BetterShield

Review what AI assistants did on your site

3 min read

Agent activity lists every ability call on your WordPress site, refused ones too: who made it, how it came in and how it ended.

The screen is under BetterShield › Activity › Agent activity. In WordPress, an ability is a named action a plugin offers to AI assistants and other tools, such as reading the score; each use of one is a call. This screen shows the calls that were made, where Agents › Surface shows what callers are able to do.

Note: Recording needs WordPress 7.1 or newer. On an earlier version the screen says agent activity is not recorded on this version, and nothing is listed.

What is recorded

Every time an ability is called on the site, whichever plugin registered it and however the call came in, including calls that were refused. Each record keeps the ability name, the time, the account it ran as, how the call came in, and the outcome. The input is kept only as a digest, never its contents, because an input can carry a secret.

Refusals also reach the site activity log: Ability refused once per ability per request, and Abilities refused repeatedly when ten requests within an hour carry a refusal. Another plugin can stop the recording, and BetterShield cannot prevent that, but it writes Agent activity recording stopped to the log, at most once an hour.

Turn recording on or off

Record what agents do on this site is on by default. The same switch appears in two places: the Recording agent activity card under Settings › General, and the same card under Agents › Permissions. Turning it off asks for your password first when Ask for my password before an action that removes a protection is on. Rows already recorded stay, and a note above the list says recording is off.

The figures at the top

FigureWhat it shows
RecordingOn, Off or Unavailable.
CallsCalls kept, or calls matching your filters.
RefusedCalls that asked for more than the account was allowed.
CompletedCalls that ran and answered.

Filters

  • Outcome, as chips with counts: All, Refused, Completed, Input rejected, Input unreadable, Output rejected, Answered early, Failed and Did not finish.
  • Namespace: the first part of an ability name, with counts. WordPress does not record which plugin registered an ability, so a namespace is a naming convention, not proof of who is behind it.
  • Came through: Any door, MCP (a connected assistant), REST, WP-CLI or PHP.
  • Clear filters resets all three.

Reading a row

Each row shows the time, the ability name, the account it ran as, how it came in (over MCP, over REST, via WP-CLI or in PHP), how long it took when that is measurable, and the outcome with any error code. A refused call is highlighted.

  • Everything this account did narrows the list to that account. Show every account goes back.
  • Agent surface, at the top, opens Agents › Surface, which shows what agents are able to do.
  • Show older entries loads more.

How long rows are kept

As long as the activity log: 30 days, or 90 days (Ultra). The note at the foot says which applies. The screen has no export; use wp bettershield agents --format=csv (WP-CLI commands).

Close the open doors today

Install the free plugin. The first audit runs when you activate it, and nothing changes until you choose a fix.

Requires WordPress 6.7 or newer and PHP 8.0 or newer.

Get BetterShield