Skip to content
Back to skills

Quireink Write

ASecurity

Write, edit, publish and steward a Quire Ink blog through its built-in MCP server — drafting and scheduling posts, tagging and taxonomy, media, the composed front page, traffic reports, comment moderation, backups and the archive audit. Use when the user asks you to write or publish to their blog, report on its readers, tidy its archive, or moderate its comments.

  • 35 stars
  • 0 votes
  • 0 copies
  • 1 view
  • Added September 19, 2026
content-marketinggorailsdebugging

Works with

  • cli
  • mcp

Security analysis

A100/100

Scanned October 5, 2026

npx -y skills add joiha-steven/quireink --skill quireink-write --agent claude-code

Installs into .claude/skills of the current project.

Are you the author of Quireink Write?

Add the live security badge to your README. It updates with every re-scan.

Security grade badge for Quireink Write
[![Security: A — Skills Directory](https://www.skillsdirectory.com/api/skills/joiha-steven-quireink-write/badge)](https://www.skillsdirectory.com/skills/joiha-steven-quireink-write)

More formats (shields.io, HTML) on the badges page. Keep it an A: scan every change in CI with Pro.

Download with Pro
SKILL.md
---
name: quireink-write
description: Write, edit, publish and steward a Quire Ink blog through its built-in MCP server — drafting and scheduling posts, tagging and taxonomy, media, the composed front page, traffic reports, comment moderation, backups and the archive audit. Use when the user asks you to write or publish to their blog, report on its readers, tidy its archive, or moderate its comments.
---

# Working a Quire Ink blog over MCP

Every tool below is a thin wrapper over the same functions the admin calls: same slug
rules, same revisions, same soft delete, same activity log. Nothing you do here is a
side door, which also means nothing you break here is invisible to the owner.

Tool internals: [`docs/mcp.md`](../../../docs/mcp.md). Worked prompts:
[`docs/agent-cookbook.md`](../../../docs/agent-cookbook.md).

## Before the first call

MCP is **off until the owner turns it on** (Admin → Settings → Server & connections → MCP) and
issues a token. Tokens are shown once, hashed after that, and **expire 180 days after
creation**. A 401 on every call usually means one of those two things, not a bug worth
debugging: ask the owner to check the toggle and the token's age.

## The surface, in the order you will reach for it

**Writing.** `create_post` `update_post` `patch_post` `get_post` `list_posts`
`delete_post` · `create_page` `update_page` `get_page` `list_pages` `delete_page` ·
`list_categories` `list_tags`

**The notebook.** `list_notes` `get_note` `create_note` `update_note` `delete_note`
`restore_note` · `list_mentions`. A note is a third kind of writing, kept apart from the
posts: it never joins the feed, the front page or the newsletter, and lives under
`/notes/{slug}` in its own namespace. A note with `sourceUrl` is a clip — pass `sourceUrl`,
`sourceTitle` and `quote` as fields, never folded into the body, because a clip that names
its source sends a Webmention to it when published. `list_mentions` answers two questions:
which pages elsewhere link here, and which passages readers keep most.

**The site itself.** `compose_homepage` (the composed front: lead, picks, category rows,
most-read) · `update_appearance` (palette, fonts, sizes) · `get_settings` ·
`list_settings` (every setting that can be changed: path, type, value now — call it to FIND
a path rather than guessing one) · `update_settings` (any of those paths; it wrote three
fields before 2.2.4). Two are worth naming before you change them, because they affect every
page a reader loads: `customCss` and `siteUrl`.

**Media and files.** `add_media_from_url` `list_media` `delete_media` · `import_images`
(one batch per call: fetch images still loading from other hosts into the library and
rewrite the references; loop until `remaining` is 0, stop early on `moved: 0`) ·
`list_files` `delete_file`

**Reading the blog.** `get_traffic` `get_post_traffic` `get_audience` `search_posts`
(the owner's own full-text search, drafts included) `get_update_status`

**Stewarding.** `list_comments` `reply_comment` `delete_comment` · `create_snapshot`
(a backup) · `send_test_newsletter` · the trash: `list_trashed_posts`
`list_trashed_pages` `list_trashed_media` `list_trashed_files` and the matching
`restore_post` `restore_page` `restore_media` `restore_file`

## What is deliberately not here

**Subscriber email addresses, and commenters' emails and IPs, are unreachable over MCP,
ever.** `get_audience` returns counts. An agent stewarding a blog needs numbers and words,
not identities. There is no tool that broadcasts a newsletter to real subscribers
(`send_test_newsletter` goes to the owner) and none that mints a token. If a task seems to
need one of those, say so and hand it back — do not look for a way around it.

## House rules for writing

- **Draft by default.** Create as a draft and say it is waiting, unless the user asked for
  it live. Publishing is one edit away for them; unpublishing something readers already saw
  is not.
- **Write Markdown, in their voice.** Read two or three of their recent posts with
  `get_post` before writing the first one. The blog stores Markdown, so what you write is
  what is kept, not a conversion of it.
- **Slugs are the site's memory.** `update_post`, `update_page` and `update_note` keep the slug
  you pass; only `newSlug` renames, and a rename leaves a redirect behind automatically. Do
  not rename slugs in bulk to tidy them. Old links in other people's posts are the point.
- **Excerpt, categories, tags, every time.** They drive the front page, the rails and search.
  An excerpt left blank is derived from the opening and follows the body on every save
  (`excerptAuto: true` on the post); write one when the opening is not a summary. An audit
  that finds categories and tags missing is the most common real job on this blog.
- **Deleting is soft.** Everything lands in Trash and the owner can restore it. You cannot
  destroy anything permanently; only they can, in the admin. This is not a reason to be
  casual — a trashed post is off the site immediately.

## Jobs worth knowing by shape

- **The Monday report.** `get_traffic` for 7 days against the 7 before, then plain words:
  what was read, where from, what grew, what fell — and one suggestion for the next post
  based on which existing posts still pull readers.
- **The archive audit.** Walk published posts; report missing categories and tags, derived
  excerpts where the opening does not summarise the post, plus pairs that cover overlapping
  ground and should link to each other. Report first, change nothing until told.
- **The moderation sweep.** `list_comments`, flag spam or abuse **with the reason**, and
  trash only after the owner confirms. Comments already pass a gate the blog runs itself
  (ADR 0032), so what reaches the queue is what got through it, not the raw firehose.
- **The front page.** `compose_homepage` curates the composed front the owner designed.
  Order the rows by what people actually read; do not invent a new layout for them.
- **Before anything destructive**, `create_snapshot`.

## Do not

- Do not publish, delete or email on your own initiative. Drafts and reports are yours;
  anything a reader would see is theirs.
- Do not paste the MCP token into a file, a commit, or a message. If you have seen one, it
  is already too widely known — tell the owner to rotate it.
- Do not fabricate figures. If `get_traffic` returns nothing for a window, say the window is
  empty; a blog with no readers yet is a fact, not an error to paper over.

Attribution

Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.

Comments

Loading comments…