docs/plans/2026-09-04-review-media-download-behavior.md
Objective: Resolve the private media report with shipped-state proof; done when valid and fixed/released/published, or invalid/duplicate and closed with exact readback; plan docs/plans/2026-09-04-review-media-download-behavior.md.
Goal plan: docs/plans/2026-09-04-review-media-download-behavior.md
Template: docs/plans/templates/task.md
Primary template: docs/plans/templates/task.md
Applied packs:
Task source:
Timed checkpoint:
Completion threshold:
node .agents/skills/autogoal/scripts/check-complete.mjs docs/plans/2026-09-04-review-media-download-behavior.md passes.Verification surface:
Constraints:
Boundaries:
Output budget strategy:
rg searches; exclude generated registry JSON, templates, dependencies, build output, caches, and logs unless they are the named artifact.Blocked condition:
Task state:
Current verdict:
Pre-solution issue challenge:
Completion rule:
update_goal(status: complete) while any required checklist item
remains unchecked. If an item does not apply, check it and add N/A: <reason>.update_goal(status: complete) until every completion threshold
above is satisfied, final handoff evidence is recorded, and
node .agents/skills/autogoal/scripts/check-complete.mjs docs/plans/2026-09-04-review-media-download-behavior.md passes.Start Gates:
| Gate | Applies | Evidence |
|---|---|---|
| Timed checkpoint parsed | no | N/A: no duration requested |
| Skill analysis before edits | yes | Loaded full security-triage, autogoal, and task instructions before implementation |
| Active goal checked or created | yes | Previous goal was complete; created the matching the private media report goal |
| Source of truth read before edits | yes | Read the full repository advisory before any product-code edit |
| Tracker comments and attachments read | yes | Full advisory response contains body, metadata, credits, and collaborators; no separate comment or attachment surface is exposed |
| Video transcript evidence required | no | N/A: report contains no video evidence |
| Pre-solution issue challenge required | yes | Claim, suggested local fix, likely broader sink owner, and stale-version concern recorded above |
| Reproduction verdict before implementation | yes | No product code will change until focused current-source and shipped-artifact proof establishes a verdict |
| Repro escalation ladder selected | yes | Source/test -> existing repo harness when applicable -> approved browser -> screenshot waiver for invisible semantics |
| Suggested fix reviewed against durable boundary | yes | Import-only validation is provisionally rejected as incomplete because file nodes have multiple origins |
docs/solutions checked for non-trivial existing-code work | yes | Required before choosing a fix; use focused search for media/link URL precedent |
| TDD decision before behavior change or bug fix | yes | If valid, load tdd and capture red before green; invalid/duplicate outcome gets no product test |
| Branch decision for code-changing task | yes | Stay on main through triage; if valid, create a dedicated codex/ branch before product edits |
| Release artifact decision | yes | Valid published-package behavior requires a patch changeset; invalid/duplicate path requires none |
| Browser tool decision for browser surface | yes | Use approved Browser proof for actual file-link behavior when a runnable route exists |
| PR expectation decision | yes | Valid code change uses a sanitized public PR under prior user approval; no-code close does not create a PR |
| Dedicated task plan selected for exact PR | yes | This plan is dedicated to this advisory and any single resulting PR only |
| Tracker sync expectation decision | yes | Close or publish the repository advisory only after final shipped-state proof |
| Output budget strategy recorded | yes | Exact/capped searches and targeted artifact excerpts recorded above |
| Security advisory pack selected | yes | Materialized into this plan |
| Advisory source read through correct authority or explicit access blocker | yes | Full private repository advisory read through gh api repos/udecode/plate/security-advisories/... |
| Affected package, vulnerable range, and fixed-version target identified | yes | Reporter claims @platejs/markdown and @platejs/media; exact current affected range and fix target must be recomputed from npm artifacts before mutation |
| Disclosure/release order recorded | yes | If valid: merge, publish patched package, update metadata, request CVE, then publish advisory |
| Private/draft disclosure safety recorded | yes | Triage-state source; any public PR remains sanitized until fixed package availability |
| CVE decision recorded | yes | Request CVE after final metadata if valid; invalid/duplicate close records N/A reason |
| Package/API pack selected | yes | Materialized because published package behavior may change |
| Public surface or package boundary identified | yes | Markdown media node construction, media URL state, and registry file-link rendering are the claimed boundaries |
