{"id":348285,"date":"2026-08-31T23:19:18","date_gmt":"2026-08-31T23:19:18","guid":{"rendered":"https:\/\/wordpress.org\/plugins\/mcp-command-kit\/"},"modified":"2026-08-31T23:18:41","modified_gmt":"2026-08-31T23:18:41","slug":"agentdesk-site-operations","status":"publish","type":"plugin","link":"https:\/\/wordpress.org\/plugins\/agentdesk-site-operations\/","author":23535249,"comment_status":"closed","ping_status":"closed","template":"","meta":{"version":"2.1.0","stable_tag":"2.1.0","tested":"7.0.4","requires":"6.4","requires_php":"7.4","requires_plugins":null,"header_name":"Agentdesk Site Operations","header_author":"CouveStack","header_description":"Connect AI agents to your site through a fixed set of predefined operations for content, media, WooCommerce, and Elementor. No file or code editing.","assets_banners_color":"011121","last_updated":"2026-08-31 23:18:41","external_support_url":"","external_repository_url":"","donate_link":"","header_plugin_uri":"https:\/\/couvestack.com\/agentdesk-site-operations","header_author_uri":"","rating":0,"author_block_rating":0,"active_installs":0,"downloads":55,"num_ratings":0,"support_threads":0,"support_threads_resolved":0,"author_block_count":0,"sections":["description","installation","faq","changelog"],"tags":{"2.1.0":{"tag":"2.1.0","author":"couvestack","date":"2026-08-31 23:18:41","revision":3675047}},"upgrade_notice":[],"ratings":[],"assets_icons":{"icon-128x128.png":{"filename":"icon-128x128.png","revision":3675074,"resolution":"128x128","location":"assets","locale":"","width":128,"height":128},"icon-256x256.png":{"filename":"icon-256x256.png","revision":3675074,"resolution":"256x256","location":"assets","locale":"","width":256,"height":256}},"assets_banners":{"banner-1544x500.png":{"filename":"banner-1544x500.png","revision":3675074,"resolution":"1544x500","location":"assets","locale":"","width":1544,"height":500},"banner-772x250.png":{"filename":"banner-772x250.png","revision":3675074,"resolution":"772x250","location":"assets","locale":"","width":772,"height":250}},"assets_blueprints":{},"all_blocks":[],"tagged_versions":["2.1.0"],"block_files":[],"assets_screenshots":[],"screenshots":[]},"plugin_section":[],"plugin_tags":[232494,569,529,242115,260626],"plugin_category":[],"plugin_contributors":[278554],"plugin_business_model":[],"class_list":["post-348285","plugin","type-plugin","status-publish","hentry","plugin_tags-ai-agent","plugin_tags-automation","plugin_tags-content","plugin_tags-mcp","plugin_tags-mcp-server","plugin_contributors-couvestack","plugin_committers-couvestack"],"banners":{"banner":"https:\/\/ps.w.org\/agentdesk-site-operations\/assets\/banner-772x250.png?rev=3675074","banner_2x":"https:\/\/ps.w.org\/agentdesk-site-operations\/assets\/banner-1544x500.png?rev=3675074","banner_rtl":false,"banner_2x_rtl":false},"icons":{"svg":false,"icon":"https:\/\/ps.w.org\/agentdesk-site-operations\/assets\/icon-128x128.png?rev=3675074","icon_2x":"https:\/\/ps.w.org\/agentdesk-site-operations\/assets\/icon-256x256.png?rev=3675074","generated":false},"screenshots":[],"raw_content":"<!--section=description-->\n<p>Agentdesk Site Operations connects MCP-capable AI clients (such as Claude, Cursor, and VS Code) to your WordPress site through a fixed, predefined set of operations built on WordPress's own APIs. Ask in plain language and your agent performs the operation.<\/p>\n\n<p><strong>This plugin does not edit files, execute code, run arbitrary SQL, or install other plugins.<\/strong> Every action is one of a fixed set of reviewed operations that go through core WordPress functions (wp_insert_post, wp_update_post, the WooCommerce CRUD APIs, and Elementor's own document meta). There is no file manager and no code editor.<\/p>\n\n<p>Content is filtered with wp_kses_post, and the Elementor HTML and Shortcode widgets are rejected, unless the acting user holds the unfiltered_html capability - the same rule WordPress itself applies in the block and classic editors.<\/p>\n\n<h4>What you can do<\/h4>\n\n<ul>\n<li><strong>Content<\/strong> - create, edit, publish, search, and organize posts, pages, and custom post types; manage categories, tags, and comments.<\/li>\n<li><strong>Media<\/strong> - browse the library, import images from a URL, and edit titles\/alt text.<\/li>\n<li><strong>WooCommerce<\/strong> - create, update and delete products; update order status and add order notes; list variations, coupons, customers and sales reports.<\/li>\n<li><strong>Elementor<\/strong> - list pages, read and update the Elementor document (structured widget data), add headings\/text\/buttons\/containers, and build pages from a brief.<\/li>\n<li><strong>SEO<\/strong> - read and update Yoast \/ Rank Math SEO meta for posts you can edit.<\/li>\n<li><strong>Site settings<\/strong> - read and update a small allowlist of general options (site title, tagline, date\/time format, posts per page). Site address, home URL and admin email are deliberately excluded.