Linux 软件免费装
Banner图

RuleFence - AI Agent Permissions & Audit for MCP

开发者 wpagentmanager
更新时间 2026年9月24日 19:26
PHP版本: 8.0 及以上
WordPress版本: 7.1
版权: GPLv2 or later
版权网址: 版权信息

标签

security permissions ai mcp abilities

下载

1.0.0

详情介绍:

Start by finding out what your site already exposes. Install RuleFence and the Ability Explorer lists every Ability your plugins register, classified by what it does and how risky it is, before you grant anything. Most administrators are surprised by that list. Everything else here is what you do about it. Because give an AI agent a WordPress login and it can do anything that login can do. The role is the only limit, and roles come in whole jobs: a Shop Manager can refund an order as easily as fix a typo in a product description. RuleFence draws the line inside the job. Every agent gets its own identity and its own credential, so you can see which agent did something and not just which user. Every registered Ability gets a decision - allow it, hold it for a person, or refuse it outright - and a request that turns out riskier than the Ability looked can be escalated on the spot rather than waved through. One switch stops every agent on the site at once. All of it - the decisions, the requests, the refusals - lands in a signed record that cannot be edited afterwards, not even by this plugin. In practice that reads like: this agent may look up orders and add notes to them, must ask a person before it changes an order's status, and may never delete a product. It connects to the clients people are actually using - Claude Desktop, Claude Code, Cursor, ChatGPT, anything else that speaks the Model Context Protocol, or plain REST. Setting up a connection ends with a configuration block you paste into the client, with the credential already in it. Nothing leaves your site This plugin contacts nothing, ever. There is no analytics call, no version ping, no licence check and no webhook. Your agents, permissions, decisions and audit trail live in your own database and are never sent anywhere. That is worth checking against anything else you are considering. A governance tool that ships your site's activity to someone else's server has moved the problem rather than solved it. The rule everything else follows An Ability nobody granted is refused. A new agent starts paused and is allowed nothing, and stays that way until you say otherwise, one Ability at a time. Nothing you install can widen that by accident, because nothing widens it except you. What it does How much there is to govern, and how to find out RuleFence governs the WordPress Abilities API, so it covers whatever your plugins register - core, WooCommerce, your own - rather than a fixed list. That also sets the scale: a site whose plugins register a lot of Abilities has a lot for this to govern. WordPress 7.1 registers three of its own, all read-only. Plugins are where the rest comes from, and a growing number of them now register Abilities - page builders, custom fields, commerce, management tools. Rather than take a number from anyone, install this and read your own: the Ability Explorer is the first screen worth opening, and it answers the question for your site specifically. Abilities are what it governs, and that is worth being exact about. An agent's credential is a WordPress user, so anything that user could already do through the ordinary REST API, it still can - the permission matrix is not in that path. What limits it there is the WordPress user you map the agent to, which is why this plugin asks for a least-privilege one, warns you when an agent is mapped to an administrator, and scores it in Readiness. WordPress capabilities are the ceiling; the matrix is how you carve out what an agent may do underneath it. Using it with Claude, ChatGPT, Cursor and other MCP clients RuleFence is not the MCP server and does not pretend to be one. WordPress 7.1 registers Abilities, the official MCP Adapter publishes them over the Model Context Protocol, and an MCP client - Claude Desktop, Claude Code, Cursor, ChatGPT, Windsurf, whatever you use - calls them. RuleFence is the layer that decides which of those calls are allowed, which wait for you, and which are refused, and records all of it. That means it governs whichever of those clients you connect, including more than one at a time, each with its own identity and its own credential that you can revoke on its own. Setting up a connection ends with the endpoint, a username, an Application Password and a configuration block you paste straight into the client. A site with no MCP Adapter is still covered: the same credential works against the REST endpoint. What this plugin is, and what a separate add-on adds Everything above is this plugin. There is no licence key, no edition, and nothing in it that a payment unlocks - what you install is what you get, working, for as many agents as you care to run. A separate paid add-on, RuleFence Pro, is available from rulefence.com and adds conditional policies and ready-made policy sets, a simulator that tries a draft policy against calls already recorded, a record of which rules actually fire, multi-step workflows with human checkpoints, undo and rollback, scheduling, email alerts and webhooks, approval routing, risk threshold and rate ceiling tuning, audit export, custom retention, saved activity views, reusable agent and permission profiles, and configuration transfer between sites. A further tier governs a multisite network: shared policies, one approval queue, a fleet inventory, and named site groups. It is a second plugin you install alongside this one; nothing about it is present here. That is worth being plain about, because the two arrangements look similar from outside and are not. This plugin does not ship the paid features in a disabled state. The screens have no buttons that exist to tell you what something would cost, and no control is switched off waiting for a key. What is never sold, in this plugin or that one: default-deny, human approvals, the signed audit chain, audit logging, secret redaction, emergency mode, WordPress capability checks, failing closed when audit integrity is unavailable, and session expiry. A security control that only works if you pay is not a security control. External services None. See "Nothing leaves your site" above. The two features that could make an outbound request - webhook notifications, and validating a licence key - both belong to the paid add-on. Neither is here, so there is no code in this plugin that could make a request even if something asked it to. Agents reach your site from outside it, over the REST API, using an Application Password you issue and can revoke. That is inbound, and it is what the plugin exists to govern.

