Make <Plan> expand inline by default #711

Description

@taras

Story

As an Executable Markdown author, I want an approved <Plan> to expand where I
wrote it, so a document can create and carry out a program without leaving the
current execution. When I need the approved source instead, I capture it with
as and none of that program runs.

Common path

Without as, <Plan> authors, reviews and approves one XMD program, then
expands the exact approved source inline at its invocation site:

Prepare the release program and carry it out here.
<Plan>
1. Read package.json and CHANGELOG.md.
2. Ask an Agent to recommend the next semantic version and explain why.
3. Validate the answer.
4. Ask me to approve it.
5. Write RELEASE.md.
</Plan>
The release program completed, so continue with the result.

The <Plan> content expands once to form the complete Prompt. Drafts stay
inert. After approval, the constrained authorship environment tears down, the
exact approved source is structurally admitted, and that source expands between
the surrounding prose.

An author who wants the approved program without carrying it out captures it:

<Planas="program">
Prepare the release program.
</Plan>

This binds the exact approved source under program and performs none of the
program's effects. Authorship and review are about the program's contents; they
do not change according to whether the authored document expands or captures
the result.

Current gap

PR #685 completed #660 by adding <Plan> to the ordinary run profile. The
component is currently a value component: it requires as, binds the approved
source as a string, and never expands that program.

xmd plan --run can execute an approved Plan, but it does so only after
authorship ends by starting a second root through the CLI. An embedded <Plan>
has no way to carry out its approved program inside the enclosing execution.

Contract

<Plan> produces approved XMD program source rather than ordinary rendered
text. Authorship always completes under the existing constrained authorship
profile, and the approved bytes have two engine-owned outcomes:

  • without as, canonical execution admits and expands the source inline at the
    <Plan> site;
  • with as, canonical execution binds the exact source and does not expand it;
    and
  • stopped, rejected, exhausted, failed, or cancelled authorship produces no
    program expansion and no binding.

The ordinary run profile declares this behavior as trusted host metadata on the
exact packaged <Plan> component. Markdown frontmatter, repository components,
workflow bundles, and component registrations cannot request it. Ordinary value
components continue to require as, including value components that return a
string.

Inline Plan source is an embedded text-root projection, not another document
execution:

  • its own frontmatter metadata, imports, and <Output> selection apply;
  • it sees the caller's bindings and current ambient props; when it declares
    root props, that schema validates the current props before its first effect;
  • a source declaring root returns is refused before its first effect because
    an inline <Plan> has no destination for a root value; and
  • it uses the enclosing execution's current component selection, Workspace,
    authority, output flow, failure mode, and cancellation scope.

The inline projection creates no second lifecycle, root result, journal, or
host profile. Its expansion and every effect receive durable identities beneath
the authored <Plan> site. Replay restores the exact approved source without
repeating authorship and resumes an interrupted expansion without repeating a
completed effect.

Security and durability

  • No candidate, rejected draft, or captured program executes.
  • The authorship profile tears down completely before approved source can
    expand or be bound.
  • The approved program receives only the authority already present at the
    authored execution site; model output grants no authority.
  • The trusted executable-source disposition is unavailable to document-authored
    components and is captured with the run profile before installation begins.
  • Admission retains the exact approved source, and ordinary component selection
    records detect an incompatible replay instead of silently selecting a
    different implementation.
  • Adding as prevents every effect of the approved program while preserving the
    same authorship and review contract.

Acceptance

  • <Plan> without as expands one approved program exactly where the component
    appears: an observable effect between two surrounding markers occurs once,
    and no approved source text is emitted in its place.
  • The same <Plan as="program"> binds byte-for-byte approved source while a
    negative-control effect in that source does not occur.
  • Stopping, rejecting, exhausting, failing, or cancelling authorship leaves the
    enclosing document without any approved-program effect or binding.
  • Inline source uses representative current-profile syntax, caller bindings,
    ambient props, imports, and <Output> behavior without starting another
    document lifecycle.
  • A declared root-props mismatch and a root returns declaration each refuse
    the inline source before a negative-control effect runs.
  • A partial journal resumes inside the approved program without another
    authorship turn, review, or completed effect.
  • An ordinary string-valued component still refuses an invocation without as,
    and a repository component cannot opt into executable-source disposition.
  • Validation, xmd syntax, the npm package, and the compiled binary describe
    and ship the same <Plan> contract.

Evidence

Extend packages/cli/tests/plan-component.test.ts with immediate, captured,
refused, cancelled, and replayed Plan cases. Add focused core coverage for the
trusted disposition, embedded text-root projection, and ordinary value-component
negative control. The tests fail if captured source executes, replay authors
again, a root contract is discarded, or inline expansion starts another root.

Run the exact focused files plus deno task test --changed. Distribution probes
cover the npm and compiled assets when the packaged <Plan> declaration
changes.

Dependencies and related work

Out of scope

  • A public Markdown frontmatter field for executable-source returns.
  • Deferred full-program expansion through <Evaluate>.
  • An independent nested-document <Run> component or process isolation.
  • Executing an unapproved draft.
  • Widening the authorship Agent's tools, filesystem, network, or permission
    ceiling.
  • Giving ordinary string-returning components executable behavior.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    enhancementNew feature or request

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions

      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Add copy buttons to all \u003cpre\u003e\u003ccode\u003e blocks\n(function() {\n function addCopyButtons() {\n document.querySelectorAll('pre code').forEach(function(codeBlock) {\n if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;\n codeBlock.parentElement.setAttribute('data-copy-added', 'true');\n \n var btn = document.createElement('button');\n btn.textContent = 'Copy';\n btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';\n btn.onmouseover = function() { this.style.opacity = '1'; };\n btn.onmouseout = function() { this.style.opacity = '0.7'; };\n btn.onclick = function() {\n navigator.clipboard.writeText(codeBlock.textContent).then(function() {\n btn.textContent = 'Copied!';\n setTimeout(function() { btn.textContent = 'Copy'; }, 1500);\n });\n };\n codeBlock.parentElement.style.position = 'relative';\n codeBlock.parentElement.appendChild(btn);\n });\n }\n \n addCopyButtons();\n \n // Re-run on dynamic content\n var observer = new MutationObserver(addCopyButtons);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Add Copy Buttons to Code Blocks"); } } catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); } })(); (function(){ try { var __m = "github.com"; var __re = new RegExp('^' + "github\\.com" + '
      Skip to content

      Make <Plan> expand inline by default #711

      Description

      @taras

      Story

      As an Executable Markdown author, I want an approved <Plan> to expand where I
      wrote it, so a document can create and carry out a program without leaving the
      current execution. When I need the approved source instead, I capture it with
      as and none of that program runs.

