Speckit.wordpress
bro-skills - Spec-Driven Development CLI
npx -y skills add wedabro/bro-skills --skill speckit.wordpressAssembled from the repository path, not quoted from the project. Check it against their README if it does not work.
One thing to look at
- 2 stars2 stars. Stars are a popularity signal and not a quality one, but at this level it is likely that nobody has read this closely except its author, and you would be relying on your own review.
What its author says it does
Copied from the file, not written here
WordPress Master Architect - Expert in developing core-compliant Themes, Gutenberg Blocks (apiVersion 3), Plugins, Interactivity API, REST API endpoints, WP-CLI automation, and Performance profiling/database optimization.
SKILL.md
6.0 KB, ~1.3k tokens by cl100k_base, as published. Nobody here has run it
🎯 Mission
Build industrial-grade, secure, performant, and highly interactive WordPress products (Themes/Plugins/Blocks), strictly adhering to official core developer guidelines and Spec-Driven Development.
📋 Protocol
1. Project Triage & Environment
- Docker-First Environment: Always build/run WordPress inside a containerized setup (WordPress + MySQL/MariaDB).
- Core Triage: Detect project type (theme vs. plugin vs. full site) and PHP/Node/Composer/npm tooling setup before making changes.
- Theme Pathing: Place theme code under
wp-content/themes/[theme-slug]/. - Plugin Pathing: Place plugin code under
wp-content/plugins/[plugin-slug]/orwp-content/mu-plugins/(for must-use plugins).
2. Plugin Development Protocol
- Architecture: Keep a single main plugin bootstrap file containing standard headers. Avoid loading heavy side-effects on file load; defer execution using hooks.
- Hooks & Lifecycle: Register activation/deactivation hooks at the top-level scope (not inside other hooks). Implement safe uninstallation using
uninstall.phporregister_uninstall_hook. - Admin UI & Settings: Prefer the official Settings API (
register_setting,add_settings_section,add_settings_field) with propersanitize_callbackfor options storage.
3. Block (Gutenberg) Development Protocol
- Metadata-Driven: Define blocks using
block.jsonwithapiVersion: 3(WordPress 6.9+ standard) to ensure correct block iframe behavior. - Edit/Save/Render Patterns:
- In the Editor: Wrap component markup with
useBlockProps(). - Static blocks (markup saved in database): Use
useBlockProps.save()insave(). - Dynamic blocks (server-rendered): Set
"render": "file:./render.php"inblock.json(or use PHPrender_callback) and keepsave()returningnull. Useget_block_wrapper_attributes()in PHP.
- In the Editor: Wrap component markup with
- Block Composition: Use
useInnerBlocksProps()for container-like blocks. - Deprecations & Migrations: If modifying saved markup/attributes, add a
deprecatedarray (newest to oldest) in the client script to avoid "Invalid block" errors.
4. Block Themes & theme.json Protocol
- Global Settings & Styles: Use
theme.jsonto define typography scales, color presets, layout constraints, and per-block custom styles. - Templates & Template Parts: Place HTML templates under
templates/and parts underparts/. Do not nest parts in subdirectories. - Style Variations: Define style presets in JSON files inside
styles/. Remember that once a user selects a variation in the editor, it is saved in the database, overriding file-level changes. - Patterns: Prefer theme-registered patterns located under
patterns/*.phpfor modular reuse.
5. Interactivity API & Hydration Protocol
- Server-Side Rendering (SSR) first: Always pre-render interactive markup on the server to prevent Layout Shift (CLS) and ensure SEO indexability.
- Directive Processing: Enable server-side directive parsing by declaring
"interactivity": trueinside the block's"supports"config. - State Initialization:
- Global state (PHP): Define initial state using
wp_interactivity_state('pluginNamespace', $initialStateArray). - Local context (PHP): Output context wrapper attributes using
wp_interactivity_data_wp_context($contextArray).
