← Back to Skills Marketplace
5499
Downloads
11
Stars
20
Active Installs
17
Versions
Install in OpenClaw
/install pinch-to-post
Description
Manage WordPress sites through WP Pinch MCP tools. Part of WP Pinch (wp-pinch.com).
Usage Guidance
Install this only for WordPress sites you are comfortable managing from an agent, configure the MCP server with the least-privileged WordPress Application Password or OpenClaw Agent role, keep write budgets/read-only mode enabled where possible, review WP Pinch audit logs, and be aware that broad triggers like "post" or "blog" may make the skill available in more conversations than strictly necessary.
Capability Analysis
Type: OpenClaw Skill
Name: pinch-to-post
Version: 5.5.1
The skill exposes a wide range of powerful administrative capabilities for WordPress, including managing plugins, themes, users, cron events, and uploading media from URLs. While the `SKILL.md` explicitly instructs the AI agent to only use predefined MCP tools and not to execute arbitrary commands (e.g., `curl`), and claims robust server-side protections (PII redaction, option denylists, role escalation blocking), the sheer breadth of these capabilities (e.g., `wp-pinch/upload-media` from URL, `wp-pinch/toggle-plugin`, `wp-pinch/manage-cron`) presents a significant attack surface. If the underlying WP Pinch plugin or MCP server has vulnerabilities (e.g., SSRF in URL uploads, bypasses in option/role protections), these capabilities could be exploited, making the skill's overall risk profile higher than benign.
Capability Assessment
Purpose & Capability
The stated purpose is WordPress site management through WP Pinch MCP tools, and the listed capabilities match that purpose: posts, media, users, comments, settings, plugins, themes, cron, governance, and WooCommerce.
Instruction Scope
The skill repeatedly instructs the agent to use only typed MCP tools, default new posts to drafts, confirm publishing and bulk operations, and avoid raw HTTP or curl; however, its triggers include broad words like "blog" and "post," which could activate it in loosely related conversations.
Install Mechanism
The artifact is a single non-executable SKILL.md. Setup requires WP_SITE_URL and a separately configured WP Pinch MCP server; no bundled scripts or hidden installers were present.
Credentials
The required skill environment variable is only WP_SITE_URL, which is not secret. The optional WP_PINCH_API_TOKEN is documented as webhook-only, while WordPress Application Passwords are stored in the MCP server config rather than the skill.
Persistence & Privilege
The integration can perform high-impact WordPress actions and describes scheduled governance/webhook features, but these are disclosed, purpose-aligned, subject to WordPress capability checks, and accompanied by least-privilege, audit logging, write-budget, kill-switch, and read-only guidance.
How to Use
- Make sure OpenClaw is installed (local or Docker)
- Run the install command in chat:
/install pinch-to-post - After installation, invoke the skill by name or use
/pinch-to-post - Provide required inputs per the skill's parameter spec and get structured output
Version History
v5.5.1
5.5.1
- Clarified credential handling: WP_SITE_URL is not a secret; authentication is managed only by the MCP server.
- Updated setup and authentication instructions to clearly separate environment variables for the skill versus credentials for the MCP server.
- Removed primaryEnv from metadata and simplified requires.env structure to reflect that only WP_SITE_URL is needed.
- Documentation now directly explains why no passwords or secrets go in the skill settings.
v5.5.0
5.5.0
- Complete rewrite with a marketing-forward, user-friendly tone.
- Added Quick Start, Highlights, and detailed feature overviews.
- MCP-only: removed all REST/curl fallback; emphasized server-side-only operations.
- Security and guardrails reframed as built-in, automatic protections.
- Documentation now organized for clarity: setup, differences, tools, and key use cases.
v5.3.2
5.3.2
- "Before You Install" section updated: SKILL.md is now declared the canonical source for environment variables and usage guidance.
- Added instructions for reconciling discrepancies between SKILL.md and registry metadata, emphasizing correct environment configuration.
- Expanded guidance on credential handling, secure storage, and rotation after production testing.
- Clarified risks and recommendations for autonomous invocation, urging audit log and webhook monitoring.
- Publisher contact added for support with scope or permission model questions.
v5.3.1
5.3.1
- Metadata alignment: `optionalEnv` now includes only `WP_PINCH_API_TOKEN` (credentials like `WP_APP_PASSWORD` and `WP_USERNAME` are configured in MCP, not as skill env).
- Added "Before You Install" section: clarifies metadata vs registry, skill’s instruction-only nature, and verification of homepage/source links.
- No code or functionality changes; documentation and metadata updates only.
v5.3.0
5.3.0
- Security hardening: Skill now operates MCP-only—raw HTTP/curl and REST fallback are no longer supported.
