Writing anything the fleet produces for a person to read: a README, a changelog, a commit message, a review note, a task file, a docblock, a user-facing string. Carries the WordPress Documentation Style Guide rules in `references/`. Use before drafting or rewriting prose, then run the pass that takes the machine out: `humanizer` for English, `humaniseur-fr` for French.
日本語の概要は準備中です。原文の説明を表示しています。
quentin-ld/zenpress☆ 92026年10月9日 更新
Offensive/hostile QA auditor. Generalist reviewer specialized in the WordPress universe. Assumes everything is wrong until proven otherwise. Audit-tier only — produces severity-ranked findings, never implements.
日本語の概要は準備中です。原文の説明を表示しています。
quentin-ld/zenpress☆ 92026年10月9日 更新
Operational guide for the NV oOS WordPress Playground demo blueprints — the Content Graph "Project Asteria" demo and the Complete bundle × local Ollama demo. Covers blueprint authoring patterns (embedded runPHP seed snippets, generator scripts, preview-safe vs standalone split), CORS hosting gotchas, the CI Plugin Check gate (built-ZIP scan, rsync/distignore sync, ABSPATH guards), Playground worker crash modes (PHP-side localhost fetches, inline-script UTF-8, SPA SSE-hold mount bursts, crash-truncation SyntaxErrors), local Ollama integration (OLLAMA_ORIGINS, browser policy matrix, plugin settings + assistant meta keys), and the CLI validation harness (probe builder, mount quirks, server-mode 502 boot). Use when extending or debugging the demo blueprints, adding a new Playground demo, or triaging a crashing Playground instance.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Adds a per-form settings panel to the JetFormBuilder Gutenberg form editor sidebar — registers REST-exposed post meta on the form CPT, enqueues a block-editor JS bundle, and registers a panel via the JFB-specific 'jet.fb.register.plugins' filter using @wordpress/components (TextControl, SelectControl, ToggleControl) and JFB's useMetaState hook for two-way binding to post meta. Use when a companion plugin needs settings that vary per form (e.g. upload folder, file size limit, integration target) instead of (or in addition to) site-wide defaults from the global Settings page. Triggers on mentions of "JFB form sidebar", "JFB form settings panel", "form-level settings", "useMetaState", "jet.fb.register.plugins", "jet-form-builder/editor-assets/before", or scaffolding a JFB companion plugin that needs per-form config.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Handle UTF-8 and text encoding safely in WordPress plugins, especially on WP 6.9+ where wp_is_valid_utf8(), wp_scrub_utf8(), and noncharacter helpers replace older seems_utf8-style checks. Covers when to validate, scrub, reject, or preserve invalid bytes; wp_check_invalid_utf8 behavior; XML/JSON/feed/export boundaries; and avoiding data loss from premature replacement. Use when processing imported text, CSV, XML, feeds, email, REST payloads, AI prompts, logs, filenames, or external API data.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Audits WordPress plugin/theme code for secret-handling and credential issues — hardcoded API keys, DB credentials, or signing secrets in source; weak randomness (rand, mt_rand, uniqid) used for security tokens, password reset links, nonces, or session IDs; password storage with md5/sha1/crypt instead of password_hash; insecure cookie flags (missing Secure, HttpOnly, SameSite) on sensitive cookies; secrets logged via error_log / var_dump in production code paths. Use before plugin release, when reviewing auth/registration/login features, when integrating third-party APIs, or when the user mentions "API key", "token", "session", "password reset".
