Governed ability

Update user meta

aafm/update-user-metaGuarded write

Update user meta is a governed ability in Agent Abilities for MCP, a free WordPress plugin that runs an MCP server on your site.

Write a single allowlisted scalar meta value to a user the agent can edit. Auth, capability, and 2FA keys are blocked outright.

How it is governed

The same model as every ability in the plugin, stated for this one.

  • Off until you enable it

    Like every ability, Update user meta ships switched off. You turn it on one at a time, and an update never widens access on its own.

  • Guarded write

    Writes stay conservative, and the plugin re-checks the capability before the call runs.

  • Capability gated

    A connection only sees Update user meta if the user you connected can run it, and the plugin checks that capability again before it executes.

  • Every call audited

    The call is written to the log in your own database, denials included, with the argument keys and the identifiers it touched, never free-text content.

Update user meta is one of the 8 governed Users abilities. Browse the other Users abilities in the catalog.

See it in action

An illustrative run. Your real calls and data stay on your own site.

agent-abilities · auditGoverned
YouUpdate user meta on this site.
RunRunning aafm/update-user-meta
GateAllowedcapability re-checked before running
Auditaafm/update-user-meta · principal: editor · args: user_id
ResultApplies the change, then writes the call to the audit log.

Try it with a prompt

Example requests you could paste to your agent.

  1. Set the department meta field to Support for user 214.
  2. Update the phone_extension key on user 88 to 4021.
  3. Change the office_location custom field for editor Priya to Remote.

These are illustrative example prompts. The agent runs them as the user you connected, checked against that user's capabilities and written to your audit log.

Frequently asked

Short answers for Update user meta.

Can this change a password or a role through meta?

No. Update user meta blocks authentication, capability, and two-factor keys outright, and writes only a single allowlisted scalar value. The ability cannot escalate privileges or touch login credentials.

Whose profiles can it write to?

Update user meta writes only to users the connected account can edit. The ability is off by default, capability-gated, and every write is logged in the plugin audit trail.

Back to all abilities

Governed by default, from the first call.

Update user meta is off until you enable it, scoped to the user you connect, and logged like everything else. Turn on only what you need.

Every ability off until you enable it, capability-gated on every call.