All skills
wordpress avatar

/wp-project-triage

@20324d2 official
by wordpresswordpress/agent-skills2.2k stars
327

Use when you need a deterministic inspection of a WordPress repository (plugin/theme/block theme/WP core/Gutenberg/full site) including tooling/tests/version hints, and a structured JSON report to guide workflows and guardrails.

Use this Skill: https://skilld.dev/gh/wordpress/agent-skills/wp-project-triage

This session only. Nothing lands on disk.

SKILL.md

≈62 tokens always: the name and description. ≈270 when used: this file. ≈1.1k more on demand in 1 file.

WP Project Triage

When to use

Use this skill to quickly understand what kind of WordPress repo you’re in and what commands/conventions to follow before making changes.

Inputs required

  • Repo root (current working directory).

Procedure

  1. Run the detector (prints JSON to stdout):
    • node skills/wp-project-triage/scripts/detect_wp_project.mjs
  2. If you need the exact output contract, read:
    • skills/wp-project-triage/references/triage.schema.json
  3. Use the report to select workflow guardrails:
    • project kind(s)
    • PHP/Node tooling present
    • tests present
    • version hints and sources
  4. If the report is missing signals you need, update the detector rather than guessing.

Verification

  • The JSON should parse and include: project.kind, signals, and tooling.
  • Re-run after changes that affect structure/tooling (adding theme.json, block.json, build config).

Failure modes / debugging

  • If it reports unknown, check whether the repo root is correct.
  • If scanning is slow, add/extend ignore directories in the script.

Source: SKILL.md on GitHub

1 warning9d5 checks · Risk SAFE
  • Gen Agent Trust Hub9d

    The skill is a WordPress project triage tool that identifies project types, versions, and tooling by scanning repository files. It functions as a standard developer utility and adheres to vendor resource patterns, though it does access sensitive configuration files and processes untrusted repository content, creating an indirect prompt injection surface.

  • Socket9d

    No alerts

  • Snyk9d

    Risk: LOW · No issues

  • Runlayer7mo

    3/3 files flagged

  • ZeroLeaks5mo

    Score: 93/100 · 2 sections analyzed

Signed by skilld at 20324d2. This ties the file your Agent reads to that commit on GitHub. It does not review the instructions.

Last checked against GitHub 2 days ago.

Activeupdated 3 months ago
Other metadata
compatibility
Targets WordPress 7.0+ (PHP 7.4.0+). Filesystem-based agent with bash + node. Some workflows require WP-CLI.
  • wordpress
  • php
  • plugin
  • theme
  • detection
  • schema
  • json
  • wp-cli
  • gutenberg
  • triage

README badge

README badge for wordpress/agent-skills/wp-project-triage

Inspects a WordPress repository (plugin, theme, block theme, WP core, or Gutenberg) and outputs structured JSON describing project kind, tooling, tests, and version hints. Use this before making changes to understand which commands and conventions apply to the codebase.

Generated from the current SKILL.md.

What WordPress versions does this skill support?
It targets WordPress 6.9+ with PHP 7.2.24+. The detector runs as a Node.js script and some workflows require WP-CLI.
What does the detector output?
A JSON report containing project.kind (plugin, theme, block theme, WP core, Gutenberg, or full site), signals (tooling and test hints), and version metadata to guide workflow decisions.
Do I need to specify the repo type myself?
No. The detector runs on the filesystem and automatically identifies whether you're in a plugin, theme, block theme, WordPress core, Gutenberg, or full-site repo.
What should I do if the detector reports 'unknown'?
Verify that the repo root is correct. If scanning is slow, consider adding or extending ignore directories in the detection script.
When should I re-run the detector?
Re-run after making changes that affect repo structure or tooling, such as adding theme.json, block.json, or build configuration files.

Generated from the current SKILL.md. These answers refresh after source changes.