Skip to content

Add read-file ability with code block rendering - #99

Merged
pluginslab merged 2 commits into
devfrom
feature/read-file-ability
Mar 21, 2026
Merged

pluginslab merged 2 commits into
devfrom
feature/read-file-ability

Conversation

@moritzbappert

@moritzbappert moritzbappert commented Mar 21, 2026 •

Copy link
Copy Markdown
Collaborator

Summary

  • Adds a `read-file` ability that reads any file within WordPress root (ABSPATH) and redacts sensitive values (DB credentials, auth keys/salts, tokens) server-side before content reaches the LLM
  • Introduces `preferSummarize` pattern: the ReAct agent short-circuits after the tool call, skipping the second LLM pass entirely — file content is displayed instantly in a styled code block rather than being truncated or paraphrased by the 512-token limit
  • Adds fenced code block rendering to the chat UI with language badge, copy button, and progressive streaming support for partial blocks; inline backtick spans now render as styled monospace
  • Adds namespace fallback in `executeTool` so the LLM can call tools with or without the `wp-agentic-admin/` prefix

Changes

  • `includes/abilities/read-file.php` — PHP ability with path traversal protection, smart bare filename resolution (root files + active theme), generalised redaction regex
  • `src/extensions/abilities/read-file.js` — JS ability with `preferSummarize: true`, `extractFilePath()`, `detectLanguage()`, `summarize()`, `interpretResult()`
  • `src/extensions/services/react-agent.js` — `preferSummarize` short-circuit + namespace fallback in `executeTool`
  • `src/extensions/services/chat-orchestrator.js` — `skipStreaming` support; skips stream simulator for pre-computed content
  • `src/extensions/components/MessageItem.jsx` — `parseBlocks()` for fenced code splitting (handles partial/streaming blocks), `CodeBlock` component, inline code styles, recursive bold parsing
  • `src/extensions/styles/main.scss` — `.agentic-code-block` dark styles, inline `code` styles in message text
  • `includes/class-abilities.php`, `src/extensions/abilities/index.js` — registration
  • `tests/abilities/core-abilities.test.js` — 4 test cases for read-file
  • `docs/ABILITIES-GUIDE.md` — new section documenting the `preferSummarize` pattern

Testing

  • Unit tests pass (npm test)
  • Ability tests pass (npm run test:abilities -- --file tests/abilities/core-abilities.test.js)
  • JS lint clean (npm run lint:js)
  • PHP lint clean (composer lint)
  • Manually tested in browser (if UI changes)

Notes

  • The `preferSummarize` pattern is documented in `docs/ABILITIES-GUIDE.md` for future ability authors
  • Sensitive value redaction covers `DB_` constants and any `define()` matching `_KEY`, `_SALT`, `_SECRET`, `_TOKEN`, `_PASS*`

- PHP ability reads any file within ABSPATH with sensitive values
  (DB credentials, auth keys, salts) automatically redacted server-side
- JS ability uses preferSummarize to bypass LLM and display file content
  instantly in a styled code block, avoiding 512-token truncation
- ReAct agent short-circuits after preferSummarize tools to skip the
  second LLM pass; chat orchestrator skips stream simulator for instant display
- MessageItem renders fenced code blocks progressively during streaming
  with language badge and copy button; inline backticks styled as monospace
- Namespace fallback in executeTool resolves bare tool names (e.g. "read-file"
  → "wp-agentic-admin/read-file") when LLM drops the prefix
- Documents preferSummarize pattern in ABILITIES-GUIDE.md

Co-Authored-By: Claude Sonnet 4.6 <[email protected]>
@moritzbappert moritzbappert added the enhancement New feature or request label Mar 21, 2026

@pluginslab pluginslab left a comment

Copy link
Copy Markdown
Owner

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

Test Results

All 4 read-file tests pass — 67/72 (93%) overall, failures are pre-existing/flaky. Welcome @moritzbappert! LGTM!

@pluginslab
pluginslab merged commit 3fbb6f8 into dev Mar 21, 2026
2 of 4 checks passed
ivdimova added a commit that referenced this pull request Mar 21, 2026
Merge commit c1704ae (PR #99) dropped the closing brace for the
read_file registration block, nesting all subsequent ability
registrations inside it and producing a PHP parse error.
Also fixes spaces-to-tabs on the database_check block from the same merge.

Co-Authored-By: Claude Opus 4.6 <[email protected]>
@pluginslab
pluginslab deleted the feature/read-file-ability branch May 27, 2026 23:04
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

enhancement New feature or request

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants