Model returns tool_call → execute → send result back → continue; first tool: current time. (Exception: structural changes to the Chat class are allowed to support tool_calls delta)
child_process runs commands, with timeout + output truncation + confirmation before execution (confirmation logic extracted as a standalone function, ready for a later permission model to replace)
ls/read/glob are read-only and need no confirmation; write/patch show a diff + confirmation before writing; the 7 accumulated tools get a unified Tool interface + registry — the Agent closes the loop on "read → modify → verify" for the first time
A persistent right-side panel shows per-turn/cumulative tokens and context usage ratio in real time; streamed replies and tool progress lines all enter the main area with coloring. Alt screen + two-pane full-frame redraw
Phase C: Safety & Permissions (Day 8) — Dares to act, and can contain the blast radius
Tool-level policy (ask/allow/deny) and the allowed root directory are configured via .geekagent/GeekAgent.json; file tools only read/write inside the root, tool results automatically mask KEY-type environment variables; the latest state is backed up before writing files, /undo restores
Phase D: Capability Upgrades (Day 9–12) — More like a real Agent
Project-root AGENTS.md fully injected into the system prompt; important runtime conclusions written to a memory file, searched by keyword and reused across sessions
memory_search upgrades from "whole-entry keyword inclusion" to "windowed chunking + BM25 scoring", hitting precise paragraphs even in long entries; each turn slices the user's input into bigrams for automatic retrieval, relevant memories are injected straight into the system prompt — the model doesn't have to remember to search
rag_add batch collection (internal fetch, full text to disk, bypassing model context) → chunking → reuses Day 13's BM25 scoring → rag_search retrieves with sources by question; the /rag command builds the index offline
Phase F: Ecosystem Connectivity (Day 15–16) — Tools you don't have to write
.geekagent/mcp.json declares servers; at startup spawn subprocesses and exchange line-delimited JSON-RPC over stdio: initialize handshake → tools/list → register as mcp_<server>_<tool> into the Day 4 registry; calls are forwarded as tools/call, defaulting to ask confirmation
At startup scan plugins/*/plugin.ts, register commands, tools and lifecycle hooks through a PluginContext; an echo plugin demonstrates the extension points, a web plugin starts an HTTP service and reuses the existing chat & tool loop over SSE