Governed ability

Get all post meta

aafm/get-all-post-metaRead only

Get all post meta is a governed ability in Agent Abilities for MCP, a free WordPress plugin that runs an MCP server on your site.

Read every allowlisted scalar meta value from a post the agent can edit, returned as a key/value map. Protected, underscore, and non-scalar values are excluded.

How it is governed

The same model as every ability in the plugin, stated for this one.

  • Off until you enable it

    Like every ability, Get all post meta ships switched off. You turn it on one at a time, and an update never widens access on its own.

  • Reads only

    It reads data and returns it to your client. Nothing on your site is created, changed, or removed.

  • Capability gated

    A connection only sees Get all post meta if the user you connected can run it, and the plugin checks that capability again before it executes.

  • Every call audited

    The call is written to the log in your own database, denials included, with the argument keys and the identifiers it touched, never free-text content.

Get all post meta is one of the 26 governed Content abilities. Browse the other Content abilities in the catalog.

See it in action

An illustrative run. Your real calls and data stay on your own site.

agent-abilities · auditGoverned
YouGet all post meta on this site.
RunRunning aafm/get-all-post-meta
GateAllowedread capability confirmed
Auditaafm/get-all-post-meta · principal: editor · args: post_id
ResultReturns the data the agent asked for. Nothing on the site changes.

Try it with a prompt

Example requests you could paste to your agent.

  1. Give me all the custom fields on post 210 as a key value list.
  2. Dump every allowlisted meta value for the About page.
  3. List all the custom field values stored on that product review post.

These are illustrative example prompts. The agent runs them as the user you connected, checked against that user's capabilities and written to your audit log.

Frequently asked

Short answers for Get all post meta.

Does this include hidden or protected fields?

No. Get all post meta leaves out protected, underscore-prefixed, and non-scalar values, so only allowlisted scalar keys come back.

Is it read only?

Yes, Get all post meta never writes. It also requires edit access to the post, is capability-gated, and is audited.

Back to all abilities

Governed by default, from the first call.

Get all post meta is off until you enable it, scoped to the user you connect, and logged like everything else. Turn on only what you need.

Every ability off until you enable it, capability-gated on every call.