{"actions":{"bootstrapAndRun":{"effect":"installs rote if missing, inspects, prepares, and asks before running","href":"https://play.modiqo.ai/install?play=himanshu-jha/archive-extraction-ambiguity@0.1.0","method":"GET","rel":"https://rote.dev/rels/bootstrap-and-run","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"inspect":{"command":"rote play inspect https://play.modiqo.ai/himanshu-jha/archive-extraction-ambiguity@0.1.0","effect":"read-only"},"installCliOnly":{"effect":"installs the rote CLI, nothing else","href":"https://play.modiqo.ai/install","method":"GET","rel":"https://rote.dev/rels/install-cli","requiresConsent":true,"responseMediaType":"text/x-shellscript"},"run":{"command":"rote play run https://play.modiqo.ai/himanshu-jha/archive-extraction-ambiguity@0.1.0","effect":"executes the play locally after consent","headless":{"approvalAssertion":"--yes","approvalRequiredBeforeInvocation":true,"commandTemplate":"rote play run https://play.modiqo.ai/himanshu-jha/archive-extraction-ambiguity@0.1.0 <name=value...> --yes","stdinPolicy":"never pipe input to automate the interactive Ready selector"},"requiresConsent":true}},"description":"Preflights an archive manifest before extraction by modeling the destination as a virtual namespace. Use it for every uploaded or third-party release archive before extraction, and again when extraction policy changes. Four independent probes detect traversal and platform aliases, order-sensitive symlink or hardlink write-through, case/Unicode/file-directory collisions, and entry-count/size/ratio expansion hazards; symlink targets are parent-relative while hardlink targets use an explicit coordinate mode that defaults to archive-root-relative. A synthesis step joins them into one severity-prioritized extraction decision. It reads a JSON manifest and never extracts, writes, follows links, or accesses the network. Run with input=path/to/manifest.json, or omit input to use the bundled adversarial demo. Limits: findings depend on the supplied manifest and policy, nested archive contents are not recursively inspected, and filesystem-specific canonicalization is approximated conservatively.","distribution":{"digest":"sha256:f4edb0b8c4fe4810d24ae28059d68ed8c954be5e7493b0d6ca5b5cbad65f7bb0","mediaType":"application/vnd.modiqo.rote-flow","size":11159,"verifiedBy":"rote verifies the downloaded archive against this digest before it runs"},"effects":{"credentialsProvidedBy":"runner","credentialsRemainLocal":true,"declaredWrites":[],"publisherReceivesCredentials":false},"id":"https://play.modiqo.ai/himanshu-jha/archive-extraction-ambiguity@0.1.0","inputPolicy":{"optionalWithDefault":"show_default_and_accept_override","optionalWithoutDefault":"omit_unless_supplied","required":"ask","secrets":"collect_locally_outside_conversation"},"license":"MIT","links":{"docs":"https://rote.dev","page":"https://play.modiqo.ai/himanshu-jha/archive-extraction-ambiguity@0.1.0","protocol":"https://play.modiqo.ai/.well-known/rote","self":"https://play.modiqo.ai/himanshu-jha/archive-extraction-ambiguity@0.1.0.json"},"name":"archive-extraction-ambiguity","owner":{"kind":"org","slug":"himanshu-jha"},"parameters":[{"description":"Workspace-relative JSON archive manifest. Omit it to analyze the bundled demo; pass input=manifests/release-bundle.json for fresh evidence.","example":"manifests/release-bundle.json","input":{"allowCustom":true,"choices":[],"label":"Input"},"name":"input","required":false,"type":"string"}],"preparation":[{"action":{"command":"rote play inspect https://play.modiqo.ai/himanshu-jha/archive-extraction-ambiguity@0.1.0 --json","effect":"read-only"},"step":1,"type":"inspect_local_readiness"},{"references":["/parameters"],"step":2,"type":"collect_parameters"},{"references":["/parameters","/requirements","/effects"],"step":3,"type":"review"},{"consentBoundary":"the user approves the exact play and parameter values","references":["/parameters","/requirements","/effects"],"step":4,"type":"obtain_run_consent"},{"action":{"command":"rote play run https://play.modiqo.ai/himanshu-jha/archive-extraction-ambiguity@0.1.0","headlessCommandTemplate":"rote play run https://play.modiqo.ai/himanshu-jha/archive-extraction-ambiguity@0.1.0 <name=value...> --yes"},"preservesAcquisitionBoundaries":["adapter_selection","oauth_dcr","google_discovery","static_token_setup","runtime_security_checks"],"requiresConsent":true,"step":5,"type":"run"}],"producedBy":{"roteVersion":"0.78.0"},"publishedAt":"2026-09-04T12:19:39.941147+00:00","reference":"himanshu-jha/archive-extraction-ambiguity@0.1.0","requirements":{"adapters":[],"browser":{"dependencies":[],"runtime":false,"signIn":false},"localTools":["python3"],"roteCli":{"minimumVersion":"0.62.0"},"sessions":false},"resolution":"pinned","schema":"rote.play.v1","stats":{"downloads":3,"installs":0},"steps":{"count":5,"names":["detect_canonical_collisions","enforce_expansion_budget","map_virtual_namespace","synthesize_extraction_decision","trace_link_write_through"]},"title":"archive-extraction-ambiguity","type":"play","version":"0.1.0","visibility":"public"}