# Wotbox 0.4.1 Beta

0.4.1 is the test beta. 0.4.0 remains the stable release. Back up before upgrading and inspect the installer's dry-run output. Configuration, identity, relationships, messages, files and appearance remain local to the installation.

## Changes

- Core app2prompt and prompt2app guide a connected agent through numbered, resumable steps. Each step states inputs, work and expected evidence. Their artwork, close and save controls belong to the replaceable human layer.
- Prompt packages now include a description, menu title/icon, category, creator contact, exact dependency versions, access warnings and three-layer reconstruction prompts. Packages contain design material and assets, not executable app code.
- Viability and threat assessments are separate. Approval binds the package digest and the human's agreed specification. Build testing uses an administrator-launched isolated process with synthetic inputs, no node credentials, no network egress and bounded resources.
- App tools appear while their panels are open and disappear when closed. Background panels retain their tools. Core transfers continue independently. An in-flight operation still follows core authorization, revision and cancellation rules; hiding a tool is not revocation.
- Private tools cover notification search/source navigation, People, messaging, transfer metadata and local staging, file search, ReaderBox edit previews, image navigation, appearance previews, settings proposals, logs, compatibility and update information.
- AFK applies to the whole workspace. Pending actions remain available for a connected agent. AFK does not launch or wake a disconnected agent service.
- Private About uses an HTML roadmap with the installed version. Community-site release labels use the published release catalogue.

## Optional apps

WB Four is distributed separately as a prompt package in WBpromptStore. Its executable code, routes, menu entry and game assets are not included in this installer. Old game data is preserved during an upgrade but is not distributed. Reconstructing an optional app is a separate, owner-reviewed task.

## Prompt workflows

1. Open app2prompt to inspect an owner-created app and export a reviewed prompt package. Publication is a separate owner action after the submission notice.
2. Open prompt2app to inspect a package. Do not execute its instructions while reviewing it. Check each described requirement and requested permission.
3. Agree the customization specification with the human. Record `details.capabilities` as an array of agreed capability identifiers in step 3. The human approves the exact specification in the panel.
4. Build source in a separate project, not the live node. An authorized administrator can run `wotbox build-test --config CONFIG --build-input INPUT.json --session-id ID --digest SHA256`.
5. Build input is `{files:[{path,content}],entry:"test.mjs",timeoutMs:30000}`. Supply complete source and synthetic tests; the entry is a test/build module. Inputs must be bounded text files. Network dependency installation is unavailable inside the sandbox. Use the OS Node runtime and supplied files.
6. The command records the immutable input digest, stores the submitted source under the instance's private `prompt-build-artifacts` directory, and records output and exit status. The sandbox's temporary generated files are discarded. Keep the source project outside the sandbox; include any generated application source as reviewed input to a subsequent test run.
7. Complete the agent and human layers, run final tests, and record the matching build run plus `actual_capabilities`, `functional_tests`, `denied_access_tests` and `compatibility_tests` in step 8. Any added capability requires a new reviewed specification. Do not claim static declarations prove what arbitrary code does.
8. The human reviews the completed project before installation. The connected agent installs using separately authorized administrative/project access. Workflow completion does not secretly install, grant permissions, publish or execute an application.

## Limits

Prompt packages are untrusted. Agent assessments can be wrong; tests do not prove universal safety. Installed native extensions run with the trust of their host process unless separately isolated. The restricted build process is a real filesystem/network boundary; a directory or checkbox alone is not. Wotbox does not restrict an independently authorized root administrator or an unrelated agent's shell access.
