Build and distribution checklist
Finish an extension as an operated capability, not just a source file.
Domain and authority
- [ ] The goal names a real user need and the chosen extension surface.
- [ ] Model-required capability has a supported tool interface.
- [ ] IDs, revisions, availability and errors are explicit.
- [ ] Human commands and tools share domain rules where required.
- [ ] No tool can infer authority from untrusted text.
- [ ] Cancellation before/after commit is documented.
- [ ] Pending permission dialogs cannot restore revoked authority.
- [ ] Host approval labels are not described as a JavaScript sandbox.
State and lifecycle
- [ ] Module, binding, transcript, branch and process lifetimes are documented.
- [ ] Branch-derived state uses
getBranch(). - [ ] Stored data is validated and versioned.
- [ ] Session switch, tree movement, branching and reopen are tested.
- [ ] Reload claims match the actual host path.
- [ ] Background work has cancellation and ownership.
- [ ] Durable work retains target, delivery ID, body and retry state.
- [ ] No cross-process coordination is implied without a real backend/lock.
UI and machine access
- [ ] Terminal-only features use
mode === "tui". - [ ] Generic
hasUIis not treated as complete method support. - [ ] Standard dialogs handle undefined/false and optional ask/chat results.
- [ ] Timeout fallback is not treated as consent.
- [ ] Tool content remains useful without custom rendering.
- [ ] Custom components sanitize data and respect visible width.
- [ ] Abort/dispose restores focus and composer state.
- [ ] RPC/ACP degraded behavior is documented and tested.
- [ ] Accessibility gaps are acknowledged; semantic alternatives remain available.
Loading and packaging
- [ ] Entries export a valid default factory.
- [ ] Manifest entries point to shipped files.
- [ ] Adjacent text/JSON assets are included.
- [ ] Helpers are not placed where loose scanning imports them accidentally.
- [ ] Runtime dependencies and compatible host versions are documented.
- [ ] Optional features do not run through unconditional imports.
- [ ] Name, flag, renderer and shortcut collisions are checked separately.
- [ ] Configured paths are resolved against the intended cwd.
- [ ] Installation scope is stated accurately.
- [ ] Disable/removal has been checked against every discovery route.
Verification and release
- [ ] Types were checked against the matching build.
- [ ] Pure domain tests assert useful state changes, not only fixture equality.
- [ ] Real loader/runner/session scenarios pass.
- [ ] Actual TUI composer behavior was tested where claimed.
- [ ] Protocol cancellation and late replies were tested.
- [ ] Real service tests are claimed only when actually run.
- [ ] Failure recovery has an operator-readable path.
- [ ] The distributed archive contains no credentials, private sessions or local machine paths.
- [ ] A clean extraction can load the intended entries.
- [ ] A release note states what was tested and what remains unverified.
The public workbook packages remain marked private: true. If you turn a copy into a real distributed package, choose your own package identity, licensing, versioning and publication route. No registry publication or install success is claimed by this workbook.
Extensions inside those boundaries · Source chapter: extensions/build-and-distribution-checklist. Original evidence remains scoped to its recorded snapshot.