Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/automattic/pressship/infogit clone --depth 1 https://github.com/Automattic/pressshipWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00246 |
| Opus 5 | $0.00000 | $0.00123 |
| Sonnet 5 | $0.00000 | $0.00049 |
| Haiku 4.5 | $0.00000 | $0.00025 |
Grade A, and why
info scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
What it actually says
Info
pressship info
pressship info ./my-plugin
pressship info 16deza-table-cell-extras
pressship info https://wordpress.org/plugins/16deza-table-cell-extras/
pressship info --remote
pressship info ./my-plugin --remote
pressship info 16deza-table-cell-extras --json
info shows detailed metadata for a local plugin path or hosted WordPress.org plugin. With no argument, it inspects the current directory.
For local plugins, it reports headers and readme metadata: version, main file, readme path, text domain, WordPress and PHP requirements, stable tag, tags, contributors, license, and description.
For hosted plugins, it uses the public WordPress.org plugin info API and reports version, author, requirements, active installs, last updated date, rating, support status, tags, description, and download URL.
Use --remote to force the hosted WordPress.org plugin-store lookup. When the target is a local path or omitted, Pressship discovers the local plugin slug first, then fetches the WordPress.org store info for that slug.
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 24 lines · 0 tokens per session scan A 5f9e94a80ef5
info is a command published in the GitHub repository Automattic/pressship (51 stars, last pushed 20d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 246 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
wp-debug
Diagnose and fix WordPress block-theme failures — block validation errors, theme.json issues, missing patterns, DB template overrides, and PHP warnings.
wp-plugin-theme
Declare plugin dependencies and generate plugin-specific CSS and compatibility code for a block theme.
wp-block
Scaffold a custom WordPress block (block.json, edit.js, save.js or render.php, styles) ready to register inside a block theme.
wp-variation
Generate a WordPress block theme style variation (styles/.json) — dark mode, color palette swap, or font swap.
scaffold-wp-theme
Generate an empty, valid WordPress block theme scaffold from scratch — no source HTML required.
README
Project-scoped slash commands. Type / in a Claude Code session and the command's body becomes the agent's marching orders for that turn.