Agent Abilities for MCP
Self-hosted WordPress MCP server with per-capability permission controls and a full audit log. This MCP entry surfaces a curated ranking/list from the project README rather than a classic multi-tool integration surface.
Teams that want a hosted security endpoint instead of running a local process. The project is written in PHP.
VERIFIED ACTIVE
LAST COMMIT 2026-08-20 · ★ 3 · #156 OF 182 MAINTAINED SECURITY · VERIFIED 2026-08-25
GPL-2.0 · PHP · how we verify → /methodology
01 · Install Agent Abilities for MCP
before you install - you'll need
Set WP_API_URL, WP_API_USERNAME, WP_API_PASSWORD before connecting.
Claude Code
claude mcp add unaibamir-agent-abilities-for-mcp --transport http https://{hostname}/wp-json/agent-abilities-for-mcp/mcp Claude Desktop / Cursor / VS Code - add to config
{
"mcpServers": {
"unaibamir-agent-abilities-for-mcp": {
"url": "https://{hostname}/wp-json/agent-abilities-for-mcp/mcp"
}
}
} Same JSON for Cursor. For VS Code, rename the top-level key from `mcpServers` to `servers`.
Using another client? Same JSON, different key
Claude Desktop · mcpServers
Cursor · mcpServers
VS Code · servers
Windsurf · mcpServers
Zed · context_servers
Cline · mcpServers
Roo Code · mcpServers
Continue · mcpServers
LibreChat · mcpServers
Gemini CLI · mcpServers
Codex CLI · mcp_servers
Full setup guides: every client.
02 · Evidence
https://{hostname}/wp-json/agent-abilities-for-mcp/mcp
transport: streamable-http
endpoint NOT responding · probed 2026-08-25
Security posture
What to check before giving this server access to your agent - from the registry, GitHub, and our own probes. We don't score safety; we show what's verifiable.
runs as remote - your agent's requests go to {hostname}
license GPL-2.0 - declared in the repository
registry namespace io.github.unaibamir is GitHub-verified and matches the repo owner
03 · What Agent Abilities for MCP can do
Prose above is summarized from the project's README and registry record - no invented capabilities.
Latest releases
1.7.0 · 2026-08-20
Sections on the Abilities tab now have an "Enable all writes" button beside "Enable all reads". It ticks the ordinary writes and leaves deletes and high-risk abilities alone. · The audit log records more. Permanent…
1.6.3 · 2026-08-09
Condensed the changelog so the full release history fits within the wordpress.org listing's length limit, in both readmes. Same releases, fewer lines, with the security and data-integrity fixes still called out one by…
1.6.2 · 2026-08-09
The credential redaction for payment gateway and shipping method settings missed several field names it was meant to catch, among them passwd, pass, account_number, merchant_id, license, and username. All of them are…
04 · Who maintains Agent Abilities for MCP
Agent Abilities for MCP is maintained by unaibamir. It's the only MCP server we track from this author; the repo dates to Jun 2026.
05 · Facts
- repository
- github.com/unaibamir/agent-abilities-for-mcp
- website
- https://agentabilitieswp.com/
- category
- security - ranked #156 of 182 actively-maintained security servers as of 2026-08-25.
- release cadence
- 10+ releases in the last 90 days (latest 2026-08-20)
- registry
- io.github.unaibamir/agent-abilities-for-mcp (active, first published 2026-07-22 · 9 versions)
06 · Agent Abilities for MCP FAQ
What is Agent Abilities for MCP?
Self-hosted WordPress MCP server with per-capability permission controls and a full audit log. This MCP entry surfaces a curated ranking/list from the project README rather than a classic multi-tool integration surface.
Is Agent Abilities for MCP still maintained?
Yes - as of 2026-08-25, its last commit was 2026-08-20 and it shipped 10+ releases in the last 90 days. We re-verify nightly.
How do I install Agent Abilities for MCP?
Run `claude mcp add unaibamir-agent-abilities-for- --transport http https://{hostname}/wp-json/agent-abilities-for-mcp/mcp`. The README documents 3 environment variables (WP_API_URL, WP_API_USERNAME, WP_API_PASSWORD) to set first. Set WP_API_URL, WP_API_USERNAME, WP_API_PASSWORD before connecting. You can also paste the ready-made client config above.
07 · Alternatives to Agent Abilities for MCP
Alternatives to Agent Abilities for MCP
Maintained security servers if Agent Abilities for MCP isn't the fit.
- SafeDep Vet MCP Protect your AI agents and IDEs from malicious open-source packages. ★ 1,102 · 2026-08-24
- SonarQube MCP Server Analyze code quality and security with SonarQube Server or Cloud directly in AI assistants. ★ 632 · 2026-08-24
- Decionis MCP Server Fail-closed policy gate for AI agent actions, with local evaluation and native pre-tool hooks. ★ 533 · 2026-08-24
- HOL Guard Local-first AI agent security evidence and approval workflows through HOL Guard's stdio MCP server. ★ 470 · 2026-08-25
- Emisar Let AI operate servers without SSH. Choose actions, approve risky changes, and audit every step. ★ 409 · 2026-08-23
- Bradesco MCP server for Bradesco - Pix, Cobrança (boleto), Arrecadação, Extrato (OAuth2 + mTLS) ★ 269 · 2026-08-12
Pairs well with
Servers that cover what Agent Abilities for MCP doesn't - only shown when the pairing reason fits the companion.
More security MCP servers · Contrast API · Siteaudit MCP · Evernote · Pincer · Vuln Check