Let AI assistants read your GTM Kit setup

GTM Kit 2.21 registers three read-only abilities with the WordPress Abilities API, so an AI assistant connected through the MCP Adapter can read your container, consent and tracking health setup.

Last updated ·

From version 2.21, GTM Kit describes its own setup to AI assistants. An assistant connected to your site can read how GTM Kit loads Google Tag Manager, which consent GTM Kit sets, and whether tracking is healthy, from the same checks the GTM Kit settings and Site Health use. It cannot change anything.

What this is for

WordPress 6.9 added the Abilities API: a standard way for plugins to describe what they can do, so other tools can find and call it. The WordPress MCP Adapter makes those abilities available to AI assistants that speak the Model Context Protocol (MCP), such as Claude, ChatGPT or Cursor.

With GTM Kit’s abilities, you can ask your assistant questions like “Which GTM container does this site load, and through which domain?”, “Is Consent Mode set up so analytics can ever be granted?” or “Does Site Health report any GTM Kit problems?”, and get an answer based on the site itself rather than a guess from the page source.

What an assistant can read

GTM Kit registers three abilities in the GTM Kit category (gtm-kit):

Get GTM Kit configuration (gtm-kit/get-configuration)

  • The container ID and the data layer name.
  • The server-side tagging domain, if one is set.
  • Which loader your pages use: the standard one, or the one Stape issues for your container, and whether a Stape loader is wanted and stored.
  • The Google tag gateway state: off, on and serving the container, on but falling back, or on but ruled out by a custom server-side tagging domain.
  • Whether GTM environment parameters are set (never their values).
  • The integrations that are switched on and whose plugin is active, and the GTM Kit version.
  • Whether GTM Kit sets Consent Mode defaults, and the consent state they set per category.
  • The consent platform GTM Kit detected, and which consent source is in charge.
  • Whether a consent integration owns consent, or GTM Kit’s defaults are the only source.
  • Whether analytics storage is granted before the visitor answers, and whether the defaults deny it with nothing on the site able to lift them.
  • How the purchase event’s customer details are treated when the page holds no consent state at all.

Get GTM Kit tracking health (gtm-kit/get-tracking-health)

  • The GTM Kit results you see yourself under Tools → Site Health, with their status (good, recommended or critical).
  • When the Google tag gateway is on, the result of its last stored check.
  • The result of GTM Kit’s daily check of a sample page: whether tracking was found, and whether it loads more than once.

What it cannot do

  • Change anything. All three abilities only read. No setting can be changed through them.
  • Run for anyone but administrators. Running an ability needs the manage_options capability. Other logged-in users can see that the abilities exist, with their names and descriptions, but get an error if they try to run one.
  • Reveal secrets. GTM environment parameters and licence data are never included in an answer.
  • Contact anything outside your site. The abilities make no outbound requests. Checks that need one, such as the gateway check, are reported from the result GTM Kit already stored.

Steps

1. Update GTM Kit

Update to GTM Kit 2.21 or later. GTM Kit requires WordPress 6.9, which includes the Abilities API, so nothing else is needed on the GTM Kit side. The abilities are registered by default.

2. Install the WordPress MCP Adapter

The WordPress MCP Adapter exposes your site’s abilities to AI assistants. Install and activate it following its own instructions.

3. Connect your assistant

Follow the MCP Adapter’s instructions for your assistant. For a remote site this usually means an application password for an administrator account (Users → Profile → Application Passwords). Use an account that is allowed to manage options, or the GTM Kit abilities will refuse to run.

4. Ask

Ask your assistant about your GTM Kit setup. It finds the GTM Kit abilities in the list the MCP Adapter provides and calls the one that fits the question.

Verify it worked

Ask the assistant which GTM container ID your site uses. It should give the ID shown under GTM Kit → Setup. Then ask for the GTM Kit Site Health results and compare them with Tools → Site Health. They come from the same checks, so they should match.

Turn it off

To keep GTM Kit out of the Abilities API, and so out of every AI assistant connected to your site, return false from the gtmkit_abilities_enabled filter. Add it from a plugin or your theme’s functions.php: WordPress builds its list of abilities once per request, early, so a filter added later has no effect.

add_filter( 'gtmkit_abilities_enabled', '__return_false' );

Common issues

The assistant does not see any GTM Kit abilities. Check that GTM Kit is 2.21 or later, that the MCP Adapter is active, and that nothing on the site returns false from gtmkit_abilities_enabled.

The assistant sees the abilities but gets an error running them. The account it connects with cannot manage options. Connect with an administrator account.

The gateway or sample-page results look out of date. They are the results GTM Kit stored the last time those checks ran, so the abilities never trigger a request of their own. The answer includes when each check ran.

← Previous

Previous article

Next →

Next article