AdvancedLesson 21 of 22 · 5 steps

Extend EMCP with hooks and a custom tool

Prepare a small developer extension with explicit permissions and a testable result.

Video coming soon

Your next step is ready.

Follow the complete written guide below.
The video will join it here when it’s ready.

Start the written lesson

Before you start

  • A practice site and permission for the task.
  • WordPress PHP development experience.
  • A separate test plugin and a local/staging environment.

Let’s do this, step by step.

Step 01

Choose the extension point

Read the documented filters and actions and choose the one matching your requirement.

Most users can skip this lesson. Developers can use normal WordPress hooks to adjust behavior without editing EMCP's own files.

Step 02

Create a tiny test plugin

Put the extension in a separate plugin and start with a narrow documented filter, such as hiding a specific ability.

Keep the change isolated and easy to deactivate. Do not modify vendor files that an update will replace.

Step 03

Define a read-only custom ability

Use the Abilities API with a name, input/output schema, execution callback, and a real permission callback.

A custom action needs its own permission check. A descriptive label does not protect it. Start with a harmless read-only example.

Step 04

Expose and verify it

Add the ability to the MCP server through the adapter's documented registration hook, reconnect, and test discovery and execution.

Confirm the current adapter registration contract before coding. Test a permitted user and a user who should be refused, then deactivate the extension and confirm the tool disappears.

Step 05

Use current extension catalogs

For custom modules or runtime skill sources, inspect the documented register_modules and skill_sources filters and test with the installed version. For Dashboard notices, inspect the attention-check contract.

The current release also has extension points for modules, skill sources and dashboard notices. Use the documented contract and verify your small extension in isolation before relying on it.

You’re done when…

The isolated extension has verified discovery, permissions, and a clean removal path.

Keep the reference handy.

The docs cover tool details and requirements for this lesson.