PluginProbe ʕ •ᴥ•ʔ
AI Engine – The Chatbot, AI Framework & MCP for WordPress / 3.6.4
AI Engine – The Chatbot, AI Framework & MCP for WordPress v3.6.4
3.6.6 3.6.4 3.6.5 3.6.3 3.6.2 3.6.1 3.6.0 3.5.9 3.5.8 3.5.7 3.5.6 3.5.5 3.5.4 3.5.3 3.5.2 3.5.1 3.5.0 3.4.9 3.4.8 3.4.7 0.2.1 1.6.91 0.2.2 1.6.92 0.2.3 1.6.93 0.2.4 1.6.94 0.2.5 1.6.95 0.2.6 1.6.96 0.2.7 1.6.97 0.2.8 1.6.98 0.2.9 1.6.99 0.3.0 1.7.0 0.3.1 1.7.1 0.3.2 1.7.2 0.3.3 1.7.3 0.3.4 1.7.4 0.3.5 1.7.5 0.3.6 1.7.6 0.4.0 1.7.7 0.4.1 1.7.8 0.4.2 1.7.9 0.4.3 1.8.0 0.4.4 1.8.1 0.4.5 1.8.2 0.4.6 1.8.3 0.4.7 1.8.4 0.4.8 1.8.5 0.4.9 1.8.6 0.5.0 1.8.7 0.5.1 1.8.8 0.5.2 1.8.9 0.5.3 1.9.0 0.5.4 1.9.1 0.5.5 1.9.2 0.5.6 1.9.3 0.5.7 1.9.4 0.5.8 1.9.5 0.5.9 1.9.6 0.6.0 1.9.7 0.6.1 1.9.8 0.6.2 1.9.81 0.6.3 1.9.82 0.6.4 1.9.83 0.6.5 1.9.84 0.6.6 1.9.85 0.6.7 1.9.86 0.6.8 1.9.87 0.6.9 1.9.88 0.7.0 1.9.89 0.7.1 1.9.90 0.7.2 1.9.91 0.7.3 1.9.92 0.7.4 1.9.93 0.7.5 1.9.94 0.7.6 1.9.95 0.7.7 1.9.96 0.7.8 1.9.97 0.7.9 1.9.98 0.8.0 1.9.99 0.8.1 2.0.0 0.8.2 2.0.1 0.8.3 2.0.2 0.8.4 2.0.3 0.8.5 2.0.4 0.8.6 2.0.5 0.8.7 2.0.6 0.8.8 2.0.7 0.8.9 2.0.8 0.9.0 2.0.9 0.9.2 2.1.0 0.9.3 2.1.1 0.9.4 2.1.2 0.9.5 2.1.3 0.9.6 2.1.4 0.9.7 2.1.5 0.9.8 2.1.6 0.9.81 2.1.7 0.9.82 2.1.8 0.9.83 2.1.9 0.9.84 2.2.0 0.9.85 2.2.1 0.9.86 2.2.2 0.9.87 2.2.3 0.9.88 2.2.4 0.9.89 2.2.5 0.9.9 2.2.51 0.9.91 2.2.52 0.9.92 2.2.53 0.9.93 2.2.54 0.9.94 2.2.56 0.9.95 2.2.57 0.9.96 2.2.6 0.9.97 2.2.60 0.9.98 2.2.61 0.9.99 2.2.62 1.0.0 2.2.63 1.0.01 2.2.70 1.0.1 2.2.80 1.0.2 2.2.81 1.0.3 2.2.90 1.0.4 2.2.91 1.0.5 2.2.92 1.0.6 2.2.93 1.0.7 2.2.94 1.0.8 2.2.95 1.0.9 2.3.0 1.1.0 2.3.1 1.1.1 2.3.2 1.1.2 2.3.3 1.1.3 2.3.4 1.1.4 2.3.5 1.1.5 2.3.6 1.1.6 2.3.7 1.1.7 2.3.8 1.1.8 2.3.9 1.1.9 2.4.0 1.2.0 2.4.1 1.2.1 2.4.2 1.2.2 2.4.3 1.2.21 2.4.4 1.2.3 2.4.5 1.2.30 2.4.6 1.3.0 2.4.7 1.3.1 2.4.8 1.3.2 2.4.9 1.3.3 2.5.0 1.3.31 2.5.1 1.3.32 2.5.2 1.3.33 2.5.3 1.3.34 2.5.4 1.3.35 2.5.5 1.3.36 2.5.6 1.3.37 2.5.7 1.3.38 2.5.8 1.3.39 2.5.9 1.3.40 2.6.0 1.3.41 2.6.1 1.3.42 2.6.2 1.3.43 2.6.3 1.3.44 2.6.5 1.3.45 2.6.6 1.3.46 2.6.7 1.3.47 2.6.8 1.3.48 2.6.9 1.3.49 2.7.0 1.3.50 2.7.1 1.3.51 2.7.2 1.3.52 2.7.3 1.3.53 2.7.4 1.3.54 2.7.5 1.3.56 2.7.6 1.3.57 2.7.7 1.3.58 2.7.8 1.3.59 2.7.9 1.3.60 2.8.0 1.3.61 2.8.1 1.3.62 2.8.2 1.3.63 2.8.3 1.3.64 2.8.4 1.3.65 2.8.5 1.3.66 2.8.6 1.3.67 