Skill-Audit-Bericht

wp-github-actions Audit-Bericht.

Sets up GitHub Actions CI/CD workflows for WordPress plugins — coding standards (WPCS/PHPCS), PHP/JS/CSS linting, PHPUnit testing, static analysis (PHPStan), Composer security scanning, WordPress Playground PR previews, and automated deployment to WordPress.org. ALWAYS use this skill when a user wants to create, add, set up, or configure GitHub Actions, CI/CD, automated checks, or deployment workflows for a WordPress plugin — even if they don't use the exact phrase "GitHub Actions". This includes any request to: add automated coding standards or PHPCS/WPCS checks to a WP plugin repo; set up linting (PHP, JS, CSS) for a WordPress plugin; configure PHPUnit testing in CI for a plugin; auto-deploy a plugin to WordPress.org from GitHub; add Playground previews to pull requests; add security scanning or static analysis to a plugin pipeline; or generally "add CI", "add automated checks", "set up workflows", or "automate" anything related to a WordPress plugin's GitHub repository. Also trigger

Experimentell · PrüfenPrüfung nötigErstellt 11. Okt. 2026Heuristisches Metadaten-Audit
71
Audit
66
Vertrauen
61
Qualität
77
Sicherheit
76
Maintain
92
Installieren

OpenAgentSkill Trust Score

66
Manuelle Prüfung

OpenAgentSkill Trust Score

The Trust Score helps an agent decide whether a skill is safe enough to shortlist before installation.

GitHub-Akzeptanz

Warnung

48

97 GitHub-Stars

Star-/Fork-Aktivität

Warnung

48

97 Stars und 10 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbar

Aktuelle Wartung

Info

76

3 Monate seit dem letzten Push

Lizenzklarheit

Bestanden

86

MIT

README/SKILL.md-Vollständigkeit

Bestanden

86

Metadaten enthalten ausreichend Nutzungs- und Workflow-Kontext

Abhängigkeits-/Laufzeitrisiko

Info

72

Zugriff auf Zugangsdaten oder Umgebungsvariablen

Installationsverfügbarkeit

Bestanden

92

npx skills add jdevalk/skills --skill wp-github-actions

Sicherheit des Installationsbefehls

Bestanden

92

Standard-Paket- oder Laufzeit-Installationspfad

Berechtigungsumfang

Warnung

60

secrets or environment access, filesystem or document access

Repository-Nachweis

Bestanden

86

https://github.com/jdevalk/skills/tree/main/wp-github-actions

Prüfstatus

Info

66

KI-Prüfdaten verfügbar

Agent-validierte Ergebnisse

Info

54

Noch keine Agent-Ergebnisdaten

Prüfungen

Installations- und Adoptionsprüfung

5 Bestanden · 13 Prüfung nötig

Installationspfad

92

Bestanden

npx skills add jdevalk/skills --skill wp-github-actions

Repository

88

Bestanden

https://github.com/jdevalk/skills/tree/main/wp-github-actions

Lizenz

86

Bestanden

MIT

Wartung

76

Prüfen

3 Monate seit dem letzten Push

KI-Prüfung

55

Prüfen

The SKILL.md description is extremely verbose and uses 'ALWAYS' language, which may cause over-triggering in unrelated contexts, but this is not a security or quality blocker.

README/SKILL.md-Vollständigkeit

86

Bestanden

Usable description available

Abhängigkeitsrisiko

72

Prüfen

Zugriff auf Zugangsdaten oder Umgebungsvariablen

Sicherheit des Installationsbefehls

92

Bestanden

Standard-Paket- oder Laufzeit-Installationspfad

Berechtigungsumfang

60

Prüfen

secrets or environment access, filesystem or document access

Star-/Fork-Aktivität

48

Beheben

97 Stars und 10 Forks; Issue-Aktivität ist in den aktuellen Metadaten nicht verfügbar

Akzeptanz

68

Info

97 GitHub-Stars

Warnungen

  • Permission surface may require sandboxing
  • The SKILL.md description is extremely verbose and uses 'ALWAYS' language, which may cause over-triggering in unrelated contexts, but this is not a security or quality blocker.
  • The skill does not explicitly state limitations or safe operating boundaries (e.g., not to run generated workflows on untrusted code), though the workflow templates are standard and safe.
  • Quality score needs review
  • Permission surface needs review: secrets or environment access, filesystem or document access
  • GitHub adoption: 97 GitHub stars
  • Stars/forks activity: 97 stars, 10 forks; issue activity unavailable in current metadata
  • Permission surface: secrets or environment access, filesystem or document access

Methode

This report combines public metadata, AI review output, repository freshness, install readiness, OpenAgentSkill events, quality scoring, trust checks, and the agent safety gate. It is not a full source-code security review.

Nahe Optionen vergleichen

Ähnliche Skills als Nächstes prüfen