Abilities & risk levels
Agent Guardrails → Abilities lists everything AI agents can do on the site: every ability registered through the WordPress Abilities API by WordPress, WooCommerce and other plugins. Risk decides the default policy for unknown agents, so correct it when the classification is wrong.
The table
Section titled “The table”| Column | Meaning |
|---|---|
| Ability | Name (for example woocommerce/product-update), label, and “Write-like inputs:” — input fields that look like they change data (price, stock, status, email, …). |
| Source | WordPress, WooCommerce, MCP Adapter, Raqvio Agent Guardrails, or the plugin/theme that registered it. |
| Exposure | Public / MCP if the ability is marked public or exposed to MCP; REST if it can be run over the REST API. |
| Risk | Read, Write, Financial or Destructive, how it was determined (Curated, Heuristic or Set by admin), and Not reversible for Financial abilities whose name mentions refund, payment, charge, payout or capture. |
| Override | Risk override: “Detected” or one of the four levels. |
| Sensitive | Never log input — the audit log stores “[sensitive ability: input not logged]” instead of the input. |
Use Search abilities (name, label or source) and the Risk filter to narrow the list, and Re-scan abilities after installing or updating plugins. The list refreshes itself when plugins are activated, deactivated or updated.
Risk levels
Section titled “Risk levels”| Level | Examples | Unknown agents (default) |
|---|---|---|
| Read | woocommerce/products-query, woocommerce/orders-query, core/get-site-info |
Allowed |
| Write | woocommerce/product-create, woocommerce/product-update, woocommerce/order-add-note |
Denied |
| Financial | woocommerce/order-update-status (setting “refunded” refunds; “cancelled” restocks), raqvio-ag/order-create-refund |
Denied |
| Destructive | woocommerce/product-delete |
Denied |
The unknown-agent defaults can be changed in Settings.
How risk is determined
Section titled “How risk is determined”- Your override, if you set one.
- Curated list — Raqvio Agent Guardrails ships verified classifications for WordPress core, WooCommerce, the MCP Adapter and its own abilities.
- Heuristics — the ability name is checked for telling words, then its annotations (destructive, read-only), then its description:
- financial: refund, payment, charge, payout, capture, withdraw, transfer, price, pricing, discount, coupon
- destructive: delete, remove, destroy, purge, trash, drop, wipe, uninstall, bulk
- write: update, create, edit, set, add, insert, write, publish, send, upload, import, assign, change, cancel, save, modify
- read: get, list, query, search, find, read, fetch, view, discover, info, count, check, lookup
- If nothing matches, the ability is treated as Write, so unknown agents are denied until you decide otherwise.
Saving an override or the sensitive flag is recorded in the audit log.
WooCommerce MCP endpoint abilities
Section titled “WooCommerce MCP endpoint abilities”When the WooCommerce MCP feature is enabled, WooCommerce serves its own MCP tools: woocommerce/products-list, -get, -create, -update, -delete and woocommerce/orders-list, -get, -create, -update. WooCommerce only registers these while it answers an MCP request, so Raqvio Agent Guardrails lists them for you, marked WooCommerce MCP endpoint only, so you can set permissions and rules for them like any other ability. woocommerce/orders-update is Financial, because it can mark an order refunded or cancelled.
Which abilities are governed
Section titled “Which abilities are governed”Every ability is governed except Raqvio Agent Guardrails’s three informational abilities for agents — raqvio-ag/get-my-permissions, raqvio-ag/get-approval-status and raqvio-ag/get-readiness-summary — which are read-only and never blocked. Raqvio Agent Guardrails’s refund ability is governed like any other.