      Common path

      Without as, <Plan> authors, reviews and approves one XMD program, then
      expands the exact approved source inline at its invocation site:

      Prepare the release program and carry it out here.
      <Plan>
      1. Read package.json and CHANGELOG.md.
      2. Ask an Agent to recommend the next semantic version and explain why.
      3. Validate the answer.
      4. Ask me to approve it.
      5. Write RELEASE.md.
      </Plan>
      The release program completed, so continue with the result.

      The <Plan> content expands once to form the complete Prompt. Drafts stay
      inert. After approval, the constrained authorship environment tears down, the
      exact approved source is structurally admitted, and that source expands between
      the surrounding prose.

      An author who wants the approved program without carrying it out captures it:

      <Planas="program">
      Prepare the release program.
      </Plan>

      This binds the exact approved source under program and performs none of the
      program's effects. Authorship and review are about the program's contents; they
      do not change according to whether the authored document expands or captures
      the result.

      Current gap

      PR #685 completed #660 by adding <Plan> to the ordinary run profile. The
      component is currently a value component: it requires as, binds the approved
      source as a string, and never expands that program.

      xmd plan --run can execute an approved Plan, but it does so only after
      authorship ends by starting a second root through the CLI. An embedded <Plan>
      has no way to carry out its approved program inside the enclosing execution.

      Contract

      <Plan> produces approved XMD program source rather than ordinary rendered
      text. Authorship always completes under the existing constrained authorship
      profile, and the approved bytes have two engine-owned outcomes:

      • without as, canonical execution admits and expands the source inline at the
        <Plan> site;
      • with as, canonical execution binds the exact source and does not expand it;
        and
      • stopped, rejected, exhausted, failed, or cancelled authorship produces no
        program expansion and no binding.

      The ordinary run profile declares this behavior as trusted host metadata on the
      exact packaged <Plan> component. Markdown frontmatter, repository components,
      workflow bundles, and component registrations cannot request it. Ordinary value
      components continue to require as, including value components that return a
      string.

      Inline Plan source is an embedded text-root projection, not another document
      execution:

      • its own frontmatter metadata, imports, and <Output> selection apply;
      • it sees the caller's bindings and current ambient props; when it declares
        root props, that schema validates the current props before its first effect;
      • a source declaring root returns is refused before its first effect because
        an inline <Plan> has no destination for a root value; and
      • it uses the enclosing execution's current component selection, Workspace,
        authority, output flow, failure mode, and cancellation scope.

      The inline projection creates no second lifecycle, root result, journal, or
      host profile. Its expansion and every effect receive durable identities beneath
      the authored <Plan> site. Replay restores the exact approved source without
      repeating authorship and resumes an interrupted expansion without repeating a
      completed effect.

      Security and durability

      • No candidate, rejected draft, or captured program executes.
      • The authorship profile tears down completely before approved source can
        expand or be bound.
      • The approved program receives only the authority already present at the
        authored execution site; model output grants no authority.
      • The trusted executable-source disposition is unavailable to document-authored
        components and is captured with the run profile before installation begins.
      • Admission retains the exact approved source, and ordinary component selection
        records detect an incompatible replay instead of silently selecting a
        different implementation.
      • Adding as prevents every effect of the approved program while preserving the
        same authorship and review contract.

      Acceptance

      • <Plan> without as expands one approved program exactly where the component
        appears: an observable effect between two surrounding markers occurs once,
        and no approved source text is emitted in its place.
      • The same <Plan as="program"> binds byte-for-byte approved source while a
        negative-control effect in that source does not occur.
      • Stopping, rejecting, exhausting, failing, or cancelling authorship leaves the
        enclosing document without any approved-program effect or binding.
      • Inline source uses representative current-profile syntax, caller bindings,
        ambient props, imports, and <Output> behavior without starting another
        document lifecycle.
      • A declared root-props mismatch and a root returns declaration each refuse
        the inline source before a negative-control effect runs.
      • A partial journal resumes inside the approved program without another
        authorship turn, review, or completed effect.
      • An ordinary string-valued component still refuses an invocation without as,
        and a repository component cannot opt into executable-source disposition.
      • Validation, xmd syntax, the npm package, and the compiled binary describe
        and ship the same <Plan> contract.

      Evidence

      Extend packages/cli/tests/plan-component.test.ts with immediate, captured,
      refused, cancelled, and replayed Plan cases. Add focused core coverage for the
      trusted disposition, embedded text-root projection, and ordinary value-component
      negative control. The tests fail if captured source executes, replay authors
      again, a root contract is discarded, or inline expansion starts another root.

      Run the exact focused files plus deno task test --changed. Distribution probes
      cover the npm and compiled assets when the packaged <Plan> declaration
      changes.

      Dependencies and related work

      Out of scope

      • A public Markdown frontmatter field for executable-source returns.
      • Deferred full-program expansion through <Evaluate>.
      • An independent nested-document <Run> component or process isolation.
      • Executing an unapproved draft.
      • Widening the authorship Agent's tools, filesystem, network, or permission
        ceiling.
      • Giving ordinary string-returning components executable behavior.

      Activity

      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

      Metadata

      Metadata

      Assignees

      No one assigned

        Labels

        enhancementNew feature or request

        Projects

        No projects

          Milestone

          No milestone

          Relationships

          None yet

          Development

          No branches or pull requests

          Issue actions

          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Force GitHub README to respect dark mode\n(function() {\n var style = document.createElement('style');\n style.textContent = '\n .markdown-body {\n color-scheme: dark light;\n }\n .markdown-body pre { background: #161b22 !important; }\n .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; }\n .markdown-body table th, .markdown-body table td { border-color: #30363d !important; }\n .markdown-body img { background: #0d1117; }\n .markdown-body blockquote { border-left-color: #8b949e; }\n .markdown-body hr { border-color: #30363d; }\n ';\n document.head.appendChild(style);\n})();", "GitHub Dark Mode README Fix"); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
          Skip to content

          Make <Plan> expand inline by default #711

          Description

          @taras

          Story

          As an Executable Markdown author, I want an approved <Plan> to expand where I
          wrote it, so a document can create and carry out a program without leaving the
          current execution. When I need the approved source instead, I capture it with
          as and none of that program runs.

          Common path

          Without as, <Plan> authors, reviews and approves one XMD program, then
          expands the exact approved source inline at its invocation site:

          Prepare the release program and carry it out here.
          <Plan>
          1. Read package.json and CHANGELOG.md.
          2. Ask an Agent to recommend the next semantic version and explain why.
          3. Validate the answer.
          4. Ask me to approve it.
          5. Write RELEASE.md.
          </Plan>
          The release program completed, so continue with the result.

          The <Plan> content expands once to form the complete Prompt. Drafts stay
          inert. After approval, the constrained authorship environment tears down, the
          exact approved source is structurally admitted, and that source expands between
          the surrounding prose.

