SenroFlux runs an agent loop on behalf of a logged-in user: one goal, many
model turns, many tool calls — pausing for a human whenever a write needs
approval, whenever the model needs to ask a clarifying question, or before
its first side-effecting write — and resuming exactly where it left off.
SenroFlux itself makes two kinds of outbound request, both only while a
human is actively driving a run from their own browser session — SenroFlux
never runs in the background.
Model calls (AI Client). Made through the WordPress AI Client (bundled
with WordPress 7.0+), using whichever provider your site has connected
under Settings Connectors — commonly OpenAI, but any provider the AI
Client supports. On every model turn (at most one per tick), SenroFlux
sends that provider:
senroflux_system_instructionNo file, database or site content is sent beyond what a run’s own tool
calls read and return as results. Sending and handling this data is
governed by the connected provider’s own terms. The site owner chooses the
AI provider, so that provider’s terms and privacy policy apply; see, for
example, OpenAI’s:
https://openai.com/policies/row-terms-of-use/ and
https://openai.com/policies/row-privacy-policy/ — consult your specific
provider’s terms if you have connected a different one.
Stock photo search (Openverse). When a run searches for a stock image
(pages/site packs), SenroFlux sends the model-generated search text as a
query string to Openverse’s public search API
(https://api.openverse.org/v1/images/) and to Openverse’s individual
image-detail endpoint when fetching a chosen result. No account
credentials, site content, or personal data are sent — only the search
terms and the id of a selected result. This runs only during an active,
human-driven run. See Openverse’s terms and privacy policy:
https://docs.openverse.org/terms_of_service.html and
https://openverse.org/privacy (Openverse is a WordPress.org project;
its privacy policy is https://wordpress.org/about/privacy/).
Image downloads. When a run imports a chosen stock photo or a generated
image, the plugin downloads the image file from the URL Openverse or the AI
provider returned (Openverse results are hosted by third-party sites such
as Flickr or Wikimedia Commons; an AI provider may instead return the image
data inline, in which case nothing is downloaded). Only the image URL is
requested, with no site data, and the file is then saved to your Media
Library.
SenroFlux stores each run in two custom tables: the ID of the user who
started it, the goal they typed, the conversation with the AI model, the
tool calls and their results, and timestamps. Runs stay until you remove
them or delete the plugin with the opt-in below.
Runs are sent off-site to the AI provider you connected, and search terms
are sent to Openverse; see “External services” above for exactly what.
SenroFlux adds suggested text for your privacy policy under Settings
Privacy Policy Guide. It does not register a personal-data exporter or
eraser.
Deleting the plugin keeps your runs by default. To remove all SenroFlux
data (both tables, its options, transients and per-user flags) when the
plugin is deleted, opt in first: wp option update senroflux_uninstall_delete_data 1,
then delete the plugin.
SENROFLUX_API_VERSION (currently 0.3.0, defined in senroflux.php) versions the declared
extension surface, independently of this plugin’s own Stable tag. Semver promise: a removal
or signature change needs a major bump; an addition needs a minor bump — this applies starting
at 0.3.0, even below 1.0.
The @api list: the Pack abstract class’s @api-tagged methods (name, roles,
abilityNamespaces, inputProperties, verbFor, objectIdKey/Prefix/ForWrite/ForRead,
roleCapabilities, withheldRoleNotice, verbMap, roleVerbs, ungrantableVerbs, governedNamespaces,
agentSafetyVerbMap, defaultBudget, skills, agentSafetyPack, validateCall, setupChecks,
runCapability, requiresAgentSafety, agentSafetyBindingError, guidesHash); the
Api\LayoutVocabulary facade (names, sectionSchema, validate, imageUrls, rulesLines); the
Skill/SkillSource/SetupCheck value types a pack constructs; and the senroflux_packs,
senroflux_run_skills and senroflux_default_budget filters. Every other filter, including
senroflux_can_tick and senroflux_http_consumers, is not part of this surface and may change
without a version bump.
REST (senroflux/v1) is the public @api consumer surface; admin-ajax is this plugin’s own private transport for its
bundled Runs screen and is not guaranteed to match REST’s shape.
Deprecation: a break goes through _deprecated_hook()/_deprecated_function() for at least
one minor release before removal at the next major. None exist yet.
See the “Extension API” section of README.md in the public repository,
https://github.com/specflux/senroflux, for the full reference, including how to
regenerate the reflection snapshot (tests/Api/public-surface.json there) that
enforces this.
The JavaScript in build/ is compiled from the sources in assets/src/ in
the public repository, https://github.com/specflux/senroflux. To rebuild it:
git clone https://github.com/specflux/senroflux.git && cd senrofluxnpm cinpm run build
npm run build runs wp-scripts build and writes build/.