Session Persistence
Medium
- Category
- Rogue Agent
- Content
## Overview - **What it does:** Connects OpenClaw to the Massblogger MCP server, giving the agent full read/write access to WordPress (posts, pages, categories, tags, media, menus, users, settings, comments, plugins, themes, revisions, scheduling) plus Massblogger's native content generation, pSEO, automation, and media pipelines. - **When to use it:** When you want an AI agent to manage one or more WordPress sites — writing, editing, publishing, restructuring, bulk operations, cross-site changes — without you copying HTML or switching tabs. - **Requirements:** A Massblogger account at massblogger.com, at least one WordPress site connected in Massblogger (with Application Password stored), and an MCP token generated from Massblogger settings.
- Confidence
- 88% confidence
- Finding
- The skill explicitly grants an agent persistent remote read/write control over WordPress sites through a hosted MCP server authenticated by a long-lived bearer token and stored WordPress application passwords. Even though this is advertised functionality, it creates a real session-persistence and high-privilege remote administration channel that could be abused if the agent, token, or Massblogger account is compromised.
