Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
git clone --depth 1 https://github.com/dr-robert-li/cowork-wordpress-expertWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/plugins/dr-robert-li/cowork-wordpress-expert/cowork-wordpress-expert)<a href="https://agentmods.dev/plugins/dr-robert-li/cowork-wordpress-expert/cowork-wordpress-expert"><img src="https://agentmods.dev/badge/plugins/dr-robert-li/cowork-wordpress-expert/cowork-wordpress-expert.svg" alt="Measured on agentmods" height="20"></a>Grade A, and why
wordpress-expert scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 8d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 193 lines — stays where its author put it; the contents beside it link to each section on GitHub.
{
"name": "wordpress-expert",
"version": "3.1.0",
"description": "Expert WordPress diagnostics and site builder: structured investigations with intake questioning, site reconnaissance, parallel execution, findings verification, WordPress site generation as Local WP importable zips, and interactive modification sessions.",
"author": {
"name": "Robert Li"
},
"commands": {
"batch": {
"description": "Run diagnostics across multiple saved site profiles with comparison matrix",
"status": "implemented"
},
"build": {
"description": "Build a WordPress site — blank install, natural language, visual design, or URL clone — packaged as Local WP importable zip",
"status": "implemented"
},
"connect": {
"description": "Connect to a WordPress site via SSH, detect WP-CLI, sync files, and save profile",
"status": "implemented"
},
"diagnose": {
"description": "Run diagnostic suite with full, security-only, code-only, or performance modes on connected WordPress sites",
"status": "implemented"
},
"investigate": {
"description": "Full-workflow investigation: intake questioning, site scouting, smart skill planning, parallel execution, and findings verification",
"status": "implemented"
},
"modify": {
"description": "Start an interactive modification session for any WordPress directory — iterate on changes conversationally with git commits per step and a versioned zip on completion",
"status": "implemented"
},
"status": {
"description": "View connected sites, sync status, diagnostic health summaries, and manage site profiles (list, remove, default, rename)",
"status": "implemented"
}
},
"skills": {
"accessibility": {
"description": "WCAG compliance and data privacy requirements evaluation for WordPress sites",
"status": "implemented"
},
"build-content": {
"description": "Install relevant WP.org plugins, What it installs
The manifest is a name and a version. 54 skills travel with it, and installing the plugin installs all of them — 2,586 tokens a session between them. Each is measured on its own page, and each can be installed alone.
- Skill build-visual A 48 tokens
- Skill build-modify A 36 tokens
- Skill diagnostic-architecture A 81 tokens
- Skill build-content A 32 tokens
- Skill diagnostic-wpcli-profile A 65 tokens
- Skill build-setup A 27 tokens
- Skill diagnostic-code-quality A 51 tokens
- Skill diagnostic-cron-analysis A 52 tokens
- Skill diagnostic-db-autoload A 67 tokens
- Skill diagnostic-db-revisions A 93 tokens
- Skill diagnostic-db-transients A 78 tokens
- Skill diagnostic-file-permissions A 54 tokens
- Skill diagnostic-malware-scan A 49 tokens
- Skill diagnostic-performance-n1 A 54 tokens
- Skill reporting A 39 tokens
- Skill trend-tracker A 78 tokens
- Skill wordpress-block-theming A 41 tokens
- Skill build-git A 31 tokens
- Skill build-theme A 47 tokens
- Skill diagnostic-arch-narrative A 82 tokens
- Skill diagnostic-config-security A 35 tokens
- Skill diagnostic-https-audit A 56 tokens
- Skill diagnostic-user-audit A 27 tokens
- Skill diagnostic-version-audit A 53 tokens
- Skill testing A 43 tokens
- Skill accessibility A 31 tokens
- Skill design-systems A 42 tokens
- Skill report-generator A 45 tokens
- Skill scan-reviewer A 27 tokens
- Skill site-scout A 31 tokens
- Skill site-specification A 34 tokens
- Skill intake A 30 tokens
- Skill security-analysis A 36 tokens
- Skill wp-interactivity-api A 51 tokens
- Skill wp-patterns A 39 tokens
- Skill performance A 36 tokens
- Skill plugin-conflicts A 33 tokens
- Skill wp-playground A 60 tokens
- Skill code-quality A 38 tokens
- Skill wp-block-development A 67 tokens
- Skill wp-performance A 59 tokens
- Skill wp-rest-api A 61 tokens
- Skill wp-abilities-api A 59 tokens
- Skill wp-block-themes A 42 tokens
- Skill wp-phpstan A 47 tokens
- Skill wp-plugin-development A 50 tokens
- Skill wp-wpcli-and-ops A 55 tokens
- Skill wpds A 28 tokens
- Skill wordpress-router A 67 tokens
- Skill wp-project-triage A 50 tokens
- Skill build-scaffold B 30 tokens
- Skill diagnostic-core-integrity B 24 tokens
- Skill build-scrape C 53 tokens
- Skill build-mcp C 42 tokens
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 8d ago First seen · 193 lines scan A 6e8c1019bda3
wordpress-expert is a plugin published in the GitHub repository dr-robert-li/cowork-wordpress-expert (28 stars, last pushed 6mo ago), licensed MIT. Its token cost is not measured: this kind of file is read by the harness, not the model. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other plugins, from other repositories
data-table-filters
Install and wire up data-table-filters — filterable, sortable React data tables with server-side filtering, faceted counts, infinite scroll, and virtualization, delivered as shadcn registry blocks.
app-starter
Bootstrap new Next.js, Flutter, and FastAPI apps with current packages, no deprecated APIs, and a consistent house style. Ships skills nextjs-app, flutter-app, and fastapi-app.
app-builder
Development, customization, testing, and deployment skills for Adobe App Builder projects, including the Workfront UI-extension suite (skills/appbuilder-workfront).
contentful
Contentful apps, API, migration, and personalization skills.
hypervibe
Bootstrap a full-stack T3 project (Next.js + tRPC + Drizzle + Tailwind + shadcn/ui) with modular addons for database, auth, payments, email, storage, i18n, analytics, domain, and SEO. Deploys to Vercel with GitHub integration.
fuse-nextjs
Expert Next.js 16 + React 19 with App Router, Server Components, Prisma 7, and Better Auth.