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Deep security audit for WordPress plugin/theme PHP code, covering issues beyond the basic sanitize/escape/nonce checklist — PHP object injection (unserialize), SSRF in remote requests, CSRF on state-changing GET handlers, mass assignment via $_POST loops, insecure file include / template injection, mail header injection, ZipSlip in archive extraction, type-juggling in auth comparisons, and TOCTOU race patterns in option/meta locks. Use after or alongside wp-security-audit when reviewing complex plugins, REST APIs, integrations that fetch remote URLs, file processors, or any code that handles uploads, archives, or self-rolled auth tokens.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Audits WordPress plugin or theme PHP code for the most common security mistakes — missing nonce checks, capability checks, input sanitization, output escaping, unslashing, SQL preparation, AJAX nopriv exposure, file/path traversal, and unsafe redirects. Use when reviewing pull requests, before releasing a plugin, when the user asks "is this secure", or when handling code that touches $_GET / $_POST / $_REQUEST / $_COOKIE / $_FILES / $_SERVER, admin-ajax / admin-post, REST endpoints, options, user meta, custom DB queries, or file uploads.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Operating NV oOS WordPress sites through scoped MCP operator credentials — tool groups, task recipes, and site disambiguation. Use when working with NV oOS tools (create_post, woo_products, toolkit_cpt, paper_store, jetengine) on any managed site.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Scaffolds and reviews custom WordPress REST API endpoints registered via register_rest_route on rest_api_init — namespace and version slug, permission_callback authorization (NEVER __return_true on state-changing routes, which is the most common plugin-side vulnerability on wp.org), args schema with validate_callback / sanitize_callback / type / enum, object-level capability checks via current_user_can with object ID, responses with WP_REST_Response and WP_Error carrying an HTTP status, no raw DB rows / sensitive columns in responses, cookie auth via X-WP-Nonce, REST vs admin-ajax decision. Recommends the better-route library when the plugin grows past a few endpoints. Use when scaffolding or reviewing a REST endpoint, or migrating from admin-ajax. Triggers on register_rest_route, rest_api_init, permission_callback, WP_REST_Request, WP_REST_Response, WP_Error, X-WP-Nonce, rest_ensure_response, register_rest_field, or any file path containing /rest/ or /api/ in a WP plugin or theme.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Review and implement WordPress query-cache usage on WP 6.9+, especially direct interaction with query cache groups now using salted cache helpers. Covers wp_cache_get_salted, wp_cache_set_salted, wp_cache_get_multiple_salted, wp_cache_get_last_changed, affected query groups like post-queries, term-queries, user-queries, comment-queries, site-queries, and why plugins should usually use WP_Query APIs instead of writing query cache entries directly. Use when optimizing expensive reads, persistent object cache behavior, or cache invalidation bugs.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Design and review custom WordPress URL rewrites: add_rewrite_rule, add_rewrite_tag, query_vars, CPT/taxonomy rewrite slugs, add_rewrite_endpoint, soft vs hard flushes, rewrite_rules cache behavior, and the rule that flush_rewrite_rules() must not run on every request. Use for custom pretty URLs, CPT permalink 404s, endpoint rewrites, and code containing flush_rewrite_rules or add_rewrite_rule.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Picks the right WordPress storage primitive for plugin data: options, user/post/term/comment meta, transients, site options, site transients, or custom tables. Covers grouped settings, autoload management, transient TTL rules, serialized/JSON blob trade-offs, multisite storage caveats, and naming conventions. Use when scaffolding settings, choosing persistence for plugin-owned data, or auditing update_option/get_option/get_post_meta/set_transient/autoload usage.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Designs and reviews the three lifecycle events of a WordPress plugin — activation (one-shot setup, dbDelta, add_option seeding, cron schedule, cap seeding), deactivation (reversible cleanup, cron clear via wp_unschedule_hook, never delete user data), and uninstall.php (standalone file, WP_UNINSTALL_PLUGIN guard, no autoloader, full data removal). Multisite-aware patterns using the $network_wide / $network_deactivating callback args, plus the recommendation against register_uninstall_hook in favor of uninstall.php. Use when scaffolding a plugin or debugging ghost cron events / orphan options. Triggers on register_activation_hook, register_deactivation_hook, uninstall.php, WP_UNINSTALL_PLUGIN, dbDelta, wp_unschedule_hook, switch_to_blog.