CtrlK
BlogDocsLog inGet started
Tessl Logo

wp-abilities-audit

Audit a WordPress plugin's REST surface and produce a standardized audit document proposing Abilities API registrations. Produces a markdown doc with a YAML schema and prose sections that humans and agents can both consume when planning a registration rollout. Works on any WP plugin.

64

Quality

80%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

Fix and improve this skill with Tessl

tessl review fix ./skills/wp-abilities-audit/SKILL.md
SKILL.md
Quality
Evals
Security

Quality

Content

81%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured procedural skill: tight sequencing, an explicit verification checklist, failure modes with concrete remedies, and well-signaled one-level-deep references that all resolve within the bundle. The main weaknesses are mild redundancy in the opening and step 4, and a hard dependency on reference files in an external sibling skill that cannot be verified from this bundle.

DimensionReasoningScore

Conciseness

Efficient for its scope: no explaining of concepts Claude already knows, and every section instructs rather than narrates ('Record every controller class + file + REST base + routes in a Controller Inventory table'). Minor instances of over-explanation could be trimmed — the opening paragraph re-states the description, and the sanity-check paragraph in step 4 belabors the plumbing-vs-ability distinction ('The route may be useful to inventory; the proposed ability must represent a real user/operator question or action'). Fits anchor 4, not 5 (some sentences are redundant) and not 3 (the padding is minor, not whole unnecessary explanations).

4 / 5

Actionability

Instruction-only skill with concrete, specific guidance: exact field lists ('name, intent, backing, permission, return_type, effort (S/M/L)...'), an exact output format ('Last updated: YYYY-MM-DD HH:MM' header, YAML block, Controller Inventory table, 'Notes and Surprises' section), and explicit handling rules for edge cases (compound gates as '{read, write}', null line numbers paired with inherited_from). Per the scoring note, absent code is not penalized since the guidance is actionable; it stays at 4 rather than 5 because the executable mechanics and the copy-paste example all live in reference files rather than inline, and two referenced rule files are external to this bundle.

4 / 5

Workflow Clarity

A clearly sequenced 7-step procedure with inputs, prerequisites, an explicit 'Verification' checklist (schema conformance, gate typing, surfaced-gaps consistency, validator round-trip), a 'Failure modes / debugging' section for error recovery, and an 'Escalation' path. This matches the anchor with explicit validation steps and feedback loops; the audit is read-only output generation, so the destructive/batch cap does not apply. Not 4 — checkpoints are explicit and complete, not 'mostly present'.

5 / 5

Progressive Disclosure

Good structure: the body is a lean overview, and all three local references (controller-enumeration.md, audit-schema.md, capability-gate-tracing.md) exist in the bundle and are clearly signaled with 'Read X now' at the exact step that needs them, one level deep. It falls short of 5 because two references point outside the bundle into a sibling skill ('../wp-abilities-api/references/grouping-heuristic.md', '../wp-abilities-api/references/domain-vs-projection.md') that is not present here — a minor organization gap that breaks navigation if that skill isn't installed.

4 / 5

Total

17

/

20

Passed

Description

70%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A distinctive, specific description for a well-defined niche, with concrete actions stated in third person and no fluff. Its main weakness is the absence of an explicit 'Use when...' trigger clause, which leaves the invocation conditions only weakly implied.

Suggestions

Add an explicit trigger clause, e.g. 'Use when registering Abilities API abilities for a WordPress plugin, when no audit doc exists yet, or when scoping a multi-plugin abilities rollout.'

Include natural synonyms and variations users might say, such as 'REST endpoints', 'REST API surface', 'capabilities/permissions', and 'agent-readiness check', to broaden trigger coverage.

Briefly state what the audit inspects (controller inventory, capability gates, proposed ability shapes) so the 'what' reflects the doc's actual contents.

DimensionReasoningScore

Specificity

Names several concrete actions — 'Audit a WordPress plugin's REST surface', 'produce a standardized audit document proposing Abilities API registrations', 'Produces a markdown doc with a YAML schema and prose sections' — with minor gaps (it never says what the audit actually inspects, e.g. controllers or capability gates). Matches the 'lists several specific actions; minor gaps in coverage' anchor, not 5 (coverage of the audit's internals is missing) and not 3 (more than 1-2 concrete actions are given).

4 / 5

Completeness

The 'what' is clear and specific, but there is no 'Use when...' clause or equivalent explicit trigger guidance — 'when planning a registration rollout' describes the artifact's consumers, not when to invoke the skill. Per the judging guideline, a missing explicit trigger clause caps completeness at 3 ('clear what but when is missing or only weakly implied'); it is above 2 because the 'what' is fully explicit.

3 / 5

Trigger Term Quality

Good natural keyword coverage: 'WordPress plugin', 'WP plugin', 'REST surface', 'Abilities API', 'audit document', 'registration rollout' — the terms a user planning abilities adoption would say. A few natural variants are missing ('REST endpoints', 'capabilities/permissions', 'agent-readiness'), so it fits the 'good keyword coverage; a few natural terms missing' anchor rather than the comprehensive-synonyms anchor at 5, and is well above the generic-keyword anchors at 2-3.

4 / 5

Distinctiveness Conflict Risk

Occupies a clear niche — auditing a WordPress plugin's REST surface to propose Abilities API registrations — with distinct trigger terms that no generic skill would match. Minimal conflict risk; fits the 'clear niche with distinct triggers' anchor, clearly above the 'minor overlap risk with closely related skills' anchor at 4.

5 / 5

Total

16

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
WordPress/agent-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.