plugin-icon

SmartCloud Agent Composer

Governed configuration, validation, and draft-only execution for agent-ready Gutenberg sites.
版本
1.0.1
最后更新
Aug 5, 2026
SmartCloud Agent Composer

SmartCloud Agent Composer adds a controlled WordPress layer for agent-assisted Gutenberg workflows. Administrators define versioned Config Sets with site contracts, page-type Blueprints, approved patterns, structured fields, relations, media policy, and safety rules. Agents can create or revise only validated, Composer-owned drafts.

Composer registers its governed Abilities through the separate WordPress MCP Adapter at /wp-json/mcp/smartcloud-agent-composer. A compatible authenticated MCP client can connect directly; an OpenAI Connector tunnel is optional and is not bundled.

Core operation runs inside WordPress without requiring a WP Suite account, subscription, hosted service, provider plugin, or proprietary theme. Optional integrations are disclosed under External Services.

Key features

  • Draft-only agent execution with separate WordPress authorship and Composer ownership.
  • Explicitly validated and activated Config Sets; imports and edits never activate automatically.
  • Optimistic concurrency for configuration and draft changes.
  • Gutenberg block-tree, pattern, template, post-type, language, excerpt, field, and relation validation.
  • Document and structured-record Blueprints, including registered REST-visible fields approved by the Site Contract.
  • Human-readable, ordered relation editing constrained by allowed target types, statuses, and cardinality.
  • Existing-image assignment and optional bounded raster ingestion from approved HTTPS hosts.
  • Short-lived preview drafts with ownership-checked cleanup.
  • Redacted, tamper-evident audit events in an append-only SHA-256 hash chain.
  • Checksum-protected Config Set lifecycle and active-theme/provider discovery.

Documentation: https://wpsuite.io/docs/

This plugin is not affiliated with or endorsed by the WordPress Foundation. All trademarks are property of their respective owners.

Usage Notice

Composer does not grant anonymous access or general WordPress administration. The dedicated smartcloud_agent role has no publishing, normal-content deletion, plugin, theme, user, arbitrary media-upload, or unfiltered-HTML capabilities.

Composer never publishes agent-created content. It deletes only expired, Composer-owned temporary previews. Optional remote ingestion is restricted to allowlisted HTTPS hosts and Composer-owned drafts; it is not a general Media Library API.

External Services

Composer’s configuration, validation, audit, ownership, concurrency, pattern assembly, local media lookup, and preview handling run inside WordPress. Optional features can make the following requests. Composer never downloads executable PHP from a remote service.

  1. Provider-owned WordPress Abilities (optional)

    • Used only when an administrator enables a provider integration and an authenticated agent requests that provider’s operation.
    • Composer passes the validated component input and non-secret execution context to the provider Ability in the same WordPress request. The provider plugin may then contact its configured service.
    • Review the provider plugin’s terms, privacy policy, endpoint, transmitted data, and retention before enabling it.
  2. Administrator-approved remote media sources (optional)

    • Used only when the active Site Contract enables remote ingestion, lists the exact HTTPS host, and an authenticated Composer agent with the dedicated capability requests one image.
    • Composer sends a normal HTTPS image request with its user-agent and standard network headers. It does not send draft content, WordPress credentials, cookies, or portable configuration secrets.
    • The bounded response is restricted to allowed raster MIME types, validated, fingerprinted, stored in the local Media Library, and assignable only to a Composer-owned draft. HTTP, redirects, embedded credentials, custom ports, and non-allowlisted hosts are rejected.
    • The administrator must verify the source’s reuse rights, terms, and privacy policy.
  3. WP Suite platform connection (optional)

    • Used only when an administrator connects the packaged shared Hub to a WP Suite workspace or enables shared account, entitlement, license, configuration, or subscription features.
    • Minimal site/workspace identifiers, plugin and capability metadata, and authentication/session data may be sent by HTTPS to wpsuite.io or api.wpsuite.io. Opening Composer alone does not send draft content.
    • Privacy: https://wpsuite.io/privacy-policy
    • Terms: https://wpsuite.io/terms-of-use
  4. Amazon Cognito (optional)

    • Used when an administrator signs in through the shared Hub or a Cognito-protected integration.
    • Authentication identifiers, session data, and authorization tokens required by the configured user pool may be sent. Composer excludes Cognito passwords from portable packages and audit events.
    • AWS Service Terms: https://aws.amazon.com/service-terms/
    • AWS Privacy: https://aws.amazon.com/privacy/
  5. Stripe (optional)

    • Used only when an administrator opens an optional WP Suite subscription or purchase flow in the shared Hub.
    • Browser/session and payment-flow data required by Stripe may be sent. Stripe handles card data; Composer does not store it.
    • Terms: https://stripe.com/legal/consumer
    • Privacy: https://stripe.com/privacy

The documentation, GitHub, and npm links in this readme are informational and are not contacted merely because the plugin is installed.

Privacy

Composer stores Config Sets, private execution metadata, validation state, and redacted audit events in WordPress. Audit events retain hashes and allowlisted/redacted context rather than credentials or full page content. Secret-like keys are rejected from imports and redacted from audit context.

Uninstall removes Composer configuration, options, scheduled cleanup, dedicated role and capabilities, audit table, and owned temporary previews from sites where it stored data. Ordinary drafts remain WordPress content. Export configuration first if it may be needed later.

Source & Build

Human-readable source and reproducible build instructions: https://github.com/smartcloudsol/agent-composer

Public TypeScript contracts: https://www.npmjs.com/package/@smart-cloud/agent-composer-core

The distributed JavaScript and CSS are built from public admin/src and core sources. PHP owns registration, authorization, persistence, audit, portability, and execution. The release assembler adds the shared Hub runtime, verifies the package, normalizes timestamps, and records SHA-256 checksums.

免费基于付费套餐
通过安装,您同意 WordPress.com 服务条款第三方插件条款
目前已测试版本
WordPress 7.0.2
这个插件是可用的下载,适用于您的站点。