CtrlK
BlogDocsLog inGet started
Tessl Logo

wp-rest-api

Use when building, extending, or debugging WordPress REST API endpoints/routes: register_rest_route, WP_REST_Controller/controller classes, schema/argument validation, permission_callback/authentication, response shaping, register_rest_field/register_meta, or exposing CPTs/taxonomies via show_in_rest.

72

Quality

91%

Does it follow best practices?

Run evals on this skill

Adds up to 20 points to the overall score

View guide
SecuritybySnyk

Passed

No findings from the security scan

SKILL.md
Quality
Evals
Security

Quality

Content

85%Weight 40%Scale 1-5

Reviews the quality of instructions and guidance provided to agents. Good implementation is clear, handles edge cases, and produces reliable results.

A well-structured procedural skill: clear sequencing, explicit verification and debugging feedback loops, and exemplary progressive disclosure to real reference files. The main gaps are minor — duplicated reference pointers and the absence of a copy-paste code example for route registration.

Suggestions

Remove the duplicate 'Read references/routes-and-endpoints.md' and 'Read references/schema.md' pointers in section 1 (they are repeated in sections 2 and 3) to tighten token efficiency.

Add a minimal copy-paste-ready register_rest_route() example (namespace, route, args with permission_callback) either inline or in routes-and-endpoints.md so the core task has fully executable coverage.

Consider adding natural trigger synonyms like 'wp-json' or 'WP API' to the description to improve recall for users who use those phrasings.

DimensionReasoningScore

Conciseness

Lean, imperative bullets with no re-explanation of concepts Claude already knows (e.g., "Never read $_GET/$_POST directly inside endpoints; use WP_REST_Request"). Not 5: "Read references/routes-and-endpoints.md" and "Read references/schema.md" each appear twice within short spans — minor duplication that could be trimmed; not 3: there are no padded or unnecessary explanation sections.

4 / 5

Actionability

Concrete, executable guidance throughout — "use __return_true for public endpoints", "WP_REST_Server::READABLE/CREATABLE/EDITABLE/DELETABLE", "per_page is capped at 100", and a runnable triage command. Not 5: no copy-paste-ready PHP snippet for the core register_rest_route task, leaving a minor gap in executable coverage; not 3: the guidance is specific and directly executable, not pseudocode.

4 / 5

Workflow Clarity

A clearly sequenced procedure (triage → choose approach → register → validate → shape responses → auth → discovery) with an explicit Verification checklist ("/wp-json/ index includes your namespace", "OPTIONS on your route returns schema") and a Failure modes section mapping symptoms to causes and fixes. Not 4: validation checkpoints and error-recovery feedback are both explicit, matching the top anchor.

5 / 5

Progressive Disclosure

The body is an overview that points to six real, one-level-deep reference files (all present in ./references/), each clearly signaled at the relevant procedural step (e.g., "Read references/authentication.md" under Authentication). Not 4: the split is appropriate and navigation is easy with no buried or nested references.

5 / 5

Total

18

/

20

Passed

Description

92%Weight 40%Scale 1-5

Based on the skill's description, can an agent find and select it at the right time? Clear, specific descriptions lead to better discovery.

A strong, highly specific description that names concrete WP REST API surfaces and pairs them with an explicit 'Use when' trigger. Its only weakness is missing a few natural synonym phrasings (e.g., 'wp-json', 'WP API') that users might say.

DimensionReasoningScore

Specificity

The description enumerates multiple concrete capabilities — "register_rest_route, WP_REST_Controller/controller classes, schema/argument validation, permission_callback/authentication, response shaping, register_rest_field/register_meta, or exposing CPTs/taxonomies via show_in_rest" — giving comprehensive coverage of the domain's actions. Not 4: there are no meaningful coverage gaps across registration, validation, auth, and response shaping.

5 / 5

Completeness

Explicitly answers both: what (building/extending/debugging endpoints with an enumerated list of subtasks) and when ("Use when building, extending, or debugging WordPress REST API endpoints/routes"). Not 4: the 'when' clause is fully explicit and paired with concrete trigger phrases, matching the top anchor.

5 / 5

Trigger Term Quality

Good natural-term coverage ("WordPress REST API endpoints/routes", "building, extending, or debugging", "authentication") plus exact function names users would quote. Not 5: common variations like "wp-json", "WP API", or "REST controller" are missing; not 3: coverage goes well beyond a few relevant keywords.

4 / 5

Distinctiveness Conflict Risk

Clear niche (WordPress REST API) with distinctive function-level triggers (register_rest_field, show_in_rest, permission_callback) that are unlikely to fire for unrelated skills. Not 4: overlap risk is minimal, not just minor.

5 / 5

Total

19

/

20

Passed

Validation

100%

Checks the skill against the spec for correct structure and formatting. All validation checks must pass before discovery and implementation can be scored.

Validation — 16 / 16 Passed

Validation for skill structure

No warnings or errors.

Repository
WordPress/agent-skills
Reviewed

Table of Contents

Is this your skill?

If you maintain this skill, you can claim it as your own. Once claimed, you can manage eval scenarios, bundle related skills, attach documentation or rules, and ensure cross-agent compatibility.