Review Packet reading the whole packet
A local HTML file can contain embedded conversation data without being a self-contained offline viewer.
That distinction was not merely inferred. The completed browser check found that blocking the export’s CDN scripts left visible controls but no rendered transcript.
Milestone: Review offline without assuming the viewer works offline
Need. Noor wants to inspect the packet without allowing external requests.
Obstacle. The transcript is embedded, but two viewer dependencies are external.
The supplied template references:
https://cdnjs.cloudflare.com/ajax/libs/marked/15.0.4/marked.min.jshttps://cdnjs.cloudflare.com/ajax/libs/highlight.js/11.9.0/highlight.min.js
The template also inlines CSS, viewer JavaScript, and the generated tool renderer bundle. Those embedded assets do not remove the two external dependencies.
Exact action: if your browser environment can block external requests, keep them blocked when opening the fictional HTML. If you cannot establish that boundary, use the raw-file route below instead of calling the preview offline.
Recorded browser observation. With both CDN scripts blocked, controls such as Auto, Light, Dark, Default, No-tools, User, Labeled, and All remained visible. The transcript did not render.
Do not try to find messages or open Scout in that failed-render state.
Use the actual fictional journals as the offline fallback:
Terminal shell — read-only offline fallback, from extracted examples/:
cat review-packet/harbor-review.jsonl
cat review-packet/harbor-review/Scout.jsonl
cat review-packet/harbor-review/Scout/Checklist.jsonl
Find these fixture markers:
| File | Marker and meaning |
|---|---|
| Parent journal | PRE-CLEAR-HISTORY: the earlier fictional draft used a blue cover. |
| Parent journal | CURRENT-CONTEXT: the current review-packet request. |
| Scout journal | SCOUT-TRANSCRIPT: the fictional headings inspection. |
| Checklist journal | CHECKLIST-TRANSCRIPT: title, summary, and owner. |
The parent contains a saved reset_boundary between the earlier and current messages.
What changes? Only your inspection surface.
What does not change? Blocking scripts does not remove embedded data, and reading raw journals does not mutate them.
Failure and recovery. A blank viewer is an availability problem, not proof of an empty or sanitized packet. Stay with text inspection if external code loading is not permitted.
Self-check. Does “the data is embedded” imply “the viewer works without external scripts”?
Answer: No.
Inspect the actual embedded payload when needed
For this fictional output, you can inspect the embedded JSON without executing the HTML.
The following optional command uses the exact session-data tag emitted by the supplied template. Publication review executed this filter against a fictional file export, confirming the parent, Scout and Checklist data and the absence of top-level live prompt/tool fields.
Terminal shell — optional read-only payload inspection using jq, from extracted examples/:
jq -eRs '
capture("<script id=\"session-data\" type=\"application/json\">(?<payload>[^<]+)</script>")
| .payload
| @base64d
| fromjson
' review-packet/harbor-review.html
This reads a file, decodes its base64 JSON, and prints it. It does not run the embedded scripts or contact the CDN.
Inspect the header, all entries, leaf, and nested sessions—not just a matching phrase. In this file-based recipe, top-level live systemPrompt and tools fields should not have been supplied.
The command depends on the current template’s tag spelling. If it fails or produces no usable payload, treat that as an inspection failure, not as proof that no data exists. A different implementation may require a different approved inspection method.
Base64 is an encoding, not encryption. Someone who receives the HTML can recover its embedded data even if the visible viewer does not work.
Milestone: Follow the nested fictional review
Need. Noor wants to inspect the checklist work behind the parent’s task result.
Obstacle. The parent’s short result is not the complete nested transcript.
The supplied files use the exporter’s adjacent-directory convention:
Non-runnable reference — supplied fictional disk layout:
review-packet/harbor-review.jsonl
review-packet/harbor-review/Scout.jsonl
review-packet/harbor-review/Scout/Checklist.jsonl
Public copies:
collectSubSessions finds these recursively and embeds keys Scout and Scout/Checklist.
For an optional rendered preview, make a separate, explicit decision to allow the two public CDN scripts for this fictional packet only. If you decline, the raw and decoded JSON routes already provide the review material.
Only after permitting those requests and reloading the fictional HTML:
- Find the parent’s current-context and pre-clear-history content.
- Open Scout’s agent link.
- Open Checklist from within Scout.
- Confirm the nested checklist text.
- Press Escape to return from Checklist to Scout.
Do not use copy-link controls in this exercise.
Recorded browser check. Headless Chromium opened Scout and Checklist through keyboard interaction, displayed the checklist transcript, and returned to Scout on Escape. Pre-clear parent history was visible.
That browser check used a privately generated fictional live-state export, with explicitly fictional prompt/tool metadata. The runnable file-export recipe uses the same saved history and nesting convention but does not add that live metadata. Neither result is a claim about a reader’s browser or a real private session.
What changes? Viewer navigation changes the local displayed transcript.
What does not change? It does not switch a running OMP session or rewrite the saved journal.
Failure and recovery. If a nested link is unavailable, inspect the raw nested file and the actual payload. Missing directories, .bak filenames, and empty/corrupt journals can be omitted. Other access errors can fail collection. Absence from a packet is not proof that no nested work ever existed.
Self-check. Is the parent’s “Fictional review complete” result enough to establish what Checklist saw?
Answer: No. Inspect the nested transcript itself.
The visible leaf is not the disclosure boundary
HTML embeds all manager entries and the leaf identifier. It can therefore contain more than the currently displayed path.
Before disclosure, account for:
- Alternative and earlier branches.
- Pre-clear history.
- Tool inputs and outputs.
- Nested session content.
- Header cwd and additional roots.
- Parent references and other metadata.
- Fields that the viewer does not render.
The export helper removes previousSessionFiles from exported headers. It does not remove every path or identifying field.
Likewise, a No-tools filter, collapsed thinking, or hidden custom-message display does not delete embedded content. Even an All filter is a viewer control, not a complete field-by-field privacy audit.
includeSubSessions: false exists as a programmatic ExportOptions setting. It is not a supplied native slash flag. Do not invent an omit-nested command option.
Source anchors: packages/coding-agent/src/export/html/index.ts — buildSessionData, sessionHeaderForExport, collectSubSessions, generateHtml; packages/coding-agent/src/export/html/template.html; packages/coding-agent/src/export/html/template.js — bootSession, sub-session overlay functions; packages/collab-web/src/tool-render/tools/task.tsx — taskRenderer.
Sessions, resets, and reviewable history · Source chapter: continuity/review-packet-reading-the-whole-packet. Original evidence remains scoped to its recorded snapshot.