- Global state (PHP): Define initial state using
- Directives: Use
data-wp-interactive,data-wp-context,data-wp-bind,data-wp-on, and custom store stores. Avoid the deprecateddata-wp-ignoredirective.
6. REST API & Endpoint Registration Protocol
- Route Registration: Register custom REST routes during the
rest_api_inithook usingregister_rest_route(). - Namespace: Use a unique namespace format like
vendor/v1(avoidwp/v2unless core). - Authentication & Validation:
- Always enforce a
permission_callback(use__return_truefor public endpoints). - Perform authorization checks via WordPress user capabilities (e.g.
current_user_can('manage_options')). - Validate request parameters via request schema/args configurations using
validate_callbackandsanitize_callback.
- Always enforce a
- Response: Enclose responses inside
rest_ensure_response()orWP_REST_Response. UseWP_Errorwith explicit HTTP status codes for errors.
7. WP-CLI Operations & Scripting
- Ops Safety: Perform database exports/backups before executing destructive commands.
- Site Targeting: Enforce
--path=<wp-path>and, for multisites,--url=<site-url>to target correct environments. - URL Migration: Use
wp search-replace --dry-runto inspect changes before running URL replacements on serialized data. - Automation: Build repeatable operations scripts using
wp-cli.ymlconfiguration defaults.
8. Performance Profiling & Database Optimization
- Database & Queries: Reduce total queries, avoid N+1 query patterns. Prefer
WP_Queryorget_postsover raw SQL. Use$wpdb->prepare()if raw SQL is necessary. - Autoload Bloat: Audit and optimize autoloaded options. Large data arrays should be converted to transients or standard non-autoloaded options.
- Caching: Integrate persistent object caching (
wp_cache_set,wp_cache_get) for heavy database operations. - Remote API calls: Enforce HTTP request timeouts (
wp_remote_get,wp_remote_post) and cache the results to prevent render blocking.
🚫 Guard Rails (Security & Anti-patterns)
- Sanitize & Escape: Validate/sanitize input early, escape output late (use
esc_html,esc_attr,esc_url,wp_kses). - CSRF Prevention: Implement and verify nonces on all admin actions, AJAX hooks, and REST requests.
- Core Hook Safety: Do not modify Core files or third-party plugin codes directly; always utilize actions, filters, or child themes.
- Plugin Sourcing: Strictly forbid using cracked, nulled, or unverified plugins.
What ships with it
Read from the repository
Just SKILL.md. No reference files, no scripts.
Gives 0 of the 12 instructions most performance cost skills give in ~1.3k tokens
Counted across 803 of the 1,058 authors here whose files we hold, read 2026-08-07
- Keep skill files under 500 lines or tokensin 82 of 803, across 16 files
- Use imperative form in instructionsin 80 of 803, across 9 files
- Draft assertions while test runs are in progressin 75 of 803, across 9 files
- Create two to three realistic test promptsin 74 of 803, across 9 files
- Write skill descriptions to be pushyin 72 of 803, across 7 files
- Save test cases to evals JSONin 72 of 803, across 6 files
- Ask questions about edge cases and input formatsin 72 of 803, across 7 files
- Save timing data immediately when runs completein 70 of 803, across 5 files
- Include all trigger conditions in the skill descriptionin 69 of 803, across 3 files
- Launch all test runs in a single turn or simultaneouslyin 69 of 803, across 3 files
- Capture intent before writing a skillin 67 of 803, across 1 file
- Import directly instead of barrel filesin 52 of 803, across 15 files
Said here and by no other author read
- defer plugin execution using hooks
- register activation hooks at top-level scope
- define blocks using block.json with apiVersion 3
- pre-render interactive markup on the server
- register rest routes during rest_api_init
- enforce permission_callback on all endpoints
Grouped from the skills themselves: near-identical wordings counted once, and counted by distinct author, so one author publishing three of these counts once. Length counted with cl100k_base; the agent that loads this file may tokenize it differently.