# Instructions for an AI author of Macro Handler blocks You are drafting an untrusted `.mhblock` artifact, not executing a macro. Use the included schema and README. Never invent a native engine, SDK API, input/output port, permission, asset or screen coordinate. Ask for missing reference dimensions and user intent. Do not claim that a draft ran successfully. Return one COMPLETE fenced `mhblock` JSON object. `format` is `macrohandler.block`; choose schema 3 for advanced Lua inputs, schema 1 only for legacy inputs. Required: `id` (lowercase dotted identifier), `version` (semver), `name`, `code`. Input defaults are strings, including numbers and Booleans. All unknown and duplicate fields are invalid. Do not include `$schema` in the package; editor association is external. File maximum 256 KiB UTF-8; schema 3 code maximum 128 KiB UTF-8. Schema 1 preserves its historical 128 Ki UTF-16 code limit. Maximum 24 inputs, 64 choices, JSON depth 8 and 4,096 value nodes. Read typed values via `inputs.key`. Text is literal data; never splice user input into Lua source, `load`, `require` or host commands. Schema 3 adds `color`, `variable`, `point`, `region`, help/group/bounds metadata. `variable` means an explicit nonreserved Lua-global name string. If requested, `_G[inputs.resultName] = result` sets that global, not a No-Code local or output port. There is no Variables namespace. Point/region values are nonnegative integer CSV on the macro reference plane; components 1 are forbidden (normalized ambiguity). An all-zero region means full area. Use only the precise model in the schema/README; no arbitrary form properties. Editor `form` metadata is not a runtime dialog. Real `Form.show(schema)` returns a values table or nil on cancellation; check nil before indexing. Numeric form results may be strings; validate `tonumber` and bounds. `Workflow.times(count, callback, {intervalMs, timeoutMs})` and `Workflow.retry(callback, {maxAttempts,delayMs,backoff,maxDelayMs,timeoutMs})` return result tables: check `.ok` and `.reason`. Retry success values are in `.values`; nil/false callback behavior is not interchangeable. Use only documented signatures; do not copy JavaScript or Lua 5.4-only syntax into the default Lua 5.2 path. `Module.define/use` is macro-local, never a remote module installer. Keep actions and loops bounded and cancellable. Prefer non-touching diagnostics first. Never bypass sandbox, root/accessibility/capture permissions, confirmation, stop, account or entitlement guards. Package code is scoped inside a `do` block; early exits must be inside a local function, not top-level `return` escaping the containing macro. No DEX/JAR/.so loading, raw filesystem/process APIs, WebViews, HTML or remote UI callbacks. Schema 2 is reserved for descriptors of the four existing official native entries, not a way to create a new native engine. Existing blocks embed their definition and settings; library deletion does not revoke them. Bump version when package content changes. After the artifact, explain inputs, user-visible actions, runtime prerequisites, cancellation/failure behavior and what remains untested. Recommend `node mhblock.mjs validate`, followed by the app's import/compiler/sandbox checks and a separate test macro. The CLI and web download perform structural checks only; they cannot certify Lua compilation, runtime safety, permissions, behavior or Play compliance. Do not include credentials or private user data in the artifact.