          An author who wants the approved program without carrying it out captures it:

          <Planas="program">
          Prepare the release program.
          </Plan>

          This binds the exact approved source under program and performs none of the
          program's effects. Authorship and review are about the program's contents; they
          do not change according to whether the authored document expands or captures
          the result.

          Current gap

          PR #685 completed #660 by adding <Plan> to the ordinary run profile. The
          component is currently a value component: it requires as, binds the approved
          source as a string, and never expands that program.

          xmd plan --run can execute an approved Plan, but it does so only after
          authorship ends by starting a second root through the CLI. An embedded <Plan>
          has no way to carry out its approved program inside the enclosing execution.

          Contract

          <Plan> produces approved XMD program source rather than ordinary rendered
          text. Authorship always completes under the existing constrained authorship
          profile, and the approved bytes have two engine-owned outcomes:

          • without as, canonical execution admits and expands the source inline at the
            <Plan> site;
          • with as, canonical execution binds the exact source and does not expand it;
            and
          • stopped, rejected, exhausted, failed, or cancelled authorship produces no
            program expansion and no binding.

          The ordinary run profile declares this behavior as trusted host metadata on the
          exact packaged <Plan> component. Markdown frontmatter, repository components,
          workflow bundles, and component registrations cannot request it. Ordinary value
          components continue to require as, including value components that return a
          string.

          Inline Plan source is an embedded text-root projection, not another document
          execution:

          • its own frontmatter metadata, imports, and <Output> selection apply;
          • it sees the caller's bindings and current ambient props; when it declares
            root props, that schema validates the current props before its first effect;
          • a source declaring root returns is refused before its first effect because
            an inline <Plan> has no destination for a root value; and
          • it uses the enclosing execution's current component selection, Workspace,
            authority, output flow, failure mode, and cancellation scope.

          The inline projection creates no second lifecycle, root result, journal, or
          host profile. Its expansion and every effect receive durable identities beneath
          the authored <Plan> site. Replay restores the exact approved source without
          repeating authorship and resumes an interrupted expansion without repeating a
          completed effect.

          Security and durability

          • No candidate, rejected draft, or captured program executes.
          • The authorship profile tears down completely before approved source can
            expand or be bound.
          • The approved program receives only the authority already present at the
            authored execution site; model output grants no authority.
          • The trusted executable-source disposition is unavailable to document-authored
            components and is captured with the run profile before installation begins.
          • Admission retains the exact approved source, and ordinary component selection
            records detect an incompatible replay instead of silently selecting a
            different implementation.
          • Adding as prevents every effect of the approved program while preserving the
            same authorship and review contract.

          Acceptance

          • <Plan> without as expands one approved program exactly where the component
            appears: an observable effect between two surrounding markers occurs once,
            and no approved source text is emitted in its place.
          • The same <Plan as="program"> binds byte-for-byte approved source while a
            negative-control effect in that source does not occur.
          • Stopping, rejecting, exhausting, failing, or cancelling authorship leaves the
            enclosing document without any approved-program effect or binding.
          • Inline source uses representative current-profile syntax, caller bindings,
            ambient props, imports, and <Output> behavior without starting another
            document lifecycle.
          • A declared root-props mismatch and a root returns declaration each refuse
            the inline source before a negative-control effect runs.
          • A partial journal resumes inside the approved program without another
            authorship turn, review, or completed effect.
          • An ordinary string-valued component still refuses an invocation without as,
            and a repository component cannot opt into executable-source disposition.
          • Validation, xmd syntax, the npm package, and the compiled binary describe
            and ship the same <Plan> contract.

          Evidence

          Extend packages/cli/tests/plan-component.test.ts with immediate, captured,
          refused, cancelled, and replayed Plan cases. Add focused core coverage for the
          trusted disposition, embedded text-root projection, and ordinary value-component
          negative control. The tests fail if captured source executes, replay authors
          again, a root contract is discarded, or inline expansion starts another root.

          Run the exact focused files plus deno task test --changed. Distribution probes
          cover the npm and compiled assets when the packaged <Plan> declaration
          changes.

          Dependencies and related work

          Out of scope

          • A public Markdown frontmatter field for executable-source returns.
          • Deferred full-program expansion through <Evaluate>.
          • An independent nested-document <Run> component or process isolation.
          • Executing an unapproved draft.
          • Widening the authorship Agent's tools, filesystem, network, or permission
            ceiling.
          • Giving ordinary string-returning components executable behavior.

          Activity

          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

          Metadata

          Metadata

          Assignees

          No one assigned

            Labels

            enhancementNew feature or request

            Projects

            No projects

              Milestone

              No milestone

              Relationships

              None yet

              Development

              No branches or pull requests

              Issue actions

              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Highlight search terms from Google/DuckDuckGo/Bing referrer\n(function() {\n var ref = document.referrer;\n var terms = [];\n \n if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) {\n var url = new URL(ref);\n var q = url.searchParams.get('q') || url.searchParams.get('p');\n if (q) {\n terms = q.split(/\\s+/).filter(function(t) { return t.length \u003e 2; });\n }\n }\n \n if (terms.length === 0) return;\n \n var style = document.createElement('style');\n style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }';\n document.head.appendChild(style);\n \n function highlight(node) {\n if (node.nodeType === 3) { // text node\n var text = node.textContent;\n var found = false;\n terms.forEach(function(term) {\n var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\\]\\\\]/g, '\\\\') + ')', 'gi');\n if (regex.test(text)) {\n found = true;\n var frag = document.createDocumentFragment();\n var parts = text.split(regex);\n parts.forEach(function(part, i) {\n if (i % 2 === 0) {\n frag.appendChild(document.createTextNode(part));\n } else {\n var span = document.createElement('span');\n span.className = 'userscript-highlight';\n span.textContent = part;\n frag.appendChild(span);\n }\n });\n node.parentNode.replaceChild(frag, node);\n }\n });\n } else if (node.nodeType === 1 && node.childNodes) { // element\n var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT'];\n if (!skipTags.includes(node.tagName)) {\n Array.from(node.childNodes).forEach(highlight);\n }\n }\n }\n \n highlight(document.body);\n \n // Re-highlight on dynamic content\n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1 || node.nodeType === 3) highlight(node);\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Highlight Search Terms"); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
              Skip to content

              Make <Plan> expand inline by default #711

              Description

              @taras

              Story

              As an Executable Markdown author, I want an approved <Plan> to expand where I
              wrote it, so a document can create and carry out a program without leaving the
              current execution. When I need the approved source instead, I capture it with
              as and none of that program runs.

              Common path

              Without as, <Plan> authors, reviews and approves one XMD program, then
              expands the exact approved source inline at its invocation site:

              Prepare the release program and carry it out here.
              <Plan>
              1. Read package.json and CHANGELOG.md.
              2. Ask an Agent to recommend the next semantic version and explain why.
              3. Validate the answer.
              4. Ask me to approve it.
              5. Write RELEASE.md.
              </Plan>
              The release program completed, so continue with the result.

