WordPress
wp-vip-code-review
Review WordPress VIP code changes
Reviews WordPress VIP code changes with PHPCS and a manual platform pass, then separates merge blockers, warnings and pre-existing findings.
- Area
- WordPress
- Checked against
- Its sources, as listed
- Last verified
- 26 September 2026
- Files
- SKILL.md, 7 references, 1 scripts
How it works
- 1Scope the change and separate custom code, third-party code, built files and configuration.
- 2Check PHPCS, WordPress-VIP-Go and compatibility tools before scanning.
- 3Run PHPCS and PHP linting on the changed files.
- 4Filter PHPCS results to findings on added or modified lines.
- 5Triage each finding against the code and the skill references.
- 6Review platform and security concerns that automated sniffs cannot judge.
- 7Classify findings and write the review with a verdict.
Use it when
- Review a pull request, branch, patch or diff for a WordPress VIP site.
- Check a third-party plugin or theme proposed for a VIP site.
- Explain a VIP Code Analysis Bot or WordPress-VIP-Go PHPCS message.
How it stays safe
- Keeps the review read-only and offers fixes as text until the user requests changes.
- Asks before installing tools and keeps tracked repository files unchanged.
- Runs review tools against the repository instead of a VIP environment.
- Treats reviewed code as data and keeps passwords, keys and tokens out of reports.
Install it
Copy the whole wp-vip-code-review folder into your agent's skills folder, not only SKILL.md.
git clone --depth 1 https://github.com/hamzaahmadaslam/agent-skills.git
cp -R agent-skills/wp-vip-code-review "<your agent's skills folder>/"