2.8.7 1.3.68 2.8.8 1.3.69 2.8.9 1.3.70 2.9.0 1.3.71 2.9.1 1.3.72 2.9.2 1.3.73 2.9.3 1.3.74 2.9.4 1.3.75 2.9.5 1.3.76 2.9.6 1.3.77 2.9.7 1.3.78 2.9.8 1.3.79 2.9.9 1.3.80 3.0.0 1.3.81 3.0.1 1.3.82 3.0.2 1.3.83 3.0.3 1.3.84 3.0.4 1.3.85 3.0.5 1.3.86 3.0.6 1.3.87 3.0.7 1.3.88 3.0.8 1.3.89 3.0.9 1.3.90 3.1.0 1.3.91 3.1.1 1.3.92 3.1.2 1.3.93 3.1.3 1.3.94 3.1.4 1.3.95 3.1.5 1.3.96 3.1.6 1.3.97 3.1.7 1.3.98 3.1.8 1.3.99 3.1.9 1.4.0 3.2.0 1.4.1 3.2.1 1.4.2 3.2.2 1.4.3 3.2.3 1.4.4 3.2.4 1.4.5 3.2.5 1.4.6 3.2.6 1.4.7 3.2.7 1.4.8 3.2.8 1.4.9 3.2.9 1.5.0 3.3.0 1.5.1 3.3.1 1.5.2 3.3.2 1.5.3 3.3.3 1.5.4 3.3.4 1.5.5 3.3.5 1.5.6 3.3.6 1.5.7 3.3.7 1.5.8 3.3.8 1.5.9 3.3.9 1.6.0 3.4.0 1.6.1 3.4.1 1.6.2 3.4.2 1.6.3 3.4.3 1.6.5 3.4.4 1.6.51 3.4.5 1.6.52 3.4.6 1.6.53 1.6.54 1.6.55 1.6.56 1.6.57 1.6.58 1.6.59 1.6.60 1.6.61 1.6.62 1.6.63 1.6.64 1.6.65 1.6.66 1.6.67 1.6.68 trunk 1.6.69 0.0.1 1.6.70 0.0.2 1.6.71 0.0.3 1.6.72 0.0.4 1.6.73 0.0.5 1.6.74 0.0.6 1.6.75 0.0.7 1.6.76 0.0.8 1.6.77 0.0.9 1.6.78 0.1.0 1.6.79 0.1.1 1.6.81 0.1.2 1.6.82 0.1.3 1.6.83 0.1.4 1.6.84 0.1.5 1.6.85 0.1.6 1.6.86 0.1.7 1.6.87 0.1.8 1.6.88 0.1.9 1.6.89 0.2.0 1.6.90
ai-engine / notes / STUDY-MCP.md
ai-engine / notes Last commit date
CHANGELOG-PROPOSAL.txt 2 days ago QA-LOOP.md 2 days ago STUDY-CONSOLIDATION.md 2 days ago STUDY-MCP.md 2 days ago STUDY-WORKSPACE.md 2 days ago STUDY-WPAI-LEARNINGS.md 2 days ago
STUDY-MCP.md
130 lines
1 # STUDY-MCP.md — AI Engine MCP: state, strategy, and improvement backlog
2
3 > **Living planning doc.** MCP + chatbot/agentic is AI Engine's core focus, so this is refined
4 > incrementally: target **at least one shipped (or proposed) MCP improvement every 3–4 days, surfaced via `/pulse`**.
5 > Each pulse: pick the highest-value unchecked item that fits the available time, ship it production-safe,
6 > and append a dated line to the Progress Log. Read `STRATEGY.md` first for the broader posture.
7
8 ## Why this matters
9
10 WordPress is standardizing on the **Abilities API** (in core since 6.9, Feb 2026) plus the official
11 **MCP Adapter** (`wordpress/mcp-adapter`, now canonical), and **WP 7.0 ships an AI Client**. AI Engine's job
12 is to be the **safe, production-ready, extensible home for MCP on WordPress**, and to stay interoperable
13 with that core direction.