              The <Plan> content expands once to form the complete Prompt. Drafts stay
              inert. After approval, the constrained authorship environment tears down, the
              exact approved source is structurally admitted, and that source expands between
              the surrounding prose.

              An author who wants the approved program without carrying it out captures it:

              <Planas="program">
              Prepare the release program.
              </Plan>

              This binds the exact approved source under program and performs none of the
              program's effects. Authorship and review are about the program's contents; they
              do not change according to whether the authored document expands or captures
              the result.

              Current gap

              PR #685 completed #660 by adding <Plan> to the ordinary run profile. The
              component is currently a value component: it requires as, binds the approved
              source as a string, and never expands that program.

              xmd plan --run can execute an approved Plan, but it does so only after
              authorship ends by starting a second root through the CLI. An embedded <Plan>
              has no way to carry out its approved program inside the enclosing execution.

              Contract

              <Plan> produces approved XMD program source rather than ordinary rendered
              text. Authorship always completes under the existing constrained authorship
              profile, and the approved bytes have two engine-owned outcomes:

              • without as, canonical execution admits and expands the source inline at the
                <Plan> site;
              • with as, canonical execution binds the exact source and does not expand it;
                and
              • stopped, rejected, exhausted, failed, or cancelled authorship produces no
                program expansion and no binding.

              The ordinary run profile declares this behavior as trusted host metadata on the
              exact packaged <Plan> component. Markdown frontmatter, repository components,
              workflow bundles, and component registrations cannot request it. Ordinary value
              components continue to require as, including value components that return a
              string.

              Inline Plan source is an embedded text-root projection, not another document
              execution:

              • its own frontmatter metadata, imports, and <Output> selection apply;
              • it sees the caller's bindings and current ambient props; when it declares
                root props, that schema validates the current props before its first effect;
              • a source declaring root returns is refused before its first effect because
                an inline <Plan> has no destination for a root value; and
              • it uses the enclosing execution's current component selection, Workspace,
                authority, output flow, failure mode, and cancellation scope.

              The inline projection creates no second lifecycle, root result, journal, or
              host profile. Its expansion and every effect receive durable identities beneath
              the authored <Plan> site. Replay restores the exact approved source without
              repeating authorship and resumes an interrupted expansion without repeating a
              completed effect.

              Security and durability

              • No candidate, rejected draft, or captured program executes.
              • The authorship profile tears down completely before approved source can
                expand or be bound.
              • The approved program receives only the authority already present at the
                authored execution site; model output grants no authority.
              • The trusted executable-source disposition is unavailable to document-authored
                components and is captured with the run profile before installation begins.
              • Admission retains the exact approved source, and ordinary component selection
                records detect an incompatible replay instead of silently selecting a
                different implementation.
              • Adding as prevents every effect of the approved program while preserving the
                same authorship and review contract.

              Acceptance

              • <Plan> without as expands one approved program exactly where the component
                appears: an observable effect between two surrounding markers occurs once,
                and no approved source text is emitted in its place.
              • The same <Plan as="program"> binds byte-for-byte approved source while a
                negative-control effect in that source does not occur.
              • Stopping, rejecting, exhausting, failing, or cancelling authorship leaves the
                enclosing document without any approved-program effect or binding.
              • Inline source uses representative current-profile syntax, caller bindings,
                ambient props, imports, and <Output> behavior without starting another
                document lifecycle.
              • A declared root-props mismatch and a root returns declaration each refuse
                the inline source before a negative-control effect runs.
              • A partial journal resumes inside the approved program without another
                authorship turn, review, or completed effect.
              • An ordinary string-valued component still refuses an invocation without as,
                and a repository component cannot opt into executable-source disposition.
              • Validation, xmd syntax, the npm package, and the compiled binary describe
                and ship the same <Plan> contract.

              Evidence

              Extend packages/cli/tests/plan-component.test.ts with immediate, captured,
              refused, cancelled, and replayed Plan cases. Add focused core coverage for the
              trusted disposition, embedded text-root projection, and ordinary value-component
              negative control. The tests fail if captured source executes, replay authors
              again, a root contract is discarded, or inline expansion starts another root.

              Run the exact focused files plus deno task test --changed. Distribution probes
              cover the npm and compiled assets when the packaged <Plan> declaration
              changes.

              Dependencies and related work

              Out of scope

              • A public Markdown frontmatter field for executable-source returns.
              • Deferred full-program expansion through <Evaluate>.
              • An independent nested-document <Run> component or process isolation.
              • Executing an unapproved draft.
              • Widening the authorship Agent's tools, filesystem, network, or permission
                ceiling.
              • Giving ordinary string-returning components executable behavior.

              Activity

              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

              Metadata

              Metadata

              Assignees

              No one assigned

                Labels

                enhancementNew feature or request

                Projects

                No projects

                  Milestone

                  No milestone

                  Relationships

                  None yet

                  Development

                  No branches or pull requests

                  Issue actions

                  , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Strip utm_, fbclid, gclid, etc. from all links on page\n(function() {\n var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content',\n 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid',\n 'ref', 'ref_src', 'source', 'medium', 'campaign'];\n \n function cleanUrl(url) {\n try {\n var u = new URL(url, window.location.origin);\n var changed = false;\n trackingParams.forEach(function(p) {\n if (u.searchParams.has(p)) {\n u.searchParams.delete(p);\n changed = true;\n }\n });\n return changed ? u.toString() : url;\n } catch (e) {\n return url;\n }\n }\n \n function cleanLinks() {\n document.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n \n cleanLinks();\n \n var observer = new MutationObserver(function(mutations) {\n mutations.forEach(function(m) {\n m.addedNodes.forEach(function(node) {\n if (node.nodeType === 1) {\n if (node.tagName === 'A') cleanLinks();\n node.querySelectorAll('a[href]').forEach(function(a) {\n var clean = cleanUrl(a.href);\n if (clean !== a.href) a.href = clean;\n });\n }\n });\n });\n });\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "Remove Tracking Parameters from Links"); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + '
                  Skip to content

                  Make <Plan> expand inline by default #711

                  Description

                  @taras

                  Story

                  As an Executable Markdown author, I want an approved <Plan> to expand where I
                  wrote it, so a document can create and carry out a program without leaving the
                  current execution. When I need the approved source instead, I capture it with
                  as and none of that program runs.

                  Common path

                  Without as, <Plan> authors, reviews and approves one XMD program, then
                  expands the exact approved source inline at its invocation site:

                  Prepare the release program and carry it out here.
                  <Plan>
                  1. Read package.json and CHANGELOG.md.
                  2. Ask an Agent to recommend the next semantic version and explain why.
                  3. Validate the answer.
                  4. Ask me to approve it.
                  5. Write RELEASE.md.
                  </Plan>
                  The release program completed, so continue with the result.

