# Triage JSON Recovery Implementation Plan

## Goal

Allow an invalid triage response to default safely to review while making all JSON repair calls formatting-only, tool-free, and isolated from repository context.

## Tasks

1. Introduce exact per-stage repair contracts and a typed double-invalid-output error.
2. Load the repair prompt without shared review instructions and send only the contract, invalid response, and parser error.
3. Add per-execution tool selection and run repair agents with `--no-tools`.
4. Catch only typed triage format failures, emit a visible fallback milestone, and continue with `review: true`.
5. Add regression tests for fallback, execution failures, required-stage failures, repair isolation, tool disabling, and progress rendering.
6. Update release notes, run complete checks, and replay packageauth PR 262 with the local extension.

## Acceptance Criteria

- Double-invalid triage output continues to summary and review.
- Triage execution errors and cancellation do not fall back.
- Double-invalid output from required stages remains incomplete.
- Repair calls cannot read the repository and do not receive snapshot or original-task context.
- The user sees a concise triage fallback milestone.
- Existing valid-output and publication behavior is unchanged.