14
15 ## Positioning (frame from strength — we are NOT a limited toolset)
16
17 - **~90 tools** across: posts, terms, media, users, comments, options, counts, plugin management,
18 theme management (incl. file read/write/alter), Polylang, 27 WooCommerce tools, and a guarded `wp_db_query`.
19 - **Modern server**: OAuth 2.1 (PKCE + Dynamic Client Registration), bearer token, streamable HTTP,
20 `.well-known` discovery, and a WAF-aware self-test diagnostic.
21 - **Production-safe by design**: curated, capability-gated tools. No arbitrary PHP eval / arbitrary filesystem.
22 That dangerous "do anything" model is the dev-only competitor lane (e.g. Novamira), not ours.
23
24 ## Strategic context
25
26 - Abilities API in core (WP 6.9); `wordpress/mcp-adapter` is the canonical package (typed DTOs). WP 7.0 ships the AI Client.
27 - Competitor watch: **Novamira** — dev-only RCE MCP server, built on the Abilities API, NOT in the wp.org repo.
28 Their only real lead is Gutenberg page authoring. (See memory `reference_novamira_mcp_competitor`.)
29 - Competitor watch: **WPVibe / `vibe-ai`** — Awesome Motive (SeedProd). Cloud-RELAY MCP server: their plugin
30 ships the site's Application Password to their Cloudflare infra and all AI traffic flows through them.
31 2k installs vs our 100k (2026-07), but the WPBeginner/SEJ/YouTuber machine plus an eventual in-admin
32 cross-promo push across the Awesome Motive family is the real threat. Their leads: near-zero-friction
33 onboarding (magic link, ~60s, works with ChatGPT), user-VISIBLE safety UX (dry-run previews, approval
34 gates, audit log), and a theme-builder demo that films well. Our counters: self-hosted (credentials never
35 leave the site, no middleman reading content), free with no monthly caps, ~90 tools vs 27, full platform.
36 (See memory `reference_wpvibe_competitor`.)
37
38 ## Improvement backlog (pick from here each /pulse)
39
40 ### A. Product capability — user-demanded, safe, on-brand
41 - [~] **Gutenberg block authoring**`wp_write_blocks` IMPLEMENTED (2026-07-02) in `labs/mcp-core.php`
42 (free tier). 12 core block types (paragraph, heading, list, quote, image, buttons, group,
43 columns, separator, spacer, code, html), replace/append/prepend modes, no partial writes.
44 Design doc removed once shipped (see commit history). VALIDATED against the live WP editor on ai.nekod.net:
45 24/24 blocks valid across all 15 core types (one fix: image figcaption class is
46 `wp-element-caption`, not `wp-block-image__caption`). Remaining: a live end-to-end MCP call to
47 confirm the write path. The #1 forum ask and Novamira's only real lead. Biggest single product win.
48 Layered plan (Novamira source read 2026-07-02, see memory `reference_novamira_mcp_competitor` for their
49 queue + hidden-editor-iframe finalizer mechanism):
50 1. **Server-side curated core blocks** — deterministic PHP renderers for ~15 stable core blocks
51 (paragraph, heading, list, image, columns, group, buttons, cover, quote, media-text, separator,
52 spacer, table, embed, gallery). We control the exact save-output HTML per block version, so output
53 validates. Headless, production-safe, no browser step. Covers 90% of "write me a page".
54 2. **Block patterns tools**`wp_list_block_patterns` (registry + theme patterns) and insert-pattern
55 with text/image slot replacement. Patterns are pre-validated theme markup: instant on-brand pages,
56 zero validation risk, and it makes the THEME do the design work. Nobody ships this; cheap win.
57 3. *(optional, later)* **Browser finalizer** for arbitrary third-party blocks, only if demand shows:
58 serialize-on-demand via an admin tab running `wp.blocks` (we already have an admin React app to
59 host it). Novamira needed this as their PRIMARY path because they refuse to curate; for us it is
60 an edge-case add-on.
61 - [ ] **MCP Skills / playbooks** — let the site owner write short markdown playbooks (stored on-site,
62 managed in settings) exposed to agents via MCP prompts/resources and auto-suggested by description.
63 Production-safe, teaches agents site conventions ("posts use this category structure", "products
64 are formatted like X"). Concept validated by Novamira's Skills; clean-room design.
65 - [x] **Block patterns tools** — DONE 2026-07-02 (free tier). `wp_list_block_patterns` (read: search/
66 category filter, compact metadata, optional content) + `wp_insert_block_pattern` (write:
67 append/replace/prepend a registered pattern into a post). Pre-validated theme/core markup, so
68 inserting is on-brand and always editor-valid; compose a page from several patterns, then swap
69 text with `wp_alter_post`. Verified on ai.nekod.net (214 patterns; 5 sampled across categories
70 parse with 0 invalid blocks).
