chat — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited chat (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
Read this before creating chat widgets.
The chat component provides a full-featured conversational UI with:
/ to see commands){
"name": "create_chat_widget",
"arguments": {
"title": "AI Assistant",
"model": "gpt-4",
"system_prompt": "You are a helpful assistant.",
"streaming": true,
"provider": "openai"
}
}from pywry import App
from pywry.chat import ChatConfig, ChatWidgetConfig
app = App()
config = ChatWidgetConfig(
title="AI Chat",
height=600,
chat=ChatConfig(
system_prompt="You are helpful.",
model="gpt-4",
streaming=True,
provider="openai",
),
)
# Widget creation handled by MCP or directly via app.show()Creates a chat widget. Returns {widget_id, thread_id}.
| Parameter | Type | Default | Description |
|---|---|---|---|
| title | string | "Chat" | Window title |
| height | integer | 600 | Window height |
| system_prompt | string | "" | System prompt for LLM |
| model | string | "gpt-4" | Model name |
| temperature | number | 0.7 | Sampling temperature (0-2) |
| max_tokens | integer | 4096 | Max tokens per response |
| streaming | boolean | true | Enable streaming |
| persist | boolean | false | Persist threads in ChatStore |
| provider | string | — | "openai", "anthropic", "callback" |
| show_sidebar | boolean | true | Show thread sidebar |
| slash_commands | array | — | Custom slash commands |
Send a user message. Returns {message_id, thread_id, sent}.
Stop an in-flight generation. Idempotent. Returns partial content.
Thread CRUD: create, switch, delete, rename, list.
Register a slash command at runtime.
Paginated conversation history with cursor (before_id).
Update model, temperature, system prompt, etc.
Show/hide the typing indicator.
| Event | Payload |
|---|---|
chat:assistant-message | {messageId, text, threadId} |
chat:stream-chunk | {chunk, messageId, threadId, done} |
chat:typing-indicator | {typing, threadId} |
chat:switch-thread | {threadId} |
chat:update-thread-list | {threads: [{thread_id, title}]} |
chat:clear | {} |
chat:register-command | {name, description} |
chat:update-settings | {model, temperature, system_prompt} |
chat:state-response | {messages, threads, settings, activeThreadId} |
chat:generation-stopped | {messageId, threadId, partialContent} |
| Event | Payload |
|---|---|
chat:user-message | {text, threadId, timestamp} |
chat:slash-command | {command, args, threadId} |
chat:thread-create | {title} |
chat:thread-switch | {threadId} |
chat:thread-delete | {threadId} |
chat:settings-change | {key, value} |
chat:request-history | {threadId, limit} |
chat:stop-generation | {threadId, messageId} |
chat:request-state | {} |
chat:stop-generation sent to backendcancel_event on GenerationHandlecancel_event.is_set() between chunksGenerationCancelledError → partial content savedchat:generation-stopped with partial contentThe UI never waits for backend confirmation — recovery is instant.
| Command | Description |
|---|---|
/clear | Clear conversation |
/export | Export chat history |
/model | Switch model |
/system | Change system prompt |
Register custom commands via chat_register_command tool or ChatConfig.slash_commands list.
{"provider": "openai"}Requires openai package and OPENAI_API_KEY environment variable.
{"provider": "anthropic"}Requires anthropic package and ANTHROPIC_API_KEY environment variable.
from pywry.chat.providers.callback import CallbackProvider
provider = CallbackProvider(
prompt_fn=my_prompt, # (session_id, content_blocks, cancel_event) → AsyncIterator[SessionUpdate]
)| Constant | Value | Purpose |
|---|---|---|
| MAX_RENDERED_MESSAGES | 200 | DOM cap for performance |
| MAX_CONTENT_LENGTH | 100,000 | Per-message content limit |
| MAX_MESSAGES_PER_THREAD | 1,000 | Eviction threshold |
| STREAM_TIMEOUT_SECONDS | 30 | Max silence before timeout |
| SEND_COOLDOWN_MS | 1,000 | Input rate limit |
| GENERATION_HANDLE_TTL | 300 | Auto-expire stale handles |
~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.