features: /changes, /search, /fork, web_search, prompt memoization, per-turn spend cap, workspace refresh
- /changes diffs the last turn's file snapshot (added/modified/deleted), reusing undo infra via SnapshotStack.peek() - system prompt memoized behind version counters (notebook/memory/skills/plugins/tools/workspace); hit-rate in /cost, foundation for provider caching - web_search: DuckDuckGo Lite, keyless, 5 results, SSRF-filtered, in the net set with ask permission - /search <query>: full-text grep over saved sessions incl. tool-input JSON - workspace file list re-walks at a turn boundary after writes - maxSpendPerTurn: per-turn cap stops a runaway step with a notice - /fork: branch the session at the last turn boundary, original untouched 821 tests pass, typecheck clean, build green
This commit is contained in:
+13
-1
@@ -71,7 +71,7 @@ Sets let you switch off what a project does not need:
|
||||
| `nav` | `find_symbol` `json_query` | navigation and structured reads |
|
||||
| `extra` | 20 tools: line edits, fs inspect, git extensions, code/env reads | on by default |
|
||||
| `git` | `git_status` `git_diff` `git_log` `git_show` `git_blame` `git_branch` `git_commit_message` | ~2,180 B + message |
|
||||
| `net` | `web_fetch` | opt in |
|
||||
| `net` | `web_fetch`, `web_search` | opt in |
|
||||
|
||||
```json
|
||||
{ "toolSets": ["edit-plus"] }
|
||||
@@ -394,6 +394,18 @@ private and loopback addresses are refused, redirects are checked one hop at a t
|
||||
body is capped. The result is untrusted page content, not an instruction, and the call asks for
|
||||
approval. It belongs to the opt-in `net` set.
|
||||
|
||||
## `web_search`
|
||||
|
||||
```
|
||||
query what to search for
|
||||
```
|
||||
|
||||
Searches the web (DuckDuckGo Lite — no API key) and returns up to five results with title,
|
||||
URL, and snippet. Results are re-checked against the same private-address rule as `web_fetch`,
|
||||
so a result cannot point the model at localhost or a cloud metadata endpoint. Same `net` set,
|
||||
same approval, same "untrusted text" framing: search results are a stranger's claims, and a
|
||||
`web_fetch` on one of them is the right follow-up.
|
||||
|
||||
## Git tools
|
||||
|
||||
All five are read-only and therefore approval-free. Each spawns `git` with a fixed argument
|
||||
|
||||
Reference in New Issue
Block a user