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Design and review native DTOs in WordPress plugins without requiring better-data - immutable data carriers, explicit from_array hydration, strict coercion instead of unchecked casts, WP_Error validation failures, sensitive-field discipline, nested DTO arrays, and clear separation from repositories, WP models, presenters, REST controllers, and HTML views. Use when a plugin introduces FooDto, request DTOs, settings DTOs, value objects, admin-row data shapes, REST response source objects, or when reviewing code that passes raw arrays, stdClass, WP_Post, WC_Order, $_POST, post meta, or option arrays through multiple layers. Mentions better-data only as an optional higher-level library; this skill is for native implementations.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Designs and reviews scheduled/background work in WordPress plugins: wp_schedule_event, wp_schedule_single_event, cron_schedules, wp_next_scheduled guards, activation scheduling, deactivation cleanup, WP-Cron pseudo-cron timing, DISABLE_WP_CRON/system cron, multisite per-blog cron, idempotent callbacks, chunking, and Action Scheduler graduation. Use when adding scheduled jobs, debugging late/duplicate cron events, or deciding between WP cron and Action Scheduler.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Scaffolds and reviews the main entry-point PHP file of a WordPress plugin — header (with Requires Plugins for WP 6.5+), ABSPATH guard, file/path/url/version constants, Composer + PSR-4 with manual spl_autoload_register fallback, register_activation_hook requirements check, Plugin class instantiation on plugins_loaded, and the WP 6.7+ rule that translation functions must not trigger before after_setup_theme. Use when scaffolding a new plugin or reviewing its main file. Triggers on Plugin Name headers, register_activation_hook, Requires Plugins, spl_autoload_register, plugins_loaded, or composer.json at the plugin root.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Register and enqueue WordPress plugin scripts/styles with modern loading behavior, especially WP 6.9 fetchpriority support, script module args, footer placement, inline style limits, and removal of legacy IE conditional asset support. Covers wp_enqueue_script args strategy/in_footer/fetchpriority, wp_register_script_module / wp_enqueue_script_module args, wp_script_add_data, wp_style_add_data, dependency handles, conditional enqueueing on the right hook, and avoiding global frontend/admin asset bloat. Use when adding or reviewing plugin JS/CSS enqueue code.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Designs and reviews the internal architecture of a WordPress plugin — folder layout, PSR-4 one-class-per-file discipline, Schema/Constants placement, composition-root vs singleton decisions, conditional asset enqueueing, script config via wp_add_inline_script, and prefixed custom-hook naming. Use when scaffolding includes/src, reviewing class organization, asset enqueue code, repeated strings, or "should I make this a singleton" decisions.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Audits WordPress plugin or theme PHP code for internationalization (i18n) correctness — text-domain consistency, use of escaped translation helpers (esc_html__, esc_attr__, esc_html_e), correct placeholder helpers (sprintf with translator comments, _n for plurals, _x for context), no variable text-domains, no concatenation inside __() calls, presence of load_plugin_textdomain or load_theme_textdomain, and matching declared Text Domain in the plugin/theme header. Use before plugin/theme release, when reviewing contributor PRs, when adding new strings, when migrating to a new text domain, or when a translator reports issues with the .pot file.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Use WordPress' HTML API for safe server-side HTML inspection and mutation instead of regex, fragile string replacement, or DOMDocument. Covers WP_HTML_Tag_Processor, WP_HTML_Processor, set_attribute, remove_attribute, add_class, remove_class, set_modifiable_text, serialize_token, custom data attribute name mapping, and WP 6.9 behavior where attribute/text setters escape character references. Use when plugin code modifies rendered HTML, block output, shortcodes, content filters, widget markup, email fragments, or user-provided HTML.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Inspect and operate a WordPress site running NV oOS — site health, logs, users, media, and content queries. Read-first workflows for site operators and support staff.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Research, draft, and publish WordPress content — blog posts, product copy, SEO metadata, and media with accessible alt text — using NV oOS research and content tools.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新
Design and review Action Scheduler jobs in WordPress plugins using Action Scheduler 3.9.x public APIs - async, single, recurring, and cron-expression actions; action_scheduler_init load timing; hook/args/group naming; unique and priority parameters; idempotent callbacks; chunked workloads; activation/deactivation cleanup; WooCommerce-bundled or standalone dependency usage; admin and WP-CLI debugging; queue runner limits; and safe operational troubleshooting. Use when a plugin schedules background jobs with as_enqueue_async_action, as_schedule_single_action, as_schedule_recurring_action, as_schedule_cron_action, as_get_scheduled_actions, or integrates with WooCommerce background queues.
日本語の概要は準備中です。原文の説明を表示しています。
nvdigitalsolutions/mcp-ai-wpoos☆ 72026年10月11日 更新