugin/package rather than relying on core.

2) Find existing Abilities usage

Search for these in the repo:

  • wp_register_ability(
  • wp_register_ability_category(
  • wp_abilities_api_init
  • wp_abilities_api_categories_init
  • wp-abilities/v1
  • @wordpress/abilities

If none exist, decide whether you’re introducing Abilities API fresh (new registrations + client consumption) or only consuming.

3) Register categories (optional)

If you need a logical grouping, register an ability category early (see references/php-registration.md).

4) Register abilities (PHP)

Implement the ability in PHP registration with:

  • stable id (namespaced),
  • label/description,
  • category,
  • meta:
    • add readonly: true when the ability is informational,
    • set show_in_rest: true for abilities you want visible to clients.

Use the documented init hooks for Abilities API registration so they load at the right time (see references/php-registration.md).

5) Confirm REST exposure

  • Verify the REST endpoints exist and return expected results (see references/rest-api.md).
  • If the client still can’t see the ability, confirm meta.show_in_rest is enabled and you’re querying the right endpoint.

6) Consume from JS (if needed)

  • Prefer @wordpress/abilities APIs for client-side access and checks.
  • Ensure build tooling includes the dependency and the project’s build pipeline bundles it.

Verification

  • wp-project-triage indicates signals.usesAbilitiesApi: true after your change (if applicable).
  • REST check (in a WP environment): endpoints under wp-abilities/v1 return your ability and category when expected.
  • If the repo has tests, add/update coverage near:
    • PHP: ability registration and meta exposure
    • JS: ability consumption and UI gating

Failure modes / debugging

  • Ability never appears:
    • registration code not running (wrong hook / file not loaded),
    • missing meta.show_in_rest,
    • incorrect category/ID mismatch.
  • REST shows ability but JS doesn’t:
    • wrong REST base/namespace,
    • JS dependency not bundled,
    • caching (object/page caches) masking changes.

Escalation

  • If you’re uncertain about version support, confirm target WP core versions and whether Abilities API is expected from core or as a plugin.
  • For canonical details, consult:
    • references/rest-api.md
    • references/php-registration.md

Source: SKILL.md on GitHub

No alerts17d4 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    The skill is safe and follows WordPress development best practices. It utilizes official WordPress APIs and provides security recommendations such as implementing permission callbacks and namespacing IDs.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer7mo

    2/3 files flagged

Signed by skilld at 95e374f. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 5 months ago.

Dormantupdated 9 months ago
Other metadata
compatibility
Targets WordPress 6.9+ (PHP 7.2.24+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.
  • wordpress
  • abilities-api
  • rest-api
  • php
  • javascript
  • permissions
  • wp-cli

README badge

README badge for automattic/agent-skills/wp-abilities-api

Registers and exposes WordPress abilities (permissions/capabilities) via PHP hooks and REST endpoints, enabling client-side permission checks through the @wordpress/abilities library. Targets WordPress 6.9+ and handles ability registration, categorization, REST exposure, and consumption in JavaScript.

Generated from the current SKILL.md.

What WordPress versions does this skill support?
WordPress 6.9+ with PHP 7.2.24+. For earlier versions, you may need the Abilities API as a separate plugin or package rather than relying on core.
Do I need WP-CLI to use this skill?
Some workflows require WP-CLI, but it is not universally required. Basic ability registration and REST exposure can work without it.
How do I make an ability visible to JavaScript clients?
Set `meta.show_in_rest: true` when registering the ability in PHP, then consume it on the client side using the `@wordpress/abilities` package.
Can I use this skill for WordPress core work, or only plugins and themes?
The skill works for core, plugins, and themes. Check the target WordPress version and whether Abilities API is expected from core or as a plugin before starting.
What should I do if an ability is registered but doesn't appear in the REST API?
Verify that `meta.show_in_rest` is enabled, the registration code is running on the correct hook, and the ability ID and category are correctly set. Check REST endpoints under `wp-abilities/v1` directly to confirm exposure.

Generated from the current SKILL.md. These answers refresh after source changes.