Imported from AuroraAeon/x-video-downloader (
AGENTS.md). Install upstream withnpx skills add AuroraAeon/x-video-downloader. Copyright stays with the author.
X Video Downloader
This is an independent Chrome Manifest V3 extension, not a MediaCrawler component.
- Use pnpm and the pinned lockfile. Build output goes in
dist; publish ZIPs fromrelease. - Keep page input untrusted. Only trusted content-script UI actions may start downloads.
- Keep runtime code bundled locally. Never add fixed X query IDs, authentication exports, remote code or a backend requirement.
- Preserve complete candidate inspection, lossless audio extraction and layout outside the player when optimizing.
- Background inspection must be bounded and cancellable. Partial quality must never be labelled as confirmed highest quality.
- Keep
package.jsonandpublic/manifest.jsonversions equal. Update README (README.mdandREADME.en.mdtogether), CHANGELOG and validation evidence with releases. - Keep user-facing text in
public/_locales/{en,zh_CN}/messages.json; runtime code renders the bundled catalogue, notchrome.i18n.getMessage. Every parameterised message must declareplaceholders: undeclared substitutions makegetMessagereturn mangled text and corrupt the manifest name and description. Browser suites pinlocale: "en-US"; never assert message text under the host machine's language. - Store listings depend on the hosted site in
docs/site(privacy policy URL). Site claims andpublic/manifest.jsonmust stay consistent:tests/privacy-claims.test.tsgates the origins, permission table and bilingual policy,tests/site.test.tsgates labelled versions, hreflang, sitemap, share-image URLs and store image sizes. Regenerate imagery withpnpm assets; do not hand-editdocs/site/assets. Never state that a store listing exists, is pending or is in review until a submission actually exists.tests/community.test.tsgates the issue forms and the front page (links, version, store status). Release automation reads credentials from environment variables only; never commit store or OAuth secrets. - Run
pnpm typecheck,pnpm test,pnpm build,pnpm test:e2e,pnpm test:layout, andpnpm exec node scripts/check-package.mjsas relevant. - Performance claims require the same fixture, latency and candidate results on both builds. Use
scripts/performance.mjsand document real-site network limits separately. - Do not commit
output, credentials, local browser profiles, recordings or downloaded media.