安装:

  1. Upload the rulefence folder to /wp-content/plugins/.
  2. Activate RuleFence.
  3. Activation opens a guided setup that walks you through the environment check, your first agent, what it may do, and its credential.
You can reopen setup any time from RuleFence > Settings > Run setup again. The full written guide is in docs/SETUP.md. WordPress 7.1 or later is required, because governance relies on the native Abilities execution lifecycle that 7.1 introduced. After setup A new agent starts paused and is allowed nothing. That is deliberate: every ability is blocked until you grant it in Abilities > Permissions. Grant a read ability first, watch it in Activity, and only then grant a write.

屏幕截图:

  • Agents: every AI client as a named identity, with the state it is in and whether it holds a working credential.
  • Connections: the Application Passwords that identify agents, each mapped to its own least-privilege WordPress user.
  • The Ability Explorer: everything installed plugins let an agent do, classified by action and risk before you grant any of it.
  • The permission matrix: every registered Ability against one agent, set to allow, require approval, or block.
  • The approval queue: what a request asked for, how risky it is, and how long there is to decide before it expires.
  • The activity trail: every permission decision recorded with the reason it was allowed, blocked, or sent for approval.
  • Readiness, scored, with the evidence and the recommendation behind each check.
  • Guided setup: six short steps, beginning with whether the site can govern an agent at all.

升级注意事项:

1.0.0 First public release. Nothing to upgrade from.

常见问题:

What does my site actually expose to an AI agent?

Open the Ability Explorer after activating. It lists every Ability your installed plugins register, grouped by the plugin that registered it, with what each one does, how risky it is, and whether it is publicly exposed. You do not have to grant anything, connect anything, or configure anything to read it - and reading it is the point of installing this before you need it.

Do I need a separate WordPress user for every agent?

Use a dedicated least-privilege WordPress user for each security boundary you need to isolate. An agent is a separate RuleFence identity, but its Application Password still inherits the mapped WordPress user's native REST capabilities. Do not map an untrusted client to an administrator.

My agent is blocked from everything. Is it broken?

No, that is the default. Governance fails closed: an ability nobody granted is refused. Grant the specific ability in Abilities > Permissions.

Where is the Application Password shown?

Once, when the connection is created. It cannot be retrieved afterwards. If it is lost, revoke that connection and issue another.

There is very little in my Ability Explorer. Is it working?

Yes, and the list is telling you something real. WordPress 7.1 registers three Abilities of its own, all read-only: core/get-site-info and core/get-environment-info need an administrator, and core/get-user-info needs only a logged-in user. Everything beyond that comes from plugins, so a short list means the plugins on that site have not registered any - and there is correspondingly little for an agent to do there. Install WooCommerce and the list grows immediately, including writes with previews and captured before-states behind them. There is a wrinkle in the meantime. An Editor mapped to an agent can reach only one of the three, while still being free to write posts through the ordinary REST API, which the permission matrix does not cover. On a stock site the safest mapping and the useful one are not yet the same thing. That is WordPress's design rather than this plugin's, it improves as plugins register Abilities with sensible capabilities, and it is the reason the Readiness screen scores your mapping instead of assuming it.

Does it control everything an agent can do?

It controls every Ability an agent invokes, which is what an AI client uses to work with your site. It does not sit in front of the ordinary WordPress REST API: a credential is a WordPress user, and that user's own capabilities decide what it can reach there. So map agents to a least-privilege user and keep it that way - the Readiness screen scores this, and the connection screen warns you if you point one at an administrator. The Activity trail records every Ability decision, and outside the Abilities API it records what a managed credential changed or was refused - so a change made through an ordinary REST route still appears, attributed to the agent that made it. Successful reads there are not kept one by one, because the trail is capped and a read-heavy client would crowd out the decisions.

Can I prove what an agent did?

Yes, and that is what the audit trail is for rather than a side effect of it. Every decision is stored with its reason in a hash-chained record, so the trail can demonstrate it has not been altered after the fact - by anyone, including this plugin. If you have to answer "what did the AI change, when, and who allowed it", the answer is on one screen and it is evidence rather than a log file.

What happens if an agent is compromised?

Revoke its connection in Agents > Connections, or stop everything at once with Settings > Emergency mode. The record of what it already did stays intact and signed.

Does anything leave my site?

No. Agents, permissions, decisions and the audit trail are stored in your own database, and this plugin makes no outbound request of any kind - there is no webhook code in it to configure.

Which features need the paid add-on?

As many agents as you want, and everything on the governance side, are here: default-deny permissions, approvals, the signed audit trail, risk assessment, emergency mode, the readiness checks and runtime verification. The add-on sells automation and convenience - workflows, policies, undo, scheduling, export. No security control is ever sold; a control you have to buy is not a control. You do not need the add-on to use this plugin, and nothing here stops working without it.

Does the plugin include an AI model, or send anything to one?

No. It governs agents that connect to your site; it is not one, and it does not talk to any model. The AI client is whatever you connect - Claude, ChatGPT, a script of your own.

Can it undo what an agent did?

This plugin captures the before-state, so the evidence of what changed is kept whether or not you ever undo it. Performing the undo is in the paid add-on. Not everything is reversible either way, and the plugin does not claim otherwise - the Ability Explorer tells you which Abilities are covered before you grant one, so you know what a grant is worth before you make it.

更新日志:

1.0.0 First public release. Development before this release was internal. No build older than this one was ever distributed.