The shelf
Publishing something you wrote, installing something somebody else wrote, and the four rules that make that safe.
The shelf is in settings. It is a search box, and then everything that has been published, as cards.
What you already have is a filter on that shelf rather than a section above it: a marketplace whose first screen is your own inventory is a filing cabinet. And the body is on the card, not behind a details link, because you should be able to read a thing before you install it.
What can be published
Wildcards. A short expansion: you type its trigger in a script field and the body is inserted as text. Nothing runs. Bodies are capped at eight thousand characters.
Scripts. These run, so they travel as a package rather than as text: the body, the front-end half, the trigger definition, and the libraries the script reaches for. An earlier version went through the clipboard, which carries text, so publishing flattened a script to its body and silently dropped the rest. That is why it is a package now.
Custom commands cannot be published, deliberately. A command shows a name, not a destination. It is the one artefact whose body you cannot judge by looking at it.
There is no separate "snippet" kind: it was a wildcard with a second name and a second store.
The four rules
Publication stops on a suspected secret and shows what it found. It never cleans it up quietly and publishes anyway.
What an artefact does is calculated from its body, never declared by its author. The card says whether it is text, whether it runs in the page, whether it reaches the server, whether it writes. When the calculation is unsure it reports the worse of the two possibilities.
Installing never overwrites. A trigger you already use is renamed, and you are told that it was.
A published artefact changes by version, and only its author changes it. An install names the version it was shown, and gets that version or nothing. What you installed cannot be edited underneath you.
The page runs those checks too, so it can tell you why before you press the button. But the worker runs the same module again and is the one that decides, because anything running in a page can be changed by that page.
Every install asks first
What comes off the shelf was written by another user, and it runs as you. So every install opens a warning first: who wrote it, what it is called, what it does, and a link to the Market terms. The terms box is ticked once and remembered with the date of those terms, but the warning itself comes back for every install. Cancel, Escape or a click outside installs nothing.
