Getting it into your agent
One page per mod, every tool's command on it. A separate URL per tool would split the same page into five that compete with each other.
npx skills add dr-robert-li/cowork-wordpress-expert --skill diagnostic-db-autoloadgit clone --depth 1 https://github.com/dr-robert-li/cowork-wordpress-expertWrote this? Show the measurements
A badge with what this costs and how it scanned, read live from this page, so it follows the numbers instead of freezing them. Markdown for a README, HTML for a documentation site or a project page.
[](https://agentmods.dev/skills/dr-robert-li/cowork-wordpress-expert/diagnostic-db-autoload)<a href="https://agentmods.dev/skills/dr-robert-li/cowork-wordpress-expert/diagnostic-db-autoload"><img src="https://agentmods.dev/badge/skills/dr-robert-li/cowork-wordpress-expert/diagnostic-db-autoload/github.svg" alt="Measured on agentmods" height="20"></a>Or the 80×15 button, for a site that already has a row of RSS and ATOM ones. Only the verdict fits; the numbers stay here.
<a href="https://agentmods.dev/skills/dr-robert-li/cowork-wordpress-expert/diagnostic-db-autoload"><img src="https://agentmods.dev/badge/skills/dr-robert-li/cowork-wordpress-expert/diagnostic-db-autoload.svg" alt="Reviewed on agentmods" width="80" height="20"></a>What it costs to keep this loaded
Counted locally with the o200k_base tokenizer, which is exact for GPT models; Claude uses its own tokenizer and its counts differ. Treat this as one consistent yardstick across the catalogue rather than a bill. Prices are per million input tokens.
| Model | Per session | Once invoked |
|---|---|---|
| Fable 5.1 | $0.00067 | $0.04016 |
| Opus 5 | $0.00034 | $0.02008 |
| Sonnet 5 | $0.00013 | $0.00803 |
| Haiku 4.5 | $0.00007 | $0.00402 |
Grade A, and why
diagnostic-db-autoload scanned grade A with 0 findings against 26 rules in 11 categories — prompt injection, anti-refusal, data exfiltration, privilege escalation, supply chain, agent snooping, system-prompt leakage, SSRF and excessive agency — measured 11d ago.
A static scan of the body, not an audit. Every finding is printed with the line that produced it so you can judge whether it matters here. A mod is markdown that instructs an agent; that is exactly why what it instructs is worth reading.
Nothing flagged
None of the 26 patterns this scan looks for appear in this file: no shell pipes, no recursive deletes, no credential paths, no hidden text, no instruction-override or anti-refusal phrasing, no agent-config snooping. That is not a guarantee, it is the absence of the things that are checkable.
How it starts
The opening of the file, as written. The whole thing — 338 lines — stays where its author put it; the contents beside it link to each section on GitHub.
Diagnostic: Autoload Bloat Analysis
You analyze the WordPress options table for autoload bloat — data loaded on every page request — and identify large autoloaded options with plugin attribution to help pinpoint which plugins are contributing to database performance overhead.
Overview
WordPress stores site settings in the wp_options table. Options marked autoload='yes' are loaded into memory on every single page request, regardless of whether they are needed. This means:
- A site with 5MB of autoloaded options loads 5MB of data on every page view
- Large autoloaded options slow down every request, including admin pages and REST API calls
- Common culprits: Yoast SEO caches, Elementor CSS data, WooCommerce settings, transient data accidentally marked autoload
The WordPress community benchmark for healthy autoload size is under 900KB. WordPress 6.6 introduced a built-in Site Health warning at 800KB. Sites above 2MB typically experience measurable latency on every request.
How It Works
Prerequisites
Before running checks, you need:
- Site connection profile from
sites.json(loaded by CoWork or /diagnose) WP_CLI_PREFIXset by the /diagnose command's Source-Type Routing sectionWP_CLI_AVAILABLE=true(this skill requires WP-CLI for all checks)
If WP_CLI_AVAILABLE is false, return a single Warning finding and stop.
Step 1: Dynamic Table Prefix Retrieval
Never hardcode wp_. Always retrieve the prefix dynamically before running any queries:
# Primary method: wp db prefix (most authoritative — reflects active DB handler)
TABLE_PREFIX=$($WP_CLI_PREFIX db prefix 2>/dev/null | tr -d '[:space:]')
# Fallback: wp config get table_prefix
if [ -z "$TABLE_PREFIX" ]; then
TABLE_PREFIX=$($WP_CLI_PREFIX config get table_prefix 2>/dev/null | tr -d '[:space:]')
fi
# If both fail, cannot proceed
if [ -z "$TABLE_PREFIX" ]; then
echo '[{"id":"DBHL-AUTOLD-ERR","severity":"Warning","category":"Database Health","title":"Could not determine table prefix","summary":"The autoload analysis could not run because the database table prefix could not be retrieved.","detail":"Both wp db prefix and wp config get table_prefix returned empty results. This may indicate a database connection failure or WP-CLI misconfiguration.","location":"wp_options table","fix":"Verify that WP-CLI can connect to the database by running: wp db check. Check the site connection profile and ensure WP-CLI has valid database credentials."}]'
exit 0
fi
What this file has done since we first saw it
Hashed on every crawl. A supply-chain change to an agent config is a question of when, not whether, so the history is kept rather than the latest state alone.
- 11d ago First seen · 338 lines · 67 tokens per session scan A 24f8c5a97cd2
diagnostic-db-autoload is a skill published in the GitHub repository dr-robert-li/cowork-wordpress-expert (28 stars, last pushed 6mo ago), licensed MIT. It adds 67 tokens to every session and 4,016 once invoked, about $0.0003 per session on Opus 5. A static security scan graded it A with 0 findings. No closer match exists in the catalogue, so it is treated as the original; first seen 2026-08-30.
Other skills, from other repositories
fix-failing-tests
Diagnose a failing test in the googleapis/mcp-toolbox repo and land a fix by reasoning from the actual error: read the failure, reproduce it, shrink it until the cause is forced into the open, then fix the cause. Use this whenever a test or CI job is red, a build breaks after a change, many packages fail at once, or a…
triage-issues
Triage GitHub issues in the googleapis/mcp-toolbox repo: propose the correct labels (type / priority / product / status), check for duplicates, verify a bug has enough info to act on, and draft a triage comment. Use whenever a maintainer asks you to triage, label, categorize, prioritize, or "look at" an issue (or a…
postgresql-indexing
PostgreSQL indexing best practices for Prowler: index design, partial indexes, partitioned table indexing, EXPLAIN ANALYZE validation, concurrent operations, monitoring, and maintenance. Trigger: When creating or modifying PostgreSQL indexes, analyzing query performance with EXPLAIN, debugging slow queries, reviewing…
graphjin-eval
Create, extend, run, baseline, and diagnose GraphJin agent evaluations through the graphjin eval CLI.
axiom-audit-grdb-performance
Use when the user mentions GRDB performance review, slow GRDB queries, app-group database setup audit, a ValueObservation that stopped updating, or pre-release GRDB scan.
django-perf-review
Django performance code review. Use when asked to "review Django performance", "find N+1 queries", "optimize Django", "check queryset performance", "database performance", "Django ORM issues", or audit Django code for performance problems.