How to Expose a Custom WordPress Ability through MCP
A custom WordPress ability can be projected through an MCP adapter, but transport exposure must not widen the ability’s permission, validation, side-effect or evidence contract.
AI is most useful here as an evidence organizer, comparison engine and drafting assistant. It can make a complex WordPress task easier to inspect, but it cannot create missing authority, certify facts it did not observe or silently convert a recommendation into permission to act.
In one sentence: A custom WordPress ability can be projected through an MCP adapter, but transport exposure must not widen the ability’s permission, validation, side-effect or evidence contract.
What this guide helps you accomplish
Prepare and verify a custom ability for MCP discovery and execution using explicit schemas, bounded permissions, negative tests and client-specific validation.
- A tested custom ability with a stable contract.
- An MCP exposure decision and configuration record.
- Discovery, execution, denial and malformed-input test evidence.
- Client-specific setup notes that do not imply universal compatibility.
The finished artifact should be understandable by the person responsible for the decision and reproducible by someone who did not participate in the original prompt. A fluent answer is not enough. Every material conclusion needs a source, a scope and a verification path. When the evidence cannot establish something, the correct output is an explicit unknown or a testable hypothesis.
Evidence and inputs to prepare
- A registered and tested WordPress ability.
- The current WordPress MCP Adapter and client documentation.
- Authentication and WordPress identity configuration.
- Safe local or staging fixtures.
- The installed WP Agent Control coverage when it supplies the WordPress identity.
Before supplying evidence to an assistant, remove credentials, secret values and unrelated personal information. Preserve the identifiers, versions, timestamps, locale, units and source labels needed to interpret what remains. A screenshot without a URL, state or date may be useful context, but it is rarely sufficient authority for a production decision.
Do not begin with a broad request such as “review this,” “fix this” or “make it better.” Define the decision the work must support, the population included, the source that is authoritative for each field, the allowed operations and the actions that remain forbidden. Authenticated WordPress access or a controlled export is required for this task.
MCP is transport and discovery
It helps a client understand and call tools. It does not replace WordPress authorization, ability validation or accountable approval.
Client support is specific
Claude Code, Codex and other clients can differ in configuration, tool presentation, approval UX and transport support. Test each named path.
A refusal is part of the contract
Unauthorized execution should fail predictably and be documented. Do not widen the WordPress identity to make a demo succeed.
Keep observation, inference and authority separate
A controlled review should distinguish at least four states:
- Observed: directly present in a named record, file, response, rendered page or executed test.
- Inferred: a plausible interpretation supported by evidence but not directly established.
- Recommended: a proposed human decision or next action.
- Authorized and verified: a separately approved change that was executed and then checked against acceptance criteria.
AI output usually begins in the first three states. It does not become authorized merely because it is detailed, internally consistent or technically convincing. Preserve this distinction in tables, reports, tickets and public case studies.
A safe workflow
- Complete and test the underlying ability before MCP exposure.
- Confirm the adapter version, transport and authentication path.
- Expose only the intended ability and metadata.
- Connect a safe client to a dedicated WordPress identity.
- Test discovery and one valid read-only or bounded fixture.
- Test unauthorized, invalid and out-of-scope requests.
- Record client, model, adapter, WordPress and plugin versions.
- Revoke the test identity and retain reproducible evidence.
This sequence deliberately places accountable review between analysis and implementation. If a later stage needs broader access, create a new task, a new identity or an explicit permission change. Do not quietly upgrade the analytical identity because it reached a correct boundary.
Prompt recipe
Replace every value in square brackets before using the prompt. Do not paste passwords, API keys, authentication cookies, private customer records or unrelated personal information.
You are reviewing [TASK SCOPE] for [SITE, REPOSITORY OR DATASET] using only the supplied evidence.
Objective:
Prepare and verify a custom ability for MCP discovery and execution using explicit schemas, bounded permissions, negative tests and client-specific validation.
