All skills
automattic avatar

/wp-abilities-api

@95e374f official
by automatticautomattic/agent-skills211 stars
37

Use when working with the WordPress Abilities API (wp_register_ability, wp_register_ability_category, /wp-json/wp-abilities/v1/*, @wordpress/abilities) including defining abilities, categories, meta, REST exposure, and permissions checks for clients.

Use this Skill: https://skilld.dev/gh/automattic/agent-skills/wp-abilities-api

This session only. Nothing lands on disk.

referencesphp-registration.md

≈636 tokens on demand. Your agent reads this file only when SKILL.md points to it.

PHP registration quick guide

Key concepts and entrypoints for the WordPress Abilities API:

  • Register ability categories and abilities in PHP.
  • Use the Abilities API init hooks to ensure registration occurs at the right lifecycle time.

Hook order (critical)

Categories must be registered before abilities. Use the correct hooks:

  1. wp_abilities_api_categories_init — Register categories here first.
  2. wp_abilities_api_init — Register abilities here (after categories exist).

Warning: Registering abilities outside wp_abilities_api_init triggers _doing_it_wrong() and the registration will fail.

// 1. Register category first
add_action( 'wp_abilities_api_categories_init', function() {
    wp_register_ability_category( 'my-plugin', [
        'label' => __( 'My Plugin', 'my-plugin' ),
    ] );
} );

// 2. Then register abilities
add_action( 'wp_abilities_api_init', function() {
    wp_register_ability( 'my-plugin/get-info', [
        'label'       => __( 'Get Site Info', 'my-plugin' ),
        'description' => __( 'Returns basic site information.', 'my-plugin' ),
        'category'    => 'my-plugin',
        'callback'    => 'my_plugin_get_info_callback',
        'meta'        => [ 'show_in_rest' => true ],
    ] );
} );

Common primitives

  • wp_register_ability_category( $category_id, $args )
  • wp_register_ability( $ability_id, $args )

Key arguments for wp_register_ability()

Argument Description
label Human-readable name for UI (e.g., command palette)
description What the ability does
category Category ID (must be registered first)
callback Function that executes the ability
input_schema JSON Schema for expected input (enables validation)
output_schema JSON Schema for returned output
permission_callback Optional function to check if current user can execute
meta.show_in_rest Set true to expose via REST API
meta.readonly Set true if ability is informational only

Recommended patterns

  • Namespace IDs (e.g. my-plugin:feature.edit).
  • Treat IDs as stable API; changing IDs is a breaking change.
  • Use input_schema and output_schema for validation and to help AI agents understand usage.
  • Always include a permission_callback for abilities that modify data.

References

Source: SKILL.md on GitHub

No alerts17d4 checks · Risk SAFE
  • Gen Agent Trust Hub17d

    The skill is safe and follows WordPress development best practices. It utilizes official WordPress APIs and provides security recommendations such as implementing permission callbacks and namespacing IDs.

  • Socket17d

    No alerts

  • Snyk17d

    Risk: LOW · No issues

  • Runlayer7mo

    2/3 files flagged

Signed by skilld at 95e374f. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 5 months ago.

Dormantupdated 9 months ago
Other metadata
compatibility
Targets WordPress 6.9+ (PHP 7.2.24+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.
  • wordpress
  • abilities-api
  • rest-api
  • php
  • javascript
  • permissions
  • wp-cli

README badge

README badge for automattic/agent-skills/wp-abilities-api

Registers and exposes WordPress abilities (permissions/capabilities) via PHP hooks and REST endpoints, enabling client-side permission checks through the @wordpress/abilities library. Targets WordPress 6.9+ and handles ability registration, categorization, REST exposure, and consumption in JavaScript.

Generated from the current SKILL.md.

What WordPress versions does this skill support?
WordPress 6.9+ with PHP 7.2.24+. For earlier versions, you may need the Abilities API as a separate plugin or package rather than relying on core.
Do I need WP-CLI to use this skill?
Some workflows require WP-CLI, but it is not universally required. Basic ability registration and REST exposure can work without it.
How do I make an ability visible to JavaScript clients?
Set `meta.show_in_rest: true` when registering the ability in PHP, then consume it on the client side using the `@wordpress/abilities` package.
Can I use this skill for WordPress core work, or only plugins and themes?
The skill works for core, plugins, and themes. Check the target WordPress version and whether Abilities API is expected from core or as a plugin before starting.
What should I do if an ability is registered but doesn't appear in the REST API?
Verify that `meta.show_in_rest` is enabled, the registration code is running on the correct hook, and the ability ID and category are correctly set. Check REST endpoints under `wp-abilities/v1` directly to confirm exposure.

Generated from the current SKILL.md. These answers refresh after source changes.