## Build and distribution checklist

Finish an extension as an operated capability\,&#32;not just a source file\.

### Domain and authority

- \[&#32;\]&#32;The goal names a real user need and the chosen extension surface\.
- \[&#32;\]&#32;Model\-required capability has a supported tool interface\.
- \[&#32;\]&#32;IDs\,&#32;revisions\,&#32;availability and errors are explicit\.
- \[&#32;\]&#32;Human commands and tools share domain rules where required\.
- \[&#32;\]&#32;No tool can infer authority from untrusted text\.
- \[&#32;\]&#32;Cancellation before\/after commit is documented\.
- \[&#32;\]&#32;Pending permission dialogs cannot restore revoked authority\.
- \[&#32;\]&#32;Host approval labels are not described as a JavaScript sandbox\.

### State and lifecycle

- \[&#32;\]&#32;Module\,&#32;binding\,&#32;transcript\,&#32;branch and process lifetimes are documented\.
- \[&#32;\]&#32;Branch\-derived state uses&#32;`getBranch()`\.
- \[&#32;\]&#32;Stored data is validated and versioned\.
- \[&#32;\]&#32;Session switch\,&#32;tree movement\,&#32;branching and reopen are tested\.
- \[&#32;\]&#32;Reload claims match the actual host path\.
- \[&#32;\]&#32;Background work has cancellation and ownership\.
- \[&#32;\]&#32;Durable work retains target\,&#32;delivery ID\,&#32;body and retry state\.
- \[&#32;\]&#32;No cross\-process coordination is implied without a real backend\/lock\.

### UI and machine access

- \[&#32;\]&#32;Terminal\-only features use&#32;`mode === "tui"`\.
- \[&#32;\]&#32;Generic&#32;`hasUI`&#32;is not treated as complete method support\.
- \[&#32;\]&#32;Standard dialogs handle undefined\/false and optional ask\/chat results\.
- \[&#32;\]&#32;Timeout fallback is not treated as consent\.
- \[&#32;\]&#32;Tool content remains useful without custom rendering\.
- \[&#32;\]&#32;Custom components sanitize data and respect visible width\.
- \[&#32;\]&#32;Abort\/dispose restores focus and composer state\.
- \[&#32;\]&#32;RPC\/ACP degraded behavior is documented and tested\.
- \[&#32;\]&#32;Accessibility gaps are acknowledged\;&#32;semantic alternatives remain available\.

### Loading and packaging

- \[&#32;\]&#32;Entries export a valid default factory\.
- \[&#32;\]&#32;Manifest entries point to shipped files\.
- \[&#32;\]&#32;Adjacent text\/JSON assets are included\.
- \[&#32;\]&#32;Helpers are not placed where loose scanning imports them accidentally\.
- \[&#32;\]&#32;Runtime dependencies and compatible host versions are documented\.
- \[&#32;\]&#32;Optional features do not run through unconditional imports\.
- \[&#32;\]&#32;Name\,&#32;flag\,&#32;renderer and shortcut collisions are checked separately\.
- \[&#32;\]&#32;Configured paths are resolved against the intended cwd\.
- \[&#32;\]&#32;Installation scope is stated accurately\.
- \[&#32;\]&#32;Disable\/removal has been checked against every discovery route\.

### Verification and release

- \[&#32;\]&#32;Types were checked against the matching build\.
- \[&#32;\]&#32;Pure domain tests assert useful state changes\,&#32;not only fixture equality\.
- \[&#32;\]&#32;Real loader\/runner\/session scenarios pass\.
- \[&#32;\]&#32;Actual TUI composer behavior was tested where claimed\.
- \[&#32;\]&#32;Protocol cancellation and late replies were tested\.
- \[&#32;\]&#32;Real service tests are claimed only when actually run\.
- \[&#32;\]&#32;Failure recovery has an operator\-readable path\.
- \[&#32;\]&#32;The distributed archive contains no credentials\,&#32;private sessions or local machine paths\.
- \[&#32;\]&#32;A clean extraction can load the intended entries\.
- \[&#32;\]&#32;A release note states what was tested and what remains unverified\.

The public workbook packages remain marked&#32;`private: true`\.&#32;If you turn a copy into a real distributed package\,&#32;choose your own package identity\,&#32;licensing\,&#32;versioning and publication route\.&#32;No registry publication or install success is claimed by this workbook\.