                  The <Plan> content expands once to form the complete Prompt. Drafts stay
                  inert. After approval, the constrained authorship environment tears down, the
                  exact approved source is structurally admitted, and that source expands between
                  the surrounding prose.

                  An author who wants the approved program without carrying it out captures it:

                  <Planas="program">
                  Prepare the release program.
                  </Plan>

                  This binds the exact approved source under program and performs none of the
                  program's effects. Authorship and review are about the program's contents; they
                  do not change according to whether the authored document expands or captures
                  the result.

                  Current gap

                  PR #685 completed #660 by adding <Plan> to the ordinary run profile. The
                  component is currently a value component: it requires as, binds the approved
                  source as a string, and never expands that program.

                  xmd plan --run can execute an approved Plan, but it does so only after
                  authorship ends by starting a second root through the CLI. An embedded <Plan>
                  has no way to carry out its approved program inside the enclosing execution.

                  Contract

                  <Plan> produces approved XMD program source rather than ordinary rendered
                  text. Authorship always completes under the existing constrained authorship
                  profile, and the approved bytes have two engine-owned outcomes:

                  • without as, canonical execution admits and expands the source inline at the
                    <Plan> site;
                  • with as, canonical execution binds the exact source and does not expand it;
                    and
                  • stopped, rejected, exhausted, failed, or cancelled authorship produces no
                    program expansion and no binding.

                  The ordinary run profile declares this behavior as trusted host metadata on the
                  exact packaged <Plan> component. Markdown frontmatter, repository components,
                  workflow bundles, and component registrations cannot request it. Ordinary value
                  components continue to require as, including value components that return a
                  string.

                  Inline Plan source is an embedded text-root projection, not another document
                  execution:

                  • its own frontmatter metadata, imports, and <Output> selection apply;
                  • it sees the caller's bindings and current ambient props; when it declares
                    root props, that schema validates the current props before its first effect;
                  • a source declaring root returns is refused before its first effect because
                    an inline <Plan> has no destination for a root value; and
                  • it uses the enclosing execution's current component selection, Workspace,
                    authority, output flow, failure mode, and cancellation scope.

                  The inline projection creates no second lifecycle, root result, journal, or
                  host profile. Its expansion and every effect receive durable identities beneath
                  the authored <Plan> site. Replay restores the exact approved source without
                  repeating authorship and resumes an interrupted expansion without repeating a
                  completed effect.

                  Security and durability

                  • No candidate, rejected draft, or captured program executes.
                  • The authorship profile tears down completely before approved source can
                    expand or be bound.
                  • The approved program receives only the authority already present at the
                    authored execution site; model output grants no authority.
                  • The trusted executable-source disposition is unavailable to document-authored
                    components and is captured with the run profile before installation begins.
                  • Admission retains the exact approved source, and ordinary component selection
                    records detect an incompatible replay instead of silently selecting a
                    different implementation.
                  • Adding as prevents every effect of the approved program while preserving the
                    same authorship and review contract.

                  Acceptance

                  • <Plan> without as expands one approved program exactly where the component
                    appears: an observable effect between two surrounding markers occurs once,
                    and no approved source text is emitted in its place.
                  • The same <Plan as="program"> binds byte-for-byte approved source while a
                    negative-control effect in that source does not occur.
                  • Stopping, rejecting, exhausting, failing, or cancelling authorship leaves the
                    enclosing document without any approved-program effect or binding.
                  • Inline source uses representative current-profile syntax, caller bindings,
                    ambient props, imports, and <Output> behavior without starting another
                    document lifecycle.
                  • A declared root-props mismatch and a root returns declaration each refuse
                    the inline source before a negative-control effect runs.
                  • A partial journal resumes inside the approved program without another
                    authorship turn, review, or completed effect.
                  • An ordinary string-valued component still refuses an invocation without as,
                    and a repository component cannot opt into executable-source disposition.
                  • Validation, xmd syntax, the npm package, and the compiled binary describe
                    and ship the same <Plan> contract.

                  Evidence

                  Extend packages/cli/tests/plan-component.test.ts with immediate, captured,
                  refused, cancelled, and replayed Plan cases. Add focused core coverage for the
                  trusted disposition, embedded text-root projection, and ordinary value-component
                  negative control. The tests fail if captured source executes, replay authors
                  again, a root contract is discarded, or inline expansion starts another root.

                  Run the exact focused files plus deno task test --changed. Distribution probes
                  cover the npm and compiled assets when the packaged <Plan> declaration
                  changes.

                  Dependencies and related work

                  Out of scope

                  • A public Markdown frontmatter field for executable-source returns.
                  • Deferred full-program expansion through <Evaluate>.
                  • An independent nested-document <Run> component or process isolation.
                  • Executing an unapproved draft.
                  • Widening the authorship Agent's tools, filesystem, network, or permission
                    ceiling.
                  • Giving ordinary string-returning components executable behavior.

                  Activity

                  Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                  Metadata

                  Metadata

                  Assignees

                  No one assigned

                    Labels

                    enhancementNew feature or request

                    Projects

                    No projects

                      Milestone

                      No milestone

                      Relationships

                      None yet

                      Development

                      No branches or pull requests

                      Issue actions

                      , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Auto-enable theater mode on YouTube\n(function() {\n function tryTheater() {\n var btn = document.querySelector('button[aria-label=\"Theater mode\"], ytd-player #player button[title=\"Theater mode\"]');\n if (btn && !btn.classList.contains('activated')) {\n btn.click();\n }\n }\n \n // Try immediately\n tryTheater();\n \n // Try after navigation (SPA)\n var lastUrl = location.href;\n setInterval(function() {\n if (location.href !== lastUrl) {\n lastUrl = location.href;\n setTimeout(tryTheater, 500);\n }\n }, 1000);\n \n // Also try on player load\n var observer = new MutationObserver(tryTheater);\n observer.observe(document.body, { childList: true, subtree: true });\n})();", "YouTube Theater Mode Default"); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                      Skip to content

                      Make <Plan> expand inline by default #711

                      Description

                      @taras

                      Story

                      As an Executable Markdown author, I want an approved <Plan> to expand where I
                      wrote it, so a document can create and carry out a program without leaving the
                      current execution. When I need the approved source instead, I capture it with
                      as and none of that program runs.

                      Common path

                      Without as, <Plan> authors, reviews and approves one XMD program, then
                      expands the exact approved source inline at its invocation site:

                      Prepare the release program and carry it out here.
                      <Plan>
                      1. Read package.json and CHANGELOG.md.
                      2. Ask an Agent to recommend the next semantic version and explain why.
                      3. Validate the answer.
                      4. Ask me to approve it.
                      5. Write RELEASE.md.
                      </Plan>
                      The release program completed, so continue with the result.