Return the following fields:
- Ability
- Adapter version
- Client
- Transport
- Identity
- Permission
- Discovery result
- Valid execution
- Denied execution
- Invalid input
- Evidence
- Known limit
Rules:
1. Do not expose abilities before their direct tests pass.
2. Preserve ability names, schemas and identifiers exactly.
3. Do not claim compatibility with untested clients or versions.
4. Do not use Full Power to bypass a denial.
5. Do not include credentials in configuration examples.
For every finding:
- identify the exact source, record, URL, file, line, object ID, state or dataset row;
- preserve dates, versions, units, locale, identifiers and denominators;
- separate observation, inference, recommendation and unknown;
- state what evidence was not available;
- do not change WordPress, source code, commerce data, analytics, external systems or published content.
Why this prompt is structured this way
The prompt creates an evidence contract before asking for recommendations. It makes missing data visible, reduces the chance that a model will complete an incomplete record with plausible prose and produces an output that can be reviewed systematically. Structured fields also make it easier to compare repeated runs or hand an approved subset to a later implementation workflow.
A production implementation may add JSON schema, typed tool inputs or automated validation. Those mechanisms improve consistency, but they do not establish that the source evidence is true, complete or current. Human review and system-specific verification remain required.
Recommended access boundary
Use Depends on the separately authorized stage for the stage described in this guide. The exact capabilities available to an identity must come from the installed product version, the published coverage contract and the connection method actually in use.
What must remain outside this task
- Production execution
- Credential disclosure
- Broad tool exposure
- Permission escalation
- Universal compatibility claims
A refused action can be useful evidence that the control boundary is working. Do not respond to an expected refusal by granting a broad administrator account or Full Power. First determine whether the action belongs in the current mandate at all. If it does, create a separately authorized stage with the narrowest required capability.
How WP Agent Control fits
The guided private folder for Claude Code or Codex uses WordPress REST and an Application Password with a dedicated read-only profile. Existing Read Only, Draft, Content Editor and Publisher profiles remain under Advanced. They are not automatically converted to OAuth and do not inherit the remote task and exact-approval model.
Get structured site information and inspect selected published pages after connecting. No temporary task is needed for this public reading. You can also browse public pages without the plugin; Agent Control adds structured access and a path toward authorized WordPress work.
Connect your AI: docs first profile · See features and compatibility: coverage
Verification checklist
- The task, population, period, environment and decision are explicit.
- Every material observation is linked to exact evidence or labelled as a hypothesis.
- Stable IDs, URLs, versions, dates, units, locales and denominators are preserved.
- Missing evidence and coverage limits remain visible.
- The analytical or research identity performed no prohibited mutation.
- A qualified owner reviewed security, accessibility, legal, commerce or release implications where applicable.
- Any implementation has a separate mandate, access level, backup and verification plan.
- Temporary identities, fixtures and sensitive evidence are revoked, reset or disposed of after the task.
Common failure modes
- Transport-first development: The team debugs MCP while the underlying ability contract is still unstable.
- Demo account overreach: A broad administrator identity hides permission defects and creates unsafe documentation.
- Client conflation: A setup tested in one client is copied to another with different configuration semantics.
- Silent side effects: A tool described as analytical changes WordPress or an external system.
A recurring cross-cutting failure is permission drift: the initial task encounters a limit, and the operator broadens access before determining whether the missing operation is necessary, supported or safe. This destroys the evidence value of the refusal and makes later results difficult to attribute.
Advanced note
Treat MCP as a projection of a governed ability contract. Discovery metadata, execution authorization and observed restitution should be tested as separate layers so that a transport change cannot silently enlarge operational authority.
Related guides
- WordPress Abilities API Guide for AI Workflows
- How to Build a WordPress Permission Test Matrix for AI Agents
- How to Connect Claude Code to WordPress
- How to Connect Codex to WordPress
Next step
Continue with the most relevant supporting guide and use the access-level guide before any authenticated task. When temporary WordPress access is no longer needed, finish by revoking the identity.
Sources and verification
This page was checked against the following primary sources. Last source review: .
- Abilities API · WordPress.org
- Abilities API REST Endpoints · WordPress.org
- From Abilities to AI Agents: Introducing the WordPress MCP Adapter · WordPress.org
- Connect Claude Code to Tools via MCP · Anthropic
- Model Context Protocol — Codex · OpenAI
- WP Agent Control Coverage · WP Agent Control