AgentStack
Browse Sign in
Browse Why AgentStack Sell Docs
Sign in
SKILL verified MIT Self-run

Wordpress

skill-xclouddev-xcloud-agent-skills-wordpress · by xCloudDev

Manage WordPress on xCloud sites — list/update/activate plugins and themes, check WordPress health and update summaries, toggle WP_DEBUG, generate magic-login URLs, run vulnerability scans and manage findings, and run PageSpeed Insights scans. Use for WordPress app management, security scans, or site performance. For SSL see xcloud:ssl; for site backups/domains/cache see xcloud:sites; for server…

No reviews yet
0 installs
29 views
0.0% view→install

Install

$ agentstack add skill-xclouddev-xcloud-agent-skills-wordpress

✓ scanned · ✓ verified, works with Claude Code, Cursor, and more.

Security review

✓ Passed

No issues found. Passed automated security review. · v0.1.0 How review works →

  • Prompt-injection patterns
  • Secret / credential exfiltration
  • Dangerous shell & filesystem operations
  • Untrusted network calls
  • Known-malicious package signatures

What it can access

  • Network access No
  • Filesystem access No
  • Shell / process execution No
  • Environment & secrets No
  • Dynamic code execution No

From automated source analysis of v0.1.0. “Used” means the capability is present in the source — more access means more to trust, not that it’s unsafe.

View the full security report →

Verified badge

Passed review? Show it. Paste this badge into your README, it links to the public security report.

AgentStack Verified badge Links to your public security report.
[![AgentStack Verified](https://agentstack.voostack.com/badges/verified.svg)](https://agentstack.voostack.com/security/report/skill-xclouddev-xcloud-agent-skills-wordpress)

Reliability & compatibility

Security review passed
0 installs to date
no reviews yet
2mo ago

Declared compatibility

Claude CodeClaude Desktop

Compatibility is declared by the source manifest. End-to-end runtime verification is coming, see below.

Preview Execution monitoring

We're building live execution health for every listing: tool-call success rate, median latency, uptime, and last-checked timestamps, measured, not self-reported. It isn't live yet, so we don't show numbers we can't stand behind.

How agent discovery & health will work →
Are you the author of Wordpress? Claim this listing to set pricing, connect Stripe payouts, and keep 70% of every sale.
Sign up to claim

About

xCloud WordPress

Owns WordPress app management plus site vulnerability scanning and PageSpeed. Read the shared layer first for auth, base URL, and conventions:

  • ${CLAUDE_PLUGIN_ROOT}/reference/auth.md
  • ${CLAUDE_PLUGIN_ROOT}/reference/conventions.md
XC="${CLAUDE_PLUGIN_ROOT}/scripts/xcloud.sh"

Scopes: reads need read:sites, writes need write:sites.

Response format

Brand every user-facing reply (see reference/conventions.mdResponse format): open with ☁️ **xCloud · WordPress** — , give the trimmed result, and close with a _via xcloud:wordpress_ line.

Narrate each call (see Progress narration): before every $XC call print one line of what xCloud is doing, e.g. ☁️ xCloud is scanning \\ for vulnerabilities…; the first call of a task opens with ☁️ xCloud is starting a session…. Every progress line and every action sentence must start with xCloud as the actor — never a bare verb like "Scanning…" or "Updating…". Say xCloud is scanning….

On the first xcloud reply in a conversation, lead with the xCloud startup banner (see reference/conventions.mdStartup banner) in a fenced code block — once per conversation.

Sub-resources (load on demand)

| Sub-resource | Reference file | |---|---| | Plugins, themes, updates, activate, refresh | reference/plugins-themes.md | | Vulnerabilities (scan, list, ignore) | reference/vulnerabilities.md | | PageSpeed Insights | reference/pagespeed.md |

Core endpoints

| Operation | Method + path | |---|---| | WP health status | GET /sites/{uuid}/wordpress/status | | Updates summary | GET /sites/{uuid}/wordpress/updates | | Toggle WP_DEBUG | POST /sites/{uuid}/wp-debug | | Magic login URL | POST /sites/{uuid}/magic-login |

Not here: SSL → xcloud:ssl; backups/domains/cache/SSH → xcloud:sites; server infra → xcloud:servers.

Examples

WordPress health + pending updates:

SITE_UUID='replace-me'
"$XC" GET "/sites/$SITE_UUID/wordpress/status"  | jq '.data'
"$XC" GET "/sites/$SITE_UUID/wordpress/updates" | jq '.data'

Toggle WP_DEBUG (enabled required):

"$XC" POST "/sites/$SITE_UUID/wp-debug" '{"enabled":true}' | jq '.message'

Generate a one-time admin magic-login URL:

"$XC" POST "/sites/$SITE_UUID/magic-login" '{"login_as":"admin"}' | jq -r '.data.url // .data'

Cross-domain note

vulnerabilities and pagespeed are addressed at /sites/{uuid}/… and work on any site, but are owned here because they are predominantly WordPress concerns. A non-WordPress "scan my site" request still routes here via the xcloud:sites cross-link.

Pitfalls

  • Plugin/theme updates and activations are async and can optionally back up

first — see reference/plugins-themes.md.

  • Magic-login URLs are single-use and short-lived; never log them.

Source & license

This open-source skill is cataloged on AgentStack and links to its original source — we do not rehost the code.

Install and usage instructions live in the source repository linked above.

Reviews

No reviews yet, be the first.

Versions

  • v0.1.0 Imported from the upstream source.