wordpress-live-validation — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited wordpress-live-validation (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
This skill loads a real WordPress post in a Playwright headless browser and verifies that what readers see matches what was uploaded. The browser is the source of truth -- REST API success does not guarantee correct rendering.
Browser backend selection: Playwright MCP (default) is used for automated validation and CI/CD. Use Chrome DevTools MCP when the user explicitly asks to "check in my browser" or "debug live", or when the task involves Lighthouse audits or performance profiling.
| Signal | Load These Files | Why |
|---|---|---|
| check specifications: severities, edge cases, JS extraction | validation-checks.md | Loads detailed guidance from validation-checks.md. |
| Playwright MCP tool signatures, pitfalls, availability detection | playwright-tools.md | Loads detailed guidance from playwright-tools.md. |
| step-by-step NAVIGATE, VALIDATE, RESPONSIVE procedures | phase-checks.md | Loads detailed guidance from phase-checks.md. |
| Phase 4 REPORT output format | output-format.md | Loads detailed guidance from output-format.md. |
| post-upload validation walkthrough; wordpress-uploader integration | examples.md | Loads detailed guidance from examples.md. |
| errors, error handling | error-handling.md | Loads detailed guidance from error-handling.md. |
article → .entry-content → .post-content → main{WORDPRESS_SITE}/?p={post_id}&preview=true)Goal: Load the WordPress post and confirm the content area is present.
See references/phase-checks.md "Phase 1: NAVIGATE — Detailed Steps" for the 4-step procedure (verify browser MCP availability, navigate, wait for content area with selector chain, remove cookie/consent banners with the JS snippet).
GATE: Page loaded with HTTP 200 (or 30x redirect to 200), content selector found. If 4xx/5xx or no selector found: capture screenshot, report FAIL with HTTP status, STOP. Do not proceed to Phase 2.
Verification means execution, not reasoning. Run the command. Do not reason about whether the command would pass. Do not summarize the expected output. Execute the check, paste the exit code, paste the relevant output. A verification phase that produces a verdict without an observed tool result is not a verification — it is a guess with a rigor aesthetic.
Goal: Inspect rendered DOM and network activity for content integrity and SEO completeness. Run all checks without stopping on individual failures.
The 7 checks (with severity, JS extraction snippets, and pass/fail criteria) are documented in references/phase-checks.md "Phase 2: VALIDATE — All 7 Checks":
GATE: All 7 checks executed, each with severity and evidence. Proceed to Phase 3.
Goal: Verify rendering at three standard breakpoints. Capture visual evidence.
Test each viewport in sequence:
| Viewport | Width | Height | Represents |
|---|---|---|---|
| Mobile | 375 | 812 | iPhone-class |
| Tablet | 768 | 1024 | iPad-class |
| Desktop | 1440 | 900 | Standard laptop |
See references/phase-checks.md "Phase 3: RESPONSIVE CHECK — Detailed Steps" for the per-viewport 4-step procedure (resize, screenshot, overflow check, container visibility check) with the JS snippets.
GATE: Screenshots captured at all three viewports. Overflow and visibility recorded. Proceed to Phase 4.
Goal: Produce structured pass/fail report with severity counts and evidence artifacts.
See references/output-format.md for the full report template, status markers ([PASS], [FAIL], [WARN], [INFO], [SKIP]), and result classification rules.
GATE: Report generated with accurate severity counts. Screenshots saved. Result matches blocker tally.
When invoked after wordpress-uploader, this skill acts as an optional Phase 5: POST-PUBLISH VALIDATION. See references/examples.md for the integration flow and the post_url / post_id / --title inputs the uploader provides.
The validation is non-blocking by default: a FAIL result produces a report for the user but does not revert the upload. The user decides whether to act on findings.
See references/examples.md for worked examples (post-upload validation, standalone live check, OG tag verification) and the wordpress-uploader integration flow.
See references/error-handling.md for the full error matrix (Playwright MCP not available, page returns 4xx/5xx, content selector not found, network timeout on image checks, cookie banner blocks content).
For detailed check specifications and Playwright tool usage:
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.