| Release artifact path selected | yes | .changeset if valid; N/A for no-code close |
changeset skill loaded when .changeset is required | yes | Load only after a valid verdict and before adding a changeset |
| Barrel/export impact decision recorded | yes | No export/layout change expected; rerun pnpm brl only if investigation changes that conclusion |
| Browser pack selected | yes | Materialized because the claim culminates in a browser navigation sink |
| Browser route / app surface identified | yes | Locate the registry file-element demo/route before browser proof; fallback is an executable loopback render of the actual owner |
| Browser tool decision recorded | yes | Approved Browser tool only; no standalone Playwright/Puppeteer substitution |
| Console/network caveat policy recorded | yes | Security URL/navigation proof owns the result; record console/network only where the route makes them meaningful |
Work Checklist:
<video-transcripts> XML, or marked N/A with reason.valid, not reproduced, invalid,
wont-fix, partially valid, or platform limitation. Feature, docs,
support, or cleanup requests with no bug claim may mark reproduction
N/A with reason.[@Browser](plugin://browser@openai-bundled) next when tests or
Playwright cannot reproduce or cannot model the surface honestly;
screenshot or explicit visual-proof waiver when visual/native state
matters.task invocation and dedicated plan; this plan is
not aggregate evidence for another PR.๐งญ Task plan: docs/plans/<plan>.md line, this file exists at the exact PR
head, and this plan records that exact PR number or URL..agents/**, .claude/**,
.codex/**, skills, hooks, commands, prompts, or user-action tooling.cve_id when available, credits/reporter when available, affected products, and current vulnerable ranges are recorded from the correct source authority or marked blocked by permissions.cve_id and is eligible, unless the user explicitly declines or a blocker is recorded; public GHSA/non-GitHub sources record existing CVE, GitHub/global owner, external CNA/request owner, or N/A reason.published_at when available, package, vulnerable range, patched version, CVE status, and propagation caveat or external-owner caveat..changeset, registry changelog, or explicit no-artifact reason..changeset work loads changeset and follows its package/version/prose rules.registry-changelog pack instead of adding a package changeset.main.Completion Gates:
| Gate | Applies | Required action | Evidence |
|---|---|---|---|
| Named verification threshold | yes | Run the command, proof, source audit, or artifact check named in this plan | Source/artifact audit, controlled browser proof, advisory close/comment/readback, and cleanup complete |
| Pre-solution issue challenge verdict | yes | Record reporter claim, suggested fix, repro verdict, validity verdict, durable boundary, and hard-stop/pivot decision before implementation | Invalid verdict and no-code hard stop recorded above |
| Repro escalation ladder | yes | For bug/behavior claims, record test/source-level, Playwright, Browser, and screenshot/visual-proof outcomes or N/A/blocker reasons before not reproduced | Detailed source/browser evidence retained in private maintainer records |
| Bug reproduced before fix | yes | Record failing test/repro or N/A with reason | Raw data flow reproduced, exact exploit disproved, so no fix is legal |
| Targeted behavior verification | yes | Run focused test/proof for changed behavior or record N/A | Detailed source/browser evidence retained in private maintainer records |
| TypeScript or typed config changed | no | Run relevant typecheck | N/A: no TypeScript or config product change |
| Package exports or file layout changed | no | Run pnpm brl before final verification and keep generated barrel updates | N/A: no export or layout change |
| Package manifests, lockfile, or install graph changed | no | Run pnpm install and relevant package checks | N/A: disposable .tmp probe dependencies were trashed |
| Agent rules or skills changed | no | Run pnpm install and verify generated skill sync | N/A: no agent, rule, or skill change |
| Workspace authority proof | yes | Run verification in the owning repo/package/app/route/tool and record cwd; do not count the wrong workspace as proof | Source/artifacts checked from /Users/zbeyens/git/plate; browser behavior checked through approved Browser surfaces |
| Browser surface changed | no | Capture Browser Use proof or record explicit waiver/blocker | N/A: no product browser surface changed |
| Browser final proof | yes | Attach screenshot or exact browser verification caveat when browser proof applies | DOM state plus server network logs recorded; screenshot N/A because execution/network is invisible |
| CI-controlled template output changed | no | Restore generated template output or record why it is intentionally kept | N/A: no template output changed |
| Package behavior or public API changed | no | Add a changeset or record why no changeset applies | N/A: no product patch |
