Extensions inside those boundaries
The earlier parts established what the runtime keeps, what it shares, and what an operation does not prove. This part turns those lessons into interface design.
Start with the smallest appropriate surface. A human command can answer locally. A model-callable tool needs a schema and a useful result contract. A skill supplies guidance, not executable enforcement. An SDK host owns initialization and disposal. A plugin selects distribution entries; installing it and executing a factory are different events.
Follow the progressive projects
Seed Desk begins with a welcome command and a read-only tool over the same fictional information. It grows into inventory queries, then branch-local reservations with exact IDs, revision checks, human-granted authority, and persisted state. Load only one complete Seed Desk stage at a time: all stages intentionally own /seeds.
Review Desk keeps a different promise. A person can edit and accept a release note locally; acceptance does not publish it. The agent’s one-action grant is held in memory and tied to the session and revision. Pending dialogs must be aborted and generation-invalidated so a late positive response cannot restore revoked authority. Standard dialogs and a native panel expose the same small domain through different presentation capabilities.
Package Lab follows Field Notes from one file to helpers, a manifest, optional features, and an embedded SDK host. Its selection is factory-local, not transcript-local: a new conversation can reuse the same closure. The package chapters make that lifetime correction explicit rather than concealing it behind the word session.
All supplied files remain available under their original paths in the complete archive, including adjacent descriptions, JSON fixtures, manifests, and helper modules. Additional complete exercises printed in the chapters remain printed exercises; they are not silently relabelled as separately observed downloads.
Match the host before claiming the behavior
The examples target the recorded custom build. Bun and the named runtime packages are real prerequisites where used. Do not replace an unavailable custom dependency with an unrelated upstream package and call the original example verified.
Binding a factory is not initializing its live actions. A session reload is not necessarily a factory reimport. hasUI is not proof that a native component works in RPC or ACP. A provider appearing in a catalog is not proof of authentication or inference. A file-fallback adapter is not an elevated writer without a real host broker and policy.
Those distinctions are part of the teaching, not unfinished work to paper over with successful no-ops.
Keep authority inside the domain
Host approval, the example’s human grant, and operating-system authority are separate gates. In-process extension code is trusted code; isProjectTrusted() is not a sandbox in the described build. Revisions prevent stale actions only when the domain validates them, and cancellation before commit is different from cancellation after a stored effect.
Read the focused laboratories after the progressive projects, then use the complete public feature inventory and all 46 event descriptions as references. The final debugging and distribution chapters explain what evidence is needed at each layer. No real provider, authentication, privileged-broker, or publication exercise is added by this unified edition.
Extensions inside those boundaries · Unified editorial chapter; connects the recorded source material without rerunning it.