                      The <Plan> content expands once to form the complete Prompt. Drafts stay
                      inert. After approval, the constrained authorship environment tears down, the
                      exact approved source is structurally admitted, and that source expands between
                      the surrounding prose.

                      An author who wants the approved program without carrying it out captures it:

                      <Planas="program">
                      Prepare the release program.
                      </Plan>

                      This binds the exact approved source under program and performs none of the
                      program's effects. Authorship and review are about the program's contents; they
                      do not change according to whether the authored document expands or captures
                      the result.

                      Current gap

                      PR #685 completed #660 by adding <Plan> to the ordinary run profile. The
                      component is currently a value component: it requires as, binds the approved
                      source as a string, and never expands that program.

                      xmd plan --run can execute an approved Plan, but it does so only after
                      authorship ends by starting a second root through the CLI. An embedded <Plan>
                      has no way to carry out its approved program inside the enclosing execution.

                      Contract

                      <Plan> produces approved XMD program source rather than ordinary rendered
                      text. Authorship always completes under the existing constrained authorship
                      profile, and the approved bytes have two engine-owned outcomes:

                      • without as, canonical execution admits and expands the source inline at the
                        <Plan> site;
                      • with as, canonical execution binds the exact source and does not expand it;
                        and
                      • stopped, rejected, exhausted, failed, or cancelled authorship produces no
                        program expansion and no binding.

                      The ordinary run profile declares this behavior as trusted host metadata on the
                      exact packaged <Plan> component. Markdown frontmatter, repository components,
                      workflow bundles, and component registrations cannot request it. Ordinary value
                      components continue to require as, including value components that return a
                      string.

                      Inline Plan source is an embedded text-root projection, not another document
                      execution:

                      • its own frontmatter metadata, imports, and <Output> selection apply;
                      • it sees the caller's bindings and current ambient props; when it declares
                        root props, that schema validates the current props before its first effect;
                      • a source declaring root returns is refused before its first effect because
                        an inline <Plan> has no destination for a root value; and
                      • it uses the enclosing execution's current component selection, Workspace,
                        authority, output flow, failure mode, and cancellation scope.

                      The inline projection creates no second lifecycle, root result, journal, or
                      host profile. Its expansion and every effect receive durable identities beneath
                      the authored <Plan> site. Replay restores the exact approved source without
                      repeating authorship and resumes an interrupted expansion without repeating a
                      completed effect.

                      Security and durability

                      • No candidate, rejected draft, or captured program executes.
                      • The authorship profile tears down completely before approved source can
                        expand or be bound.
                      • The approved program receives only the authority already present at the
                        authored execution site; model output grants no authority.
                      • The trusted executable-source disposition is unavailable to document-authored
                        components and is captured with the run profile before installation begins.
                      • Admission retains the exact approved source, and ordinary component selection
                        records detect an incompatible replay instead of silently selecting a
                        different implementation.
                      • Adding as prevents every effect of the approved program while preserving the
                        same authorship and review contract.

                      Acceptance

                      • <Plan> without as expands one approved program exactly where the component
                        appears: an observable effect between two surrounding markers occurs once,
                        and no approved source text is emitted in its place.
                      • The same <Plan as="program"> binds byte-for-byte approved source while a
                        negative-control effect in that source does not occur.
                      • Stopping, rejecting, exhausting, failing, or cancelling authorship leaves the
                        enclosing document without any approved-program effect or binding.
                      • Inline source uses representative current-profile syntax, caller bindings,
                        ambient props, imports, and <Output> behavior without starting another
                        document lifecycle.
                      • A declared root-props mismatch and a root returns declaration each refuse
                        the inline source before a negative-control effect runs.
                      • A partial journal resumes inside the approved program without another
                        authorship turn, review, or completed effect.
                      • An ordinary string-valued component still refuses an invocation without as,
                        and a repository component cannot opt into executable-source disposition.
                      • Validation, xmd syntax, the npm package, and the compiled binary describe
                        and ship the same <Plan> contract.

                      Evidence

                      Extend packages/cli/tests/plan-component.test.ts with immediate, captured,
                      refused, cancelled, and replayed Plan cases. Add focused core coverage for the
                      trusted disposition, embedded text-root projection, and ordinary value-component
                      negative control. The tests fail if captured source executes, replay authors
                      again, a root contract is discarded, or inline expansion starts another root.

                      Run the exact focused files plus deno task test --changed. Distribution probes
                      cover the npm and compiled assets when the packaged <Plan> declaration
                      changes.

                      Dependencies and related work

                      Out of scope

                      • A public Markdown frontmatter field for executable-source returns.
                      • Deferred full-program expansion through <Evaluate>.
                      • An independent nested-document <Run> component or process isolation.
                      • Executing an unapproved draft.
                      • Widening the authorship Agent's tools, filesystem, network, or permission
                        ceiling.
                      • Giving ordinary string-returning components executable behavior.

                      Activity

                      Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                      Metadata

                      Metadata

                      Assignees

                      No one assigned

                        Labels

                        enhancementNew feature or request

                        Projects

                        No projects

                          Milestone

                          No milestone

                          Relationships

                          None yet

                          Development

                          No branches or pull requests

                          Issue actions

                          , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Remove or un-stick sticky/fixed headers that block content\n(function() {\n function unstick() {\n document.querySelectorAll('header, nav, [role=\"banner\"], .header, .navbar, .sticky, .fixed-top, [style*=\"position: fixed\"], [style*=\"position:sticky\"]').forEach(function(el) {\n if (el.style.position === 'fixed' || el.style.position === 'sticky' || \n getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') {\n el.style.position = 'static';\n el.style.top = 'auto';\n el.style.zIndex = 'auto';\n }\n });\n }\n \n unstick();\n \n var observer = new MutationObserver(unstick);\n observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] });\n})();", "Kill Sticky Headers"); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + '
                          Skip to content

                          Make <Plan> expand inline by default #711

                          Description

                          @taras

                          Story

                          As an Executable Markdown author, I want an approved <Plan> to expand where I
                          wrote it, so a document can create and carry out a program without leaving the
                          current execution. When I need the approved source instead, I capture it with
                          as and none of that program runs.

                          Common path

                          Without as, <Plan> authors, reviews and approves one XMD program, then
                          expands the exact approved source inline at its invocation site:

                          Prepare the release program and carry it out here.
                          <Plan>
                          1. Read package.json and CHANGELOG.md.
                          2. Ask an Agent to recommend the next semantic version and explain why.
                          3. Validate the answer.
                          4. Ask me to approve it.
                          5. Write RELEASE.md.
                          </Plan>
                          The release program completed, so continue with the result.

                          The <Plan> content expands once to form the complete Prompt. Drafts stay
                          inert. After approval, the constrained authorship environment tears down, the
                          exact approved source is structurally admitted, and that source expands between
                          the surrounding prose.

