

See a compatible agent use a reviewed public Core capability; the separately deployed Assistant shown is optional and is not included in Core.
Publish reviewed WordPress and WooCommerce capabilities as MCP and WebMCP tools. You choose what agents may discover, and supported changes require approval.
Install the plugin, enable Standard Tools, review the catalog, then publish and verify it. Core works without an Open for Agents account, AI API key or paid license, and nothing is published merely because the plugin was activated.
Open for Agents is for website owners who want agents to use reviewed site capabilities. It is not unrestricted WordPress administration.
Activation alone publishes nothing. Public publishing and the browser runtime are disabled by default, and detected forms or endpoints do not become tools automatically.
Safe Public includes only the reviewed public selection. An exact session-bound read such as cart inspection can be enabled without cart changes. Write tools still require the write framework and trusted, argument-bound visitor approval. Checkout, payment, order placement and account changes remain unavailable.
Core requires no Open for Agents account, model API key, paid license or hosted service. Every included capability remains available without a paid upgrade.
Executable forms exclude captcha, consent, payment, upload, account, signature, calculation and multi-page workflows. Generic REST and AJAX mining is lower-confidence discovery for administrator review, not native provider support. Detection never means automatic publication; execution requires provider enablement, exact per-form opt-in and a trusted approval verifier.
Form preparation lets compatible browser assistants fill exact reviewed WPForms Lite and Contact Form 7 forms. Visitors check every answer and submit the form themselves.
MCP lets compatible external clients discover and call reviewed tools through a bounded server endpoint. WebMCP makes the same reviewed capabilities available to compatible browser agents on the relevant pages.
Core can also publish the owner-approved catalog through llms.txt, an API Catalog, an MCP Server Card, Agent Skills and optional Agentic Resource Discovery output. AI crawler controls for robots.txt, validation, diagnostics and scan history help administrators understand the published surface.
The separately distributed Open for Agents Assistant is optional and is not included in this WordPress.org package. It is available only for approved deployments, not general public download. Core works without it.
Core does not contact an external service operated by Enoki Limited or another provider.
Published MCP Server Card and Agent Skills documents contain $schema identifiers at static.modelcontextprotocol.io and schemas.agentskills.io. The plugin does not request those URLs, transmit data to them or require them to be available.
Deep scan is an optional developer integration point, not a bundled service. When enabled, the plugin passes a page URL and non-secret request settings only to locally installed code attached to open_for_agents_deep_scan_report; it never passes authentication cookies, authorization headers or WordPress nonces. A developer who connects an external renderer must disclose that separate service, its data, terms and privacy policy. Without an integration, the plugin uses its same-site static scan and sends nothing externally.
Core does not create an Enoki Limited account, load remote tracking code or transmit site data to an Open for Agents service.
Normal scanning and verification make HTTP requests to the WordPress site’s own public or administrator-authorized same-origin URLs. Authenticated scan cookies are used only for same-origin requests during that scan and are never included in public output.
Any configured third-party renderer may process page URLs, request context or rendered content and must be governed separately.
Privacy policy: Open for Agents privacy policy
Terms: Open for Agents terms