<\/li>\n<li><strong>Maintenance<\/strong> - flush page and object caches; detect installed integrations.<\/li>\n<li><strong>Read &amp; audit<\/strong> - site info, health checks, environment diagnostics, user and plugin\/theme inventory, debug configuration, and an action log.<\/li>\n<\/ul>\n\n<p>The plugin does not create users, change roles, or modify user passwords.<\/p>\n\n<h4>Predefined operations, by design<\/h4>\n\n<p>Every tool is a fixed operation with a typed input schema. The agent cannot write files, edit theme or plugin code, run raw database queries, or install software. This keeps the surface small, reviewable, and safe.<\/p>\n\n<h4>Safety<\/h4>\n\n<ul>\n<li>Authentication - a bcrypt-hashed API key or a WordPress Application Password is required on every request.<\/li>\n<li>Capability checks - each operation runs as a real WordPress user. Content operations are checked per object (you cannot edit or delete an item you could not edit in wp-admin), and internal or block-theme template post types are never writable.<\/li>\n<li>Safe mode (default on) - blocks permanently destructive operations such as deleting posts, media, products and comments.<\/li>\n<li>Power mode (default off) - required for sensitive operations: site settings, and overwriting or importing an Elementor document.<\/li>\n<li>Rate limiting - a per-IP flood guard plus a per-key request budget.<\/li>\n<li>Audit log - every action is recorded.<\/li>\n<\/ul>\n\n<h4>Self-hosted<\/h4>\n\n<p>Runs entirely on your site. No external service and no account: nothing is sent to us or to any third-party service. Your own AI client connects directly to your site.<\/p>\n\n<!--section=installation-->\n<ol>\n<li>Install and activate Agentdesk Site Operations.<\/li>\n<li>Go to Settings &gt; Agentdesk Site Operations and click Create API Key (shown once - copy it).<\/li>\n<li>Add the endpoint and key to your MCP client:\nhttps:\/\/your-site.com\/wp-json\/agentdesk-site-operations\/v1\/mcp<\/li>\n<li>Enable Power Mode only when you need site settings or Elementor document overwrites; keep Safe Mode on.<\/li>\n<\/ol>\n\n<!--section=faq-->\n<dl>\n<dt id=\"does%20it%20edit%20files%20or%20run%20code%3F\"><h3>Does it edit files or run code?<\/h3><\/dt>\n<dd><p>No. There is no file editor, file manager, or code execution. Every action is a fixed, predefined operation through WordPress's own APIs.<\/p><\/dd>\n<dt id=\"does%20it%20send%20my%20data%20anywhere%3F\"><h3>Does it send my data anywhere?<\/h3><\/dt>\n<dd><p>No. It is entirely self-hosted; your agent connects to your site and nothing leaves your server.<\/p><\/dd>\n<dt id=\"which%20ai%20clients%20work%20with%20it%3F\"><h3>Which AI clients work with it?<\/h3><\/dt>\n<dd><p>Any client that speaks MCP over HTTP with a Bearer token, such as Claude, Cursor, and VS Code.<\/p><\/dd>\n\n<\/dl>\n\n<!--section=changelog-->\n<h4>2.1.0<\/h4>\n\n<ul>\n<li>Added per-object and post-type capability checks for all content operations.<\/li>\n<li>Elementor content is now filtered unless the user has unfiltered_html.<\/li>\n<li>Removed site address, home URL and admin email from the writable options allowlist.<\/li>\n<li>Removed user creation and role editing; user data is now read-only.<\/li>\n<li>Renamed the plugin and aligned all descriptions with the actual feature set.<\/li>\n<\/ul>\n\n<h4>2.0.0<\/h4>\n\n<ul>\n<li>Refocused on a fixed set of predefined operations. Removed all file management, file\/code editing, arbitrary database search-replace, plugin installation, and theme switching. The plugin now performs only reviewed content, commerce, media, and read\/audit operations through core WordPress APIs.<\/li>\n<\/ul>","raw_excerpt":"Manage your WordPress content, media, and WooCommerce store from an AI agent through a fixed set of predefined operations. No file or code editing.","jetpack_sharing_enabled":true,"_links":{"self":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin\/348285","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin"}],"about":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/types\/plugin"}],"replies":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/comments?post=348285"}],"author":[{"embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wporg\/v1\/users\/couvestack"}],"wp:attachment":[{"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/media?parent=348285"}],"wp:term":[{"taxonomy":"plugin_section","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_section?post=348285"},{"taxonomy":"plugin_tags","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_tags?post=348285"},{"taxonomy":"plugin_category","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_category?post=348285"},{"taxonomy":"plugin_contributors","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_contributors?post=348285"},{"taxonomy":"plugin_business_model","embeddable":true,"href":"https:\/\/wordpress.org\/plugins\/wp-json\/wp\/v2\/plugin_business_model?post=348285"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}