                          An author who wants the approved program without carrying it out captures it:

                          <Planas="program">
                          Prepare the release program.
                          </Plan>

                          This binds the exact approved source under program and performs none of the
                          program's effects. Authorship and review are about the program's contents; they
                          do not change according to whether the authored document expands or captures
                          the result.

                          Current gap

                          PR #685 completed #660 by adding <Plan> to the ordinary run profile. The
                          component is currently a value component: it requires as, binds the approved
                          source as a string, and never expands that program.

                          xmd plan --run can execute an approved Plan, but it does so only after
                          authorship ends by starting a second root through the CLI. An embedded <Plan>
                          has no way to carry out its approved program inside the enclosing execution.

                          Contract

                          <Plan> produces approved XMD program source rather than ordinary rendered
                          text. Authorship always completes under the existing constrained authorship
                          profile, and the approved bytes have two engine-owned outcomes:

                          • without as, canonical execution admits and expands the source inline at the
                            <Plan> site;
                          • with as, canonical execution binds the exact source and does not expand it;
                            and
                          • stopped, rejected, exhausted, failed, or cancelled authorship produces no
                            program expansion and no binding.

                          The ordinary run profile declares this behavior as trusted host metadata on the
                          exact packaged <Plan> component. Markdown frontmatter, repository components,
                          workflow bundles, and component registrations cannot request it. Ordinary value
                          components continue to require as, including value components that return a
                          string.

                          Inline Plan source is an embedded text-root projection, not another document
                          execution:

                          • its own frontmatter metadata, imports, and <Output> selection apply;
                          • it sees the caller's bindings and current ambient props; when it declares
                            root props, that schema validates the current props before its first effect;
                          • a source declaring root returns is refused before its first effect because
                            an inline <Plan> has no destination for a root value; and
                          • it uses the enclosing execution's current component selection, Workspace,
                            authority, output flow, failure mode, and cancellation scope.

                          The inline projection creates no second lifecycle, root result, journal, or
                          host profile. Its expansion and every effect receive durable identities beneath
                          the authored <Plan> site. Replay restores the exact approved source without
                          repeating authorship and resumes an interrupted expansion without repeating a
                          completed effect.

                          Security and durability

                          • No candidate, rejected draft, or captured program executes.
                          • The authorship profile tears down completely before approved source can
                            expand or be bound.
                          • The approved program receives only the authority already present at the
                            authored execution site; model output grants no authority.
                          • The trusted executable-source disposition is unavailable to document-authored
                            components and is captured with the run profile before installation begins.
                          • Admission retains the exact approved source, and ordinary component selection
                            records detect an incompatible replay instead of silently selecting a
                            different implementation.
                          • Adding as prevents every effect of the approved program while preserving the
                            same authorship and review contract.

                          Acceptance

                          • <Plan> without as expands one approved program exactly where the component
                            appears: an observable effect between two surrounding markers occurs once,
                            and no approved source text is emitted in its place.
                          • The same <Plan as="program"> binds byte-for-byte approved source while a
                            negative-control effect in that source does not occur.
                          • Stopping, rejecting, exhausting, failing, or cancelling authorship leaves the
                            enclosing document without any approved-program effect or binding.
                          • Inline source uses representative current-profile syntax, caller bindings,
                            ambient props, imports, and <Output> behavior without starting another
                            document lifecycle.
                          • A declared root-props mismatch and a root returns declaration each refuse
                            the inline source before a negative-control effect runs.
                          • A partial journal resumes inside the approved program without another
                            authorship turn, review, or completed effect.
                          • An ordinary string-valued component still refuses an invocation without as,
                            and a repository component cannot opt into executable-source disposition.
                          • Validation, xmd syntax, the npm package, and the compiled binary describe
                            and ship the same <Plan> contract.

                          Evidence

                          Extend packages/cli/tests/plan-component.test.ts with immediate, captured,
                          refused, cancelled, and replayed Plan cases. Add focused core coverage for the
                          trusted disposition, embedded text-root projection, and ordinary value-component
                          negative control. The tests fail if captured source executes, replay authors
                          again, a root contract is discarded, or inline expansion starts another root.

                          Run the exact focused files plus deno task test --changed. Distribution probes
                          cover the npm and compiled assets when the packaged <Plan> declaration
                          changes.

                          Dependencies and related work

                          Out of scope

                          • A public Markdown frontmatter field for executable-source returns.
                          • Deferred full-program expansion through <Evaluate>.
                          • An independent nested-document <Run> component or process isolation.
                          • Executing an unapproved draft.
                          • Widening the authorship Agent's tools, filesystem, network, or permission
                            ceiling.
                          • Giving ordinary string-returning components executable behavior.

                          Activity

                          Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                          Metadata

                          Metadata

                          Assignees

                          No one assigned

                            Labels

                            enhancementNew feature or request

                            Projects

                            No projects

                              Milestone

                              No milestone

                              Relationships

                              None yet

                              Development

                              No branches or pull requests

                              Issue actions

                              , 'i'); if (__m === '*' || __re.test(location.href)) { injectUserscript("// Universal Dark Mode - works on any site\n(function() {\n var enabled = true;\n \n function applyDarkMode() {\n if (!enabled) return;\n \n // Create style element if it doesn't exist\n var style = document.getElementById('universal-dark-mode-style');\n if (!style) {\n style = document.createElement('style');\n style.id = 'universal-dark-mode-style';\n document.head.appendChild(style);\n }\n \n // Dark mode CSS - inverts colors but preserves images/video\n style.textContent = '\n /* Invert everything except media */\n html {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #1a1a2e !important;\n }\n \n /* Restore images, videos, iframes, canvas */\n img, video, iframe, canvas, svg, picture, [style*=\"background-image\"] {\n filter: invert(1) hue-rotate(180deg) !important;\n }\n \n /* Preserve specific elements that should not be inverted */\n .no-dark-mode, .no-dark-mode *,\n [data-theme=\"light\"], [data-theme=\"light\"],\n .ace_editor, .ace_editor *,\n .CodeMirror, .CodeMirror *,\n .monaco-editor, .monaco-editor *,\n .markdown-body pre, .markdown-body pre *,\n .highlight, .highlight *,\n pre code, pre code * {\n filter: none !important;\n }\n \n /* Fix common UI elements */\n .modal, .popup, .dropdown-menu, .tooltip, .popover {\n filter: invert(1) hue-rotate(180deg) !important;\n background: #2d2d44 !important;\n border-color: #444 !important;\n }\n \n /* Scrollbars */\n ::-webkit-scrollbar { background: #1a1a2e !important; }\n ::-webkit-scrollbar-thumb { background: #444 !important; }\n ::-webkit-scrollbar-thumb:hover { background: #555 !important; }\n \n /* Selection */\n ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; }\n ';\n }\n \n function removeDarkMode() {\n var style = document.getElementById('universal-dark-mode-style');\n if (style) style.remove();\n }\n \n // Toggle with Alt+Shift+D\n document.addEventListener('keydown', function(e) {\n if (e.altKey && e.shiftKey && e.key === 'D') {\n e.preventDefault();\n enabled = !enabled;\n if (enabled) {\n applyDarkMode();\n console.log('[Universal Dark Mode] Enabled');\n } else {\n removeDarkMode();\n console.log('[Universal Dark Mode] Disabled');\n }\n }\n });\n \n // Apply on load\n applyDarkMode();\n \n // Re-apply on dynamic content\n var observer = new MutationObserver(function(mutations) {\n if (enabled && !document.getElementById('universal-dark-mode-style')) {\n applyDarkMode();\n }\n });\n observer.observe(document.head, { childList: true });\n \n console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle');\n})();", "Universal Dark Mode"); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })();
                              Skip to content

