Tubearchivist
TubeArchivist API integration — manage videos, channels, downloads, and search
| Argument | Type | Description |
|---|---|---|
| query | string | Search query |
Resources
2026.08.08.1
Two bug fixes, both found by using the model against a live TubeArchivist instance rather than by reading it.
searchwas broken for every query. It built?q=<query>, but TubeArchivist's/api/search/readsquery. Every call came back400 {"message":"no search query specified"}— the method has never worked. Now sends?query=.- The
tokenglobal argument was not declared sensitive. swamp reads thesensitivemarker off the schema to decide what to mask, so an unmarked credential is written verbatim into@swamp/method-summaryreport data — both the rendered markdown and the JSON payload — on every method run, including failures, and that data is persisted. This was a known gap: the wave-2a security review found it and pinned it intubearchivist_coverage_test.tsas a documented HIGH finding to be fixed in follow-up, becausetubearchivist.tswas byte-frozen at the time. It was not theoretical — a real API token was later found in cleartext in a stored failure report. Now carries.meta({ sensitive: true })and redacts to***.
Both fixes were driven test-first; all three new assertions failed against the unfixed model before the change.
Note for anyone who ran this model before upgrading: the sensitivity fix only stops future leaks. Tokens already written into stored report data are still there in cleartext — rotate the token.
Tests: 126 → 128 pass.
tubearchivist_methods_test.ts— the happy-path search test assertedsearchParams.get("q"), i.e. it had characterized the bug as correct behavior. Retargeted toquery, plus a new regression test that also assertsqis absent, so a future "send both to be safe" edit is caught.tubearchivist_coverage_test.ts— thetoken is NOT marked sensitivepin is flipped to assert the annotation is present, exactly as that pin's own failure message instructed. Also pins the negative (hoststays unredacted) so a blanket "mark everything sensitive" change doesn't pass.tubearchivist_adversarial_test.ts— the unicode round-trip test also readq; retargeted toquery. Percent-encoding assertion unchanged.
Release 2026.07.16.2 — align model versions with manifests
Maintenance release across the @magistr extensions. For most packages this
carries no functional change: the only edit is the model's version: field,
brought back in line with its manifest version so the published model type
version and the package version no longer drift.
Functional changes in this release are limited to:
anime-cron: normalizeTitle now strips a ": subtitle" suffix and a trailing parenthesized year before comparison, fixing dedup false-misses where the torrent title carries a subtitle or year that the AniList romaji does not.
arckit: first publish. Standalone ArcKit port — a 12-phase architecture governance state machine with 65 bundled templates, driven by a bundled skill.
Also tracks three extensions (kaiten, observability-agent, music-library) that previously existed only as untracked working-tree directories, recovered from stashes.
Added 1, removed 1 models
Merge pull request #4 from umag/extensions/magistr-grade-a-workspace
extensions: stage 15 @magistr extensions as Grade A workspace dirs + wire CI
- Has README or module doc2/2earned
- README has a code example1/1earned
- README is substantive1/1earned
- Most symbols documented1/1earned
- No slow types (deprecated)1/1earned
- Dependencies pass trust audit2/2earned
- Has description1/1earned
- Platform support declared (or universal)2/2earned
- License declared1/1earned
- Verified public repository2/2earned