# Review hosted Project Types

Review each hosted Block for import while tracking which connected Steps still need execution.

A Project Type can include reviewed `text.generate`, `audio.speech`, and
`image.generate` Blocks alongside local recipe/JavaScript Blocks and StillMade
workspaces. Import checks two separate things: whether every embedded package is
safe and reviewed, and which parts of the connected workflow have actually run.
Passing independent Block fixtures does not prove their connected production flow.

### Prepare portable source

The source contains ordinary pinned packages and connections. It never contains
account receipts, chosen payment methods, API keys or provider approval. For
example, run this from the extracted SDK directory to create a script-to-speech
Project Type using the included complete Block examples:

```js
import {writeFile} from 'node:fs/promises';
import {textGenerate} from './packages/block-sdk/capability-example.js';
import {audioSpeech} from './packages/block-sdk/speech-example.js';

const type = {
  schemaVersion: 1,
  id: 'creator.script-and-speech',
  version: '1.0.0',
  name: 'Script and speech',
  description: 'Draft a short narration script and turn it into reviewed speech.',
  license: 'MIT',
  stages: [
    {id: 'draft', blockId: textGenerate.manifest.id, version: '1.0.0', label: 'Draft narration'},
    {id: 'voice', blockId: audioSpeech.manifest.id, version: '1.0.0', label: 'Narrate script'}
  ],
  packages: [textGenerate, audioSpeech],
  connections: [
    {from: {stage: 'draft', port: 'script'}, to: {stage: 'voice', port: 'script'}}
  ]
};
await writeFile('script-and-speech.stillmade.json', JSON.stringify(type, null, 2), {flag: 'wx'});
```

This writes source only. It has not generated narration or speech. The offline
validator checks its structure, versions and typed connections. Local fixture
checks still execute in isolation; hosted fixture expectations require an account
review in StillMade. Source packaging does not install a package or authorize a
provider call.

### Review in StillMade

Open **Import package** and select the JSON or ZIP. Review each hosted Block with
the model, payment method, voice or image quality selected in the host controls.
An exact saved import review can be shown and accepted without new generation.
Running a new review still requires its displayed quote and explicit confirmation
for the fixtures and separate sample. Review actual text, audio or images before
accepting the evidence. Source, account or selection changes invalidate reuse.

Every embedded hosted package needs a matching review, including packages used
only by disabled Steps or currently unused packages. Repeated placements of an
unchanged package share one package review. They do not share a production run:
each placement's actual connected input still requires its own execution approval.

After package reviews, StillMade runs the local checks and the portions of the
sample flow that can execute locally. An enabled hosted Step is marked unexecuted;
its dependent Steps wait for its real output. They never receive the hosted
Block's independent fixture sample as a substitute. Missing independent context,
invalid connections and failing local code still prevent import. A genuinely
disabled Step or a valid conditional bypass keeps its ordinary workflow behavior.

The report distinguishes `passed` (package admission) from `workflowComplete`
(all enabled connected Steps completed). **Confirm Import** installs the reviewed
source, and the report continues to show any required workflow rehearsal. A new
release or another account's installation rechecks the receipts and current
source. ComfyUI-containing Project Types use their separate connection-bound
review map, described below.
Unattended hosted automation and a single complete hosted-workflow execution proof
remain separate work; an import report must not claim either one.

### Host review envelope

The authenticated host passes `typeCapabilityReviews` alongside `content` to
`POST /api/blocks/imports/review` and `/api/blocks/imports`, and alongside the
normal release/install fields to `/api/blocks/releases` and `/api/blocks/install`.
It is a plain object with exactly the distinct embedded hosted package digests:

```js
const typeCapabilityReviews = {
  [exactPackageDigest]: {
    receiptId: verifiedReview.receiptId,
    selection: verifiedReview.selection
  }
};
```

Use the SDK `digest(package)` on the entire exact package. The map has at most
100 entries and is at most 64 KiB as JSON. Each entry contains only `receiptId`
and the existing exact host `selection`. Unknown/missing digests, another
account's receipts, changed source, expired receipts or invalid retained media
are rejected. The server rechecks before writing the import, release or install;
these checks never generate output or charge again. They do not extend a review's
one-hour standalone import expiry. Project-only expired evidence cannot be used.

The server returns the sanitized map in the account review report, outside the
portable source. A host may use `verifyHostedProjectTypePackages` from
`packages/block-platform/hosted-type-reviews.js` with its trusted authenticated
receipt verifier to obtain the opaque `verifiedHostedPackages` option for
`testProjectType` and `previewProjectType`. Guest JSON cannot construct this
in-memory proof. The helper itself does not authenticate receipts; ordinary Block
authors should use StillMade's review UI.

### Retained samples and setup

Saved imports, releases and hosted installations retain their reviewed sample
media through account-bound server reports. Installed review metadata stores
no extra source copy and grants no release access. Removing team access still stops new private source downloads.
Retaining a historical sample does not extend its import-approval expiry. Legacy
installations without a saved report are not retroactively assigned a receipt.
The current storage and encrypted BYOK vault are reused.
