CtrlK
BlogDocsLog inGet started
Tessl Logo

wp-abilities-verify

Verify a WordPress plugin's Abilities API registrations: enumerate abilities, check that callback behavior matches each annotation's claim (the adversarial readonly-but-writes detection), validate permissions and schemas, and validate audit documents produced by wp-abilities-audit.

69

Quality

87%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

92%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

An exemplary instruction-skill body: a crisply sequenced adversarial verification workflow with explicit verdict semantics, error recovery, and boundary-setting (Out of scope), backed by a well-organized one-level-deep reference bundle. The only tightening opportunity is minor redundancy between the modes overview and the procedure steps.

DimensionReasoningScore

Conciseness

The body is dense and imperative with no explanations of concepts Claude already knows — every section carries skill-specific judgment (e.g. "Source-only → FAIL (registration not firing). Runtime-only → WARN"). It is not 5 because a few asides are slightly redundant — the idempotent definition and the "signal, not a verdict" caveat each appear in both the modes section and step 4 — and not 3 because almost every token is non-inferable guidance.

4 / 5

Actionability

Fully actionable for an instruction-only skill: exact tool invocation ("rg --multiline --pcre2"), concrete search pattern ("wp_register_ability("), per-annotation check rules, a literal suppression syntax ("// verify-ignore: <annotation> -- <reason>"), and a copy-paste report template. The scoring note's exception applies — absence of code is not penalized when the guidance is this concrete.

5 / 5

Workflow Clarity

A seven-step numbered procedure, each step pointing at its reference file, with explicit validation semantics ("A single FAIL → top-line FAIL; WARNs without FAILs → WARN; otherwise PASS"), a failure-modes section with concrete recovery actions ("Re-run wp-project-triage, then fix the env. Don't fall back silently"), and escalation guidance. This matches the anchor-5 shape: clear sequence, explicit checkpoints, feedback loops.

5 / 5

Progressive Disclosure

The body is a lean overview and every step clearly signals its one-level-deep reference ("Read references/annotation-correctness.md", etc.); all six referenced files exist in the bundle, and bulk detail is appropriately split out of SKILL.md. The cross-skill pointers (../wp-abilities-api/references/...) are also one level deep, so navigation is easy throughout.

5 / 5

Total

19

/

20

Passed

Description

75%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A specific, well-scoped description with strong concrete action verbs and low conflict risk, written in third person without padding. Its one real weakness is the complete absence of "when to use" trigger guidance, which both caps completeness and leaves natural trigger phrasings underexploited.

Suggestions

Append an explicit trigger clause, e.g. "Use when verifying a WordPress plugin's Abilities API registrations before landing a PR, when a refactor may have changed readonly behavior, or when validating an audit doc from wp-abilities-audit."

Work natural trigger phrasings into that clause — "abilities", "annotations", "callback claims", "permission gates" — so users' varied wording matches the description.

State the two modes (static/runtime) in one clause so users asking for a no-env check know the skill applies.

DimensionReasoningScore

Specificity

The description lists multiple concrete actions — "enumerate abilities", "check that callback behavior matches each annotation's claim (the adversarial readonly-but-writes detection)", "validate permissions and schemas", "validate audit documents" — giving comprehensive coverage of the skill's capabilities. It exceeds anchor 4 because the action list is complete rather than having minor gaps.

5 / 5

Completeness

The "what" is explicit and precise, but there is no "Use when..." clause or any equivalent trigger guidance — "when" is at best weakly implied from the what, which caps completeness at 3 per the judging guidelines. It is not 4 because the when is entirely absent rather than merely imprecise.

3 / 5

Trigger Term Quality

Good natural keyword coverage: "WordPress plugin", "Abilities API", "abilities", "permissions", "schemas", "audit" are all phrases a user needing this skill would say. It falls short of anchor 5 because common variations like "annotations", "callbacks", or "registrations" as standalone triggers are absent, and it is clearly above anchor 3 since the core natural terms are all present.

4 / 5

Distinctiveness Conflict Risk

It occupies a clear niche — verifying a WordPress plugin's Abilities API registrations — and even names its sibling skill "wp-abilities-audit" to scope the audit-validation half, minimizing conflict risk. No neighboring anchor fits better.

5 / 5

Total

17

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
WordPress/agent-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.