                              Make <Plan> expand inline by default #711

                              Description

                              @taras

                              Story

                              As an Executable Markdown author, I want an approved <Plan> to expand where I
                              wrote it, so a document can create and carry out a program without leaving the
                              current execution. When I need the approved source instead, I capture it with
                              as and none of that program runs.

                              Common path

                              Without as, <Plan> authors, reviews and approves one XMD program, then
                              expands the exact approved source inline at its invocation site:

                              Prepare the release program and carry it out here.
                              <Plan>
                              1. Read package.json and CHANGELOG.md.
                              2. Ask an Agent to recommend the next semantic version and explain why.
                              3. Validate the answer.
                              4. Ask me to approve it.
                              5. Write RELEASE.md.
                              </Plan>
                              The release program completed, so continue with the result.

                              The <Plan> content expands once to form the complete Prompt. Drafts stay
                              inert. After approval, the constrained authorship environment tears down, the
                              exact approved source is structurally admitted, and that source expands between
                              the surrounding prose.

                              An author who wants the approved program without carrying it out captures it:

                              <Planas="program">
                              Prepare the release program.
                              </Plan>

                              This binds the exact approved source under program and performs none of the
                              program's effects. Authorship and review are about the program's contents; they
                              do not change according to whether the authored document expands or captures
                              the result.

                              Current gap

                              PR #685 completed #660 by adding <Plan> to the ordinary run profile. The
                              component is currently a value component: it requires as, binds the approved
                              source as a string, and never expands that program.

                              xmd plan --run can execute an approved Plan, but it does so only after
                              authorship ends by starting a second root through the CLI. An embedded <Plan>
                              has no way to carry out its approved program inside the enclosing execution.

                              Contract

                              <Plan> produces approved XMD program source rather than ordinary rendered
                              text. Authorship always completes under the existing constrained authorship
                              profile, and the approved bytes have two engine-owned outcomes:

                              • without as, canonical execution admits and expands the source inline at the
                                <Plan> site;
                              • with as, canonical execution binds the exact source and does not expand it;
                                and
                              • stopped, rejected, exhausted, failed, or cancelled authorship produces no
                                program expansion and no binding.

                              The ordinary run profile declares this behavior as trusted host metadata on the
                              exact packaged <Plan> component. Markdown frontmatter, repository components,
                              workflow bundles, and component registrations cannot request it. Ordinary value
                              components continue to require as, including value components that return a
                              string.

                              Inline Plan source is an embedded text-root projection, not another document
                              execution:

                              • its own frontmatter metadata, imports, and <Output> selection apply;
                              • it sees the caller's bindings and current ambient props; when it declares
                                root props, that schema validates the current props before its first effect;
                              • a source declaring root returns is refused before its first effect because
                                an inline <Plan> has no destination for a root value; and
                              • it uses the enclosing execution's current component selection, Workspace,
                                authority, output flow, failure mode, and cancellation scope.

                              The inline projection creates no second lifecycle, root result, journal, or
                              host profile. Its expansion and every effect receive durable identities beneath
                              the authored <Plan> site. Replay restores the exact approved source without
                              repeating authorship and resumes an interrupted expansion without repeating a
                              completed effect.

                              Security and durability

                              • No candidate, rejected draft, or captured program executes.
                              • The authorship profile tears down completely before approved source can
                                expand or be bound.
                              • The approved program receives only the authority already present at the
                                authored execution site; model output grants no authority.
                              • The trusted executable-source disposition is unavailable to document-authored
                                components and is captured with the run profile before installation begins.
                              • Admission retains the exact approved source, and ordinary component selection
                                records detect an incompatible replay instead of silently selecting a
                                different implementation.
                              • Adding as prevents every effect of the approved program while preserving the
                                same authorship and review contract.

                              Acceptance

                              • <Plan> without as expands one approved program exactly where the component
                                appears: an observable effect between two surrounding markers occurs once,
                                and no approved source text is emitted in its place.
                              • The same <Plan as="program"> binds byte-for-byte approved source while a
                                negative-control effect in that source does not occur.
                              • Stopping, rejecting, exhausting, failing, or cancelling authorship leaves the
                                enclosing document without any approved-program effect or binding.
                              • Inline source uses representative current-profile syntax, caller bindings,
                                ambient props, imports, and <Output> behavior without starting another
                                document lifecycle.
                              • A declared root-props mismatch and a root returns declaration each refuse
                                the inline source before a negative-control effect runs.
                              • A partial journal resumes inside the approved program without another
                                authorship turn, review, or completed effect.
                              • An ordinary string-valued component still refuses an invocation without as,
                                and a repository component cannot opt into executable-source disposition.
                              • Validation, xmd syntax, the npm package, and the compiled binary describe
                                and ship the same <Plan> contract.

                              Evidence

                              Extend packages/cli/tests/plan-component.test.ts with immediate, captured,
                              refused, cancelled, and replayed Plan cases. Add focused core coverage for the
                              trusted disposition, embedded text-root projection, and ordinary value-component
                              negative control. The tests fail if captured source executes, replay authors
                              again, a root contract is discarded, or inline expansion starts another root.

                              Run the exact focused files plus deno task test --changed. Distribution probes
                              cover the npm and compiled assets when the packaged <Plan> declaration
                              changes.

                              Dependencies and related work

                              Out of scope

                              • A public Markdown frontmatter field for executable-source returns.
                              • Deferred full-program expansion through <Evaluate>.
                              • An independent nested-document <Run> component or process isolation.
                              • Executing an unapproved draft.
                              • Widening the authorship Agent's tools, filesystem, network, or permission
                                ceiling.
                              • Giving ordinary string-returning components executable behavior.

                              Activity

                              Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

                              Metadata

                              Metadata

                              Assignees

                              No one assigned

                                Labels

                                enhancementNew feature or request

                                Projects

                                No projects

                                  Milestone

                                  No milestone

                                  Relationships

                                  None yet

                                  Development

                                  No branches or pull requests

                                  Issue actions