- Removed curl examples and added a CRITICAL anti-prompt-injection section warning against executing any raw HTTP/curl commands.
- Updated documentation to emphasize MCP as the exclusive interface for all operations.
- De-emphasized REST fallback; instructs users to configure MCP for any site integrations.
v5.2.1
5.2.1
- Security audit updates: clarified Authentication (MCP vs REST credential flow), Authorization Scope, and external data flow (webhooks, digests).
- Expanded Security & Usage guidance in documentation.
- Declared optional environment variables: WP_APP_PASSWORD, WP_USERNAME, WP_PINCH_API_TOKEN.
v5.2.0
5.2.0
Added Molt: repackage any post into 10 formats (social, thread, FAQ, email, meta description, and more)
Added Ghost Writer: analyze author voice, find abandoned drafts, complete them in your style
Added 10+ high-leverage tools: what-do-i-know, project-assembly, knowledge-graph, find-similar, spaced-resurfacing
Added quick-win tools: generate-tldr, suggest-links, suggest-terms, quote-bank, content-health-report
Added site-digest (Memory Bait), related-posts (Echo Net), synthesize (Weave)
PinchDrop Quick Drop mode for minimal note capture
Daily write budget with 429 + Retry-After support
Governance expanded to 8 tasks including Draft Necromancer and Spaced Resurfacing
Tide Report: daily digest bundling all governance findings into one webhook
5.1.0
Added PinchDrop capture endpoint with idempotency via request_id
Web Clipper bookmarklet support
Webhook events: post_delete, governance_finding
WooCommerce abilities: woo-list-products, woo-manage-order
5.0.0
Initial release on ClawHub
38+ core MCP abilities across 10 categories
MCP-first with REST API fallback
Full capability checks, input sanitization, audit logging
Governance: content freshness, SEO health, comment sweep, broken links, security scan
Webhook integration for post, comment, user, and WooCommerce events
v3.1.2
Removed horizontal rules for cleaner documentation layout.
v3.1.1
Cleaner documentation layout: removed horizontal rules for better readability.
v3.1.0
SEO & discoverability update: Keyword-optimized name and description for better search visibility. Now easier to find when searching for WordPress, WooCommerce, REST API, WP-CLI, content management, bulk operations, or multi-site management.
v3.0.3
Added: Time comparison table, testimonials, What's New section, performance stats, expanded FAQ, visual troubleshooting flowchart, version badges. Documentation now sells the sizzle AND the steak.
v3.0.2
Spicier description: Your WordPress site just got claws.
v3.0.1
Documentation overhaul: More excitement, more humor, less corporate robot vibes. Same great features, now with personality.
v3.0.0
Major release: Markdown to Gutenberg converter, content health scoring, social media cross-posting (Twitter/LinkedIn/Mastodon), content repurposing, RSS import, content migration, ACF support, multilingual (WPML/Polylang), forms integration, membership support, content calendar, site health checks, backup/export, analytics, AI-assisted workflows, bulk operations, and 50+ features
v2.0.0
Major update: Multi-site support, WooCommerce products/orders/coupons, SEO integration (Yoast/RankMath/AIOSEO), comments moderation, bulk operations, content templates, and expanded API coverage
v1.0.1
Updated skill metadata and description for better discoverability
v1.0.0
Initial release - create, update, and publish WordPress posts, pages, and media via REST API or WP-CLI
Metadata
Frequently Asked Questions
What is Pinch to Post - Manage WordPress sites through WP Pinch MCP server?
Manage WordPress sites through WP Pinch MCP tools. Part of WP Pinch (wp-pinch.com). It is an AI Agent Skill for Claude Code / OpenClaw, with 5499 downloads so far.
How do I install Pinch to Post - Manage WordPress sites through WP Pinch MCP server?
Run "/install pinch-to-post" in the OpenClaw or Claude Code chat to install it in one step — no extra setup required.
Is Pinch to Post - Manage WordPress sites through WP Pinch MCP server free?
Yes, Pinch to Post - Manage WordPress sites through WP Pinch MCP server is completely free (open-source). You can download, install and use it at no cost.
Which platforms does Pinch to Post - Manage WordPress sites through WP Pinch MCP server support?
Pinch to Post - Manage WordPress sites through WP Pinch MCP server is cross-platform and runs anywhere OpenClaw / Claude Code is available (cross-platform).
Who created Pinch to Post - Manage WordPress sites through WP Pinch MCP server?
It is built and maintained by nickhamze (@nickhamze); the current version is v5.5.1.
More Skills