Governed ability

Update post meta

aafm/update-post-metaGuarded write

Update post meta is a governed ability in Agent Abilities for MCP, a free WordPress plugin that runs an MCP server on your site.

Write a single allowlisted scalar meta value to a post the agent can edit.

How it is governed

The same model as every ability in the plugin, stated for this one.

  • Off until you enable it

    Like every ability, Update post meta ships switched off. You turn it on one at a time, and an update never widens access on its own.

  • Guarded write

    Writes stay conservative, and the plugin re-checks the capability before the call runs.

  • Capability gated

    A connection only sees Update post meta if the user you connected can run it, and the plugin checks that capability again before it executes.

  • Every call audited

    The call is written to the log in your own database, denials included, with the argument keys and the identifiers it touched, never free-text content.

Update post meta is one of the 26 governed Content abilities. Browse the other Content abilities in the catalog.

See it in action

An illustrative run. Your real calls and data stay on your own site.

agent-abilities · auditGoverned
YouUpdate post meta on this site.
RunRunning aafm/update-post-meta
GateAllowedcapability re-checked before running
Auditaafm/update-post-meta · principal: editor · args: post_id
ResultApplies the change, then writes the call to the audit log.

Try it with a prompt

Example requests you could paste to your agent.

  1. Set the subtitle meta on post 142 to A Practical Guide.
  2. Update the read_time custom field to 8 on that tutorial post.
  3. Change the cta_label meta value on the pricing page to Start free.

These are illustrative example prompts. The agent runs them as the user you connected, checked against that user's capabilities and written to your audit log.

Frequently asked

Short answers for Update post meta.

Can it write any field?

Update post meta writes only keys on the allowlist, and only scalar values. Anything off the list is refused.

Who can run it?

Update post meta is off by default and only works on posts the agent's user can edit, with the write recorded in the audit log.

Why can it not touch image alt text or the featured image?

Alt text lives under `_wp_attachment_image_alt` and the featured image under `_thumbnail_id`. Both are protected meta in stock WordPress, so they are refused for every caller whatever their role, and no allowlist entry changes that. Use update media for alt text and set featured image, or the featured_media field on a post write, for the thumbnail. Since 1.7.0 the refusal names the right tool instead of reading as a permission problem.

Back to all abilities

Governed by default, from the first call.

Update post meta is off until you enable it, scoped to the user you connect, and logged like everything else. Turn on only what you need.

Every ability off until you enable it, capability-gated on every call.