--- name: update-web-assets description: > Update the third-party JavaScript vendored into the app for the artifact, diagram, and math WebViews (KaTeX, mermaid, marked, highlight.js, Tailwind, Babel, React). Checks what is outdated, reads each pin's rationale before proposing a bump, re-downloads from the official source, verifies the lock, and runs the gates. Ends by naming what must be checked on a device, because a broken WebView asset fails silently. Use when bumping a vendored web library, adding a new one, or investigating whether a rendering bug comes from a stale pin. allowed-tools: Bash, Read, Edit, Write, Glob, Grep, WebFetch, AskUserQuestion argument-hint: "[asset-id ...] (optional, defaults to checking all of them)" --- # Update vendored web assets The artifact, diagram and math renderers are WebViews, and every script they execute ships inside the app. `scripts/web-assets.json` is the registry; `scripts/vendor-web-assets.py` moves the bytes; `scripts/web-assets.lock.json` records a sha256 per file and CI verifies it. **Read `scripts/web-assets.json` before doing anything.** Every entry carries a `pin_reason`, and several of them are load-bearing rather than informational — two pins must NOT be moved to the newest version, and the reason is in the file, not in this skill. ## What makes this different from a Gradle dependency bump A wrong version here does not fail the build, fail a test, or throw anything Kotlin can catch. The failure happens inside the WebView, and the usual shape of it is a blank box or a feature that quietly stops working. Both libraries this system replaced were already broken that way before anyone noticed: - **marked** deleted its `highlight` option in v5. Passing one to `setOptions` is accepted and silently ignored, so syntax highlighting had been dead with no error anywhere. - **highlight.js** was being loaded from a URL that served CommonJS. In a browser `