← All changes
|
vendor/wordpress/mcp-adapter/includes/Abilities/ExecuteAbilityAbility.php
+1
-1
4.3.0-beta1
→
trunk
View file →
| @@ -19,9 +19,9 @@ | ||
| 19 | 19 | * WordPress ability through the MCP protocol. |
| 20 | 20 | * |
| 21 | 21 | * SECURITY CONSIDERATIONS: |
| 22 | 22 | * - This ability has openWorldHint=true, allowing execution of any registered ability |
| 23 | - * - Only abilities with mcp.public=true metadata can be executed via default MCP server. | |
| 23 | + * - Only abilities with effective MCP public exposure can be executed via default MCP server. | |
| 24 | 24 | * - Requires proper WordPress capability checks for secure operation |
| 25 | 25 | * - Caller identity verification is enforced through WordPress authentication |
| 26 | 26 | * |
| 27 | 27 | * @see https://developer.wordpress.org/apis/security/ for detailed security guidance |