[WordPress] 外掛分享: SmartCloud Agent Composer

首頁外掛目錄 › SmartCloud Agent Composer
WordPress 外掛 SmartCloud Agent Composer 的封面圖片
全新外掛
安裝啟用
尚無評分
11 天前
最後更新
問題解決
WordPress 6.9+ PHP 8.1+ v1.1.1 上架:2026-08-03

內容簡介

SmartCloud Agent Composer 為代理協助的 Gutenberg 工作流程提供了一個受控的 WordPress 層。管理員可以定義版本化的配置集,確保代理僅能創建或修改經過驗證的草稿,提升內容管理的安全性與效率。

【主要功能】
• 代理執行僅限草稿,擁有獨立的 WordPress 作者與 Composer 所有權
• 明確驗證和啟用的配置集,導入和編輯不會自動啟用
• 極樂主義的並發處理配置和草稿變更
• Gutenberg 區塊樹、模式、模板、文章類型等驗證
• 文檔和結構化記錄藍圖,包含經網站合約批准的 REST 可見字段
• 限制目標類型、狀態和基數的人類可讀關係編輯

外掛標籤

開發者團隊

⬇ 下載最新版 (v1.1.1) 或搜尋安裝

① 下載 ZIP → 後台「外掛 › 安裝外掛 › 上傳外掛」
② 後台搜尋「SmartCloud Agent Composer」→ 直接安裝(推薦)
📦 歷史版本下載

原文外掛簡介

SmartCloud Agent Composer adds a controlled WordPress layer for agent-assisted Gutenberg workflows. Administrators define versioned Config Sets with site contracts, page-type Blueprints, approved patterns, structured fields, relations, media policy, and safety rules. Agents can create or revise only validated, Composer-owned drafts.
Composer registers its governed Abilities through the separate WordPress MCP Adapter at /wp-json/mcp/smartcloud-agent-composer. A compatible authenticated MCP client can connect directly; an OpenAI Connector tunnel is optional and is not bundled.
Core operation runs inside WordPress without requiring a WP Suite account, subscription, hosted service, provider plugin, or proprietary theme. Optional integrations are disclosed under External Services.
Key features

Draft-only agent execution with separate WordPress authorship and Composer ownership.
Explicitly validated and activated Config Sets; imports and edits never activate automatically.
Optimistic concurrency for configuration and draft changes.
Gutenberg block-tree, pattern, template, post-type, language, excerpt, field, and relation validation.
Document and structured-record Blueprints, including registered REST-visible fields approved by the Site Contract.
Human-readable, ordered relation editing constrained by allowed target types, statuses, and cardinality.
Existing-image assignment and optional bounded raster ingestion from approved HTTPS hosts.
Short-lived preview drafts with ownership-checked cleanup.
Redacted, tamper-evident audit events in an append-only SHA-256 hash chain.
Checksum-protected Config Set lifecycle and active-theme/provider discovery.

Documentation: https://wpsuite.io/docs/
This plugin is not affiliated with or endorsed by the WordPress Foundation. All trademarks are property of their respective owners.
Usage Notice
Composer does not grant anonymous access or general WordPress administration. The dedicated smartcloud_agent role has no publishing, normal-content deletion, plugin, theme, user, arbitrary media-upload, or unfiltered-HTML capabilities.
Composer never publishes agent-created content. It deletes only expired, Composer-owned temporary previews. Optional remote ingestion is restricted to allowlisted HTTPS hosts and Composer-owned drafts; it is not a general Media Library API.
External Services
Composer’s configuration, validation, audit, ownership, concurrency, pattern assembly, local media lookup, and preview handling run inside WordPress. Optional features can make the following requests. Composer never downloads executable PHP from a remote service.

Provider-owned WordPress Abilities (optional)

Used only when an administrator enables a provider integration and an authenticated agent requests that provider’s operation.
Composer passes the validated component input and non-secret execution context to the provider Ability in the same WordPress request. The provider plugin may then contact its configured service.
Review the provider plugin’s terms, privacy policy, endpoint, transmitted data, and retention before enabling it.

Administrator-approved remote media sources (optional)

Used only when the active Site Contract enables remote ingestion, lists the exact HTTPS host, and an authenticated Composer agent with the dedicated capability requests one image.
Composer sends a normal HTTPS image request with its user-agent and standard network headers. It does not send draft content, WordPress credentials, cookies, or portable configuration secrets.
The bounded response is restricted to allowed raster MIME types, validated, fingerprinted, stored in the local Media Library, and assignable only to a Composer-owned draft. HTTP, redirects, embedded credentials, custom ports, and non-allowlisted hosts are rejected.
The administrator must verify the source’s reuse rights, terms, and privacy policy.

WP Suite platform connection (optional)

Used only when an administrator connects the packaged shared Hub to a WP Suite workspace or enables shared account, entitlement, license, configuration, or subscription features.
Minimal site/workspace identifiers, plugin and capability metadata, and authentication/session data may be sent by HTTPS to wpsuite.io or api.wpsuite.io. Opening Composer alone does not send draft content.
Privacy: https://wpsuite.io/privacy-policy
Terms: https://wpsuite.io/terms-of-use

Amazon Cognito (optional)

Used when an administrator signs in through the shared Hub or a Cognito-protected integration.
Authentication identifiers, session data, and authorization tokens required by the configured user pool may be sent. Composer excludes Cognito passwords from portable packages and audit events.
AWS Service Terms: https://aws.amazon.com/service-terms/
AWS Privacy: https://aws.amazon.com/privacy/

Stripe (optional)

Used only when an administrator opens an optional WP Suite subscription or purchase flow in the shared Hub.
Browser/session and payment-flow data required by Stripe may be sent. Stripe handles card data; Composer does not store it.
Terms: https://stripe.com/legal/consumer
Privacy: https://stripe.com/privacy

The documentation, GitHub, and npm links in this readme are informational and are not contacted merely because the plugin is installed.
Privacy
Composer stores Config Sets, private execution metadata, validation state, and redacted audit events in WordPress. Audit events retain hashes and allowlisted/redacted context rather than credentials or full page content. Secret-like keys are rejected from imports and redacted from audit context.
Uninstall removes Composer configuration, options, scheduled cleanup, dedicated role and capabilities, audit table, and owned temporary previews from sites where it stored data. Ordinary drafts remain WordPress content. Export configuration first if it may be needed later.
Source & Build
Human-readable source and reproducible build instructions:
https://github.com/smartcloudsol/agent-composer
Public TypeScript contracts:
https://www.npmjs.com/package/@smart-cloud/agent-composer-core
The distributed JavaScript and CSS are built from public admin/src and core sources. PHP owns registration, authorization, persistence, audit, portability, and execution. The release assembler adds the shared Hub runtime, verifies the package, normalizes timestamps, and records SHA-256 checksums.

延伸相關外掛

文章
Filter
Mastodon