Metadata-Version: 2.4
Name: fred-capability-html-artifact
Version: 4.4.3
Summary: Fred agent capability: render agent-generated static HTML/CSS in a sandboxed viewer beside the chat (html_artifact).
Author-email: Thales <noreply@thalesgroup.com>
License: Apache-2.0
Project-URL: Homepage, https://site.fredlab.dev
Project-URL: Repository, https://github.com/ThalesGroup/fred
Classifier: License :: OSI Approved :: Apache Software License
Classifier: Programming Language :: Python :: 3
Classifier: Programming Language :: Python :: 3 :: Only
Classifier: Operating System :: OS Independent
Requires-Python: <3.13,>=3.12
Description-Content-Type: text/markdown
Requires-Dist: fred-core>=4.4.3
Requires-Dist: fred-sdk[agents]>=4.4.3
Requires-Dist: pydantic<3.0.0,>=2.7.0
Requires-Dist: langchain-core>=0.3.0
Requires-Dist: langchain>=0.3.0
Provides-Extra: dev
Requires-Dist: bandit>=1.8.6; extra == "dev"
Requires-Dist: basedpyright==1.31.0; extra == "dev"
Requires-Dist: detect-secrets>=1.5.0; extra == "dev"
Requires-Dist: fred-runtime>=4.4.3; extra == "dev"
Requires-Dist: pytest>=8.4.2; extra == "dev"
Requires-Dist: pytest-asyncio>=1.2.0; extra == "dev"
Requires-Dist: pytest-cov>=6.2.1; extra == "dev"
Requires-Dist: pytest-socket>=0.7.0; extra == "dev"
Requires-Dist: ruff>=0.12.5; extra == "dev"

# fred-capability-html-artifact

A Fred agent capability (`html_artifact`) that lets an agent produce a **static
HTML/CSS artifact** rendered live in a **sandboxed viewer beside the chat** —
the "artifact" experience, scoped to static markup (no JavaScript) for v1.

Design: `docs/swift/rfc/HTML-ARTIFACT-CAPABILITY-RFC.md` (issue #2478).

## What it ships

- **Tool** `render_html_artifact(title, html, css, artifact_id?)` — HTML and CSS
  kept separate (for the viewer's tabs). Combined size is capped at 256 KB.
- **Chat part** `HtmlArtifactPart` (`type="html_artifact"`) carrying the markup
  **inline** — no owned table, no router, no migration (v1 is read-only; chat
  `ui_parts` persist across reload).
- **Prompt fragment** steering the model to call the tool (static only) instead of
  pasting code into the chat.
- **Side panel** `html_artifact_pane` (frontend): read-only tabs **Preview**
  (sandboxed `<iframe srcdoc>`) / **HTML** / **CSS** + download.

`execution_models=("react",)`: the prompt overlay is a `wrap_model_call` hook, so
the tool is carried by the capability's middleware (mirrors `writable_document`).

## Registration

Installing this package IS the registration — the `fred.capabilities` entry point
in `pyproject.toml` points the fred-agents pod at `HtmlArtifactCapability`. It is
wired into the pod as an editable path dependency of `apps/fred-agents`.

## Security

The markup is untrusted LLM output; the backend carries only inert strings. Safe
rendering is a frontend concern (RFC §4.7): the Preview iframe uses `sandbox`
**without** `allow-scripts`/`allow-same-origin` and a restrictive CSP, so no
script runs and no network egress is possible.

## Dev

```
make code-quality   # ruff + format + type-check
make test           # offline unit tests
```