71 - [ ] **Global Styles / theme colors** — read/write the `wp_global_styles` entry (palette, typography, spacing)
72 without touching theme files. Answers the recurring "change my theme colors" question.
73 - [ ] **Navigation menus** — list/create/edit menus and assign to locations.
74 - [ ] **Widgets / block areas / template parts** — for "build my homepage" workflows.
75
76 ### B. Query power — reduce risky raw-SQL fallback
77 - [ ] **Structured filters on `wp_get_posts`**`meta_query`, `tax_query`, real `orderby`, so agents stop
78 dropping to `wp_db_query` for "products over $50, published, newest first".
79
80 ### C. Reliability / polish — "rock-solid, well updated"
81 - [ ] **Read caps** — clamp `limit` on `wp_get_posts` / `wp_get_media` / `wp_get_users` / `wp_get_comments`
82 (Polylang already clamps to 100; core tools accept `limit: 10000`).
83 - [ ] **Token-bloat controls** — meta exclude / cap on `wp_get_post_snapshot` (the gallery problem, for meta).
84 - [ ] **Ignored-param sweep** — audit every read tool for accepted-but-silently-ignored or
85 expected-but-missing params; wire them up or document them. (This session fixed 3 such bugs.)
86 - [ ] **Bulk writes** — batch post / meta / term update (only WooCommerce has batch today).
87 - [ ] **SSE fail-fast** — when no API key is configured, SSE should error clearly instead of hanging.
88 (Largely moot once legacy SSE is removed; see memory `project_mcp_sse_removal`, ~2026-07-01.)
89
90 ### D. Onboarding / framing
91 - [ ] **One-click `.mcpb` bundle** for Claude Desktop (removes the copy-paste step; Novamira ships this).
92 - [ ] **Auto health-check on enable** — run the self-test proactively, surface WAF / `.well-known` issues
93 before the user hits a failed connect.
94 - [ ] **Simplify auth paths** and finish the legacy SSE removal (scheduled ~2026-07-01).
95 - [ ] **Connection wizard** — a "Connect your AI" flow in the MCP settings: pick your client (Claude,
96 Claude Code, ChatGPT, Cursor), get the exact steps/URL/token for that client, run the self-test
97 inline. WPVibe's magic-link onboarding is their #1 lead; this closes most of the gap without
98 becoming a cloud middleman.
99 - [ ] **Visible safety UX** — productize what we already enforce: an opt-in "approval mode" that holds
100 destructive tool calls (delete, option writes, user changes) for one-click confirmation, and an
101 "Agent Activity" view over the existing event logs (who connected, which tools ran, what changed).
102 We ARE the production-safe option; today the user can't SEE that. WPVibe markets exactly this.
103
104 ### E. Strategic — future-proofing
105 - [ ] **Abilities bridge** — register AI Engine's tools as core Abilities so they're discoverable by the
106 official MCP Adapter and WP 7's AI Client, while keeping our own server for curation / OAuth / WP 6.0+
107 back-compat. This is the `/labs/wp7-integration/
108
109 ## Caveats
110
111 - The tool inventory and gap list were partly sourced from exploration agents — **verify the specific
112 file/line before implementing any item**.
113 - Every change stays production-safe and backward-compatible (REST / shortcode / DB schemas are sacred).
114
115 ## Progress log
116
117 - **2026-06-21** — Initial study written. This session also shipped MCP fixes: `author` / `author_name` /
118 `author__not_in` filters (posts, media, comments), `content_format=prose` reads, `wp_update_option`
119 JSON-array decode, `wp_get_option` `raw` flag, and the generic `mwai_mcp_mutate` write hook.
120 - **2026-07-02** — Shipped Gutenberg authoring (`wp_write_blocks`, 12 block types, editor-validated
121 24/24) and block patterns (`wp_list_block_patterns` + `wp_insert_block_pattern`), both free tier in
122 `labs/mcp-core.php`. This closes Novamira's one real product lead, headless and production-safe. Next:
123 live end-to-end MCP smoke test, then Global Styles / theme colors.
124 - **2026-07-02** — Competitive deep-dive (Novamira + WPVibe). Added WPVibe to the watch list and two new
125 backlog items derived from their leads: Connection wizard and Visible safety UX. Confirmed: Novamira
126 still not on wp.org (480 stars, tiny release downloads); WPVibe at 2k installs / 86 dl-day baseline vs
127 our 100k / ~2,192, but backed by Awesome Motive's marketing machine. Verdict: the fight right now is
128 narrative (share of "WordPress MCP" content), not installs. Gutenberg block authoring remains the top
129 product item — it is what both competitors' demos are made of.
130