| User-visible registry output changed | no | Use the registry-changelog pack: add/update apps/www/src/registry/changelog/entries/*.mdx, run node tooling/scripts/generate-ui-changelog-entries.mjs --write, run node tooling/scripts/generate-ui-changelog-entries.mjs --check, or record N/A | N/A: registry source unchanged |
| Docs or content changed | no | For docs-heavy work, use --template docs; for supporting public docs/content/API/example changes, load docs-creator and close the docs pack; for typo/link-only edits, record the explicit reason and proportional proof | N/A: only internal task evidence changed |
| High-risk mini gate | no | For public API/runtime/package-boundary/browser/agent-action/command-contract changes, record realistic failure mode, proof plan, and why the chosen boundary is right; otherwise N/A | N/A: no runtime or public API change |
| Agent-native review for agent/tooling changes | no | For .agents/**, .claude/**, .codex/**, skills, hooks, commands, prompts, or user-action tooling, load .agents/skills/agent-native-reviewer/SKILL.md and close accepted/actionable findings, or record N/A | N/A: no agent tooling changed |
| Local install corruption suspected | no | Run pnpm run reinstall once, rerun the exact failing command, or record N/A | N/A: no install-corruption signal |
| Autoreview for non-trivial implementation changes | no | Load .agents/skills/autoreview/SKILL.md; use dirty local --mode local, branch/PR --mode branch --base <base>, or committed slice --mode commit --commit <ref> until no accepted/actionable findings, or record N/A for docs-only/trivial/no local patch | N/A: no implementation patch |
| PR create or update | no | Run check before PR work and sync PR body to the task-style final handoff | N/A: invalid no-code close |
| Per-PR task ownership | no | Verify one task-plan body line, plan at exact head, and exact PR ownership in this plan | N/A: no PR |
| Task-style PR body verified | no | Verify the PR body with gh pr view --json body; it must preserve auto-release blocks when applicable, must not include a current-PR self-link, and must use the kitcn PR #270 emoji format: ๐ Fixes ..., ๐ข 95-100% confidence, Phase / ๐งช Tests / ๐ Browser table, and bold emoji Outcome/Caveat/Design/Verified sections | N/A: no PR body |
| PR proof image hosting | no | If PR body needs browser proof, replace local image paths with hosted GitHub URLs or record N/A | N/A: no PR |
| Tracker sync-back | yes | Post concise issue/Linear sync after PR exists, or record N/A/blocker | Private advisory closeout private discussion readback posted and read back |
| Final handoff contract | yes | Fill the final handoff fields below with exact PR/issue/confidence/tests/browser/outcome/caveats/design/verification content or N/A reason | Completed below |
| Final lint | no | Run pnpm lint:fix or scoped equivalent | N/A: no product source or generated code changed |
| Output budget discipline | yes | Verify no unbounded high-volume command output was streamed, or record the accidental output and recovery | Searches and artifact excerpts were scoped/capped; browser snapshots were exact proof surfaces |
| Timed checkpoint | no | If duration was requested, keep improving until elapsed, then finish the current loop cleanly; otherwise N/A | N/A: no duration requested |
| Goal plan complete | yes | Run node .agents/skills/autogoal/scripts/check-complete.mjs docs/plans/2026-09-04-review-media-download-behavior.md | Passed after final plan write |
| Advisory source read | yes | Read repo advisories through gh api repos/<owner>/<repo>/security-advisories/<GHSA_ID>, public read-only GHSA records through gh api advisories/<GHSA_ID>, npm-only advisories through npm/advisory registry source, or private reports through the provided report source; otherwise record access blocker | Full private repository advisory read through the repo-scoped API |
| Security repro / regression proof | yes | Record failing-before/passing-after proof, PoC validation, or N/A reason | Detailed source/browser evidence retained in private maintainer records |
| Private disclosure guard | yes | For private/draft/embargoed/not-yet-public sources, use repository advisory/private fork or sanitized public artifacts until approved disclosure; otherwise record N/A: already public | No public code, PR, release, or advisory publication; only private closeout note |
| Patched version published | no | Verify npm/package publish and GitHub release/tag when a package release is part of the fix | N/A: invalid report; no patch/version |
| Advisory metadata updated | no | For repository advisories, update affected product metadata with exact package, vulnerable range, and patched version; for public read-only GHSA/non-GitHub sources, record N/A with source owner/blocker | N/A: invalid report closed without publication; submitted ranges preserved as report history |
| Advisory published | no | Publish repository advisory after patched version availability, or record public GHSA/external/npm/private publication state or blocker | N/A: closed private without publication |
