Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx agentmods add commands/automattic/pressship/releasegit clone --depth 1 https://github.com/Automattic/pressshipWhat it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5 | $0.00000 | $0.00574 |
| Opus 5 | $0.00000 | $0.00287 |
| Sonnet 5 | $0.00000 | $0.00115 |
| Haiku 4.5 | $0.00000 | $0.00057 |
Grade A, and why
release scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 2d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 64 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Release
pressship release ./my-plugin --slug my-plugin
WordPress.org initial review uses a zip upload. Approved plugin releases use SVN. release keeps the approved-plugin workflow explicit and is equivalent to publish --release.
If svn is missing, Pressship detects your operating system and package manager, then asks before installing Subversion. Use --no-install-svn when you want it to fail with manual install instructions instead.
release will:
- verify the plugin with readme validation and Plugin Check;
- checkout or update
https://plugins.svn.wordpress.org/<slug>; - confirm the local version has not already been released as
tags/<version>; - sync packaged plugin files into
trunk/; - sync
.wordpress-org/into SVNassets/when the folder exists; - create
tags/<version>from trunk; - show
svn status; - ask for confirmation;
- commit the release with a generated WordPress.org SVN password.
Use --no-verify only when you intentionally want to skip readme validation and Plugin Check before committing to SVN.
If the SVN tag already exists, Pressship stops with a “No version change detected” message. Bump the plugin version before publishing again.
When running from a working copy created by pressship get, Pressship uses trunk/ as the plugin directory and the checkout root as the SVN working copy:
pressship get my-plugin ./my-plugin
cd ./my-plugin
pressship version patch
pressship publish
SVN Password
Pressship infers the SVN username from the saved WordPress.org login when possible. If no SVN password has been saved yet, it will direct you to:
https://profiles.wordpress.org/<username>/profile/edit/group/3/?screen=svn-password
Generate the password there, paste it into Pressship once, and it will be saved locally at ~/.config/pressship/svn-credentials.json for future release commits.
Options
pressship release ./my-plugin --slug my-plugin
pressship release ./my-plugin --version 1.2.3
pressship release ./my-plugin --username WpOrgUser
pressship release ./my-plugin --message "Release 1.2.3"
pressship release ./my-plugin --wp-path /path/to/wordpress
pressship release ./my-plugin --ignore "assets/**/*.mp4"
pressship release ./my-plugin --dry-run
pressship release ./my-plugin --no-verify
pressship release ./my-plugin --yes
pressship release ./my-plugin --no-install-svn
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 2d ago First seen · 64 lines · 0 tokens per session scan A c1a4798d7fbb
release is a command published in the GitHub repository Automattic/pressship (51 stars, last pushed 20d ago), licensed MIT. It costs nothing until one of its globs matches a file; then it loads 574 tokens. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other commands, from other repositories
wp-debug
Diagnose and fix WordPress block-theme failures — block validation errors, theme.json issues, missing patterns, DB template overrides, and PHP warnings.
wp-plugin-theme
Declare plugin dependencies and generate plugin-specific CSS and compatibility code for a block theme.
wp-variation
Generate a WordPress block theme style variation (styles/.json) — dark mode, color palette swap, or font swap.
wp-block
Scaffold a custom WordPress block (block.json, edit.js, save.js or render.php, styles) ready to register inside a block theme.
scaffold-wp-theme
Generate an empty, valid WordPress block theme scaffold from scratch — no source HTML required.
README
Project-scoped slash commands. Type / in a Claude Code session and the command's body becomes the agent's marching orders for that turn.