| CVE request decision | no | Request CVE through repository advisory API when applicable, or record existing CVE, GitHub/global owner, external CNA/request owner, or N/A reason | N/A: invalid report; cve_id=null retained |
| Advisory final readback | yes | Read back repository advisory state, published_at, cve_id, vulnerabilities, and URL, or record equivalent public GHSA/external source readback | API and authenticated UI show closed, unpublished, no CVE, reporter credited, and one closeout comment |
| Propagation caveat | no | Record GitHub review / Dependabot / advisory database propagation caveat, public GHSA/global owner, or external-source propagation owner in final handoff | N/A: private closed advisory has no public propagation |
| Public API / package boundary proof | yes | Source-audit public API, exports, and package boundary impact | Package data owners and registry click owner audited; no package API change |
| Release artifact classification | yes | Record whether the change is published package behavior/API/types/config/runtime, registry-only, or no published user-visible delta | No published user-visible delta |
| Published package changeset | no | If published package users see a delta, load changeset, add/update one .changeset/*.md per package, and prove no forbidden minor on @platejs/slate, @platejs/core, or platejs | N/A: no package change |
| Registry changelog | no | If the change is registry-only under apps/www/src/registry/**, use the registry-changelog pack and do not add a package changeset | N/A: no registry change |
| No release artifact | yes | If no artifact is needed, record the exact reason: internal-only, docs-only, agent-only, test-only, or no user-visible delta from main | Invalid no-code close; no user-visible delta from main |
| Package typecheck/build/test | no | Run owning package checks or record N/A with reason | N/A: no package source changed; runtime claim tested directly in supported React versions |
| Barrel/export generation | no | Run pnpm brl when exports or exported file layout changed, otherwise N/A | N/A: no export/layout change |
| Browser interaction proof | yes | Exercise the target route/interaction with the approved browser tool or record blocker | Detailed source/browser evidence retained in private maintainer records |
| Browser console/network check | yes | Record console/network state or why it is not applicable | Detailed source/browser evidence retained in private maintainer records |
| Browser final proof artifact | yes | Record screenshot/trace/route proof or exact caveat | Machine-readable accessibility DOM and network evidence recorded; screenshot waived for invisible semantics |
Phase / pass table:
| Phase | Status | Evidence | Next |
|---|---|---|---|
| Intake and source read | complete | Full private advisory, current owners, prior overlap, and latest npm artifacts inspected | controlled reproduction |
| Implementation | complete | N/A: invalid report; hard stop prohibited a product patch | verification |
| Verification | complete | Detailed source/browser evidence retained privately | private tracker closeout |
| PR / tracker sync | complete | N/A: no PR; advisory closed, reporter note posted, API and UI read back | closeout |
| Closeout | complete | Temporary harness trashed; plan and final goal checker recorded | final response |
Findings:
Decisions and tradeoffs:
Implementation notes:
Review fixes:
autoreview is not applicable to an invalid/no-code close.Error attempts:
| Error / failed attempt | Count | Next different move | Resolution |
|---|---|---|---|
| Private browser setup details | N/A | Retain detailed receipts privately | Closed in maintainer records |
Verification evidence:
Final handoff contract:
Task-style PR body contract:
<!-- auto-release:start --> block. If a changeset is
part of the diff and repo policy expects auto release, include that block.๐ Fixes #123 or ๐ Fixes โ N/A, then
exactly one ๐งญ Task plan: docs/plans/<plan>.md line, then an emoji
confidence line like ๐ข 95-100% confidence. The plan must exist at the
exact PR head and identify that exact PR.| Phase | ๐งช Tests | ๐ Browser |.Reproduced and Verified rows. Mark passing proof with ๐ข, repro or
failing proof with ๐ด, and non-applicable cells with โ N/A.**โ
Outcome**, **โ ๏ธ Caveat**,
**๐๏ธ Design**, and **๐งช Verified**.Summary / Verification PR body, an
adaptive prose body from a git helper skill, plain ## Outcome sections, or
an unrelated generated badge footer unless the caller or repo template
explicitly asks for it.gh pr view --json body output or a concise source-backed summary
of that output.Final handoff / sync:
Timeline:
Reboot status:
| Question | Answer |
|---|---|
| Where am I? | Closed invalid advisory; final mechanical goal check |
| Where am I going? | Final response |
| What is the goal? | Resolve the advisory with shipped-state and executable-boundary proof |
| What have I learned? | The raw value exists, but the exact shipped click boundary is inert in Chromium and Safari |
| What have I done? | Audited source/artifacts, ran controlled cross-engine proof, closed the advisory, thanked the reporter, and read back state |
Open risks: