The shell CSP pinned the markdown editor's inline script and the mermaid
frame's inline script, so editing either one needed a new native binary.
Both scripts now ship as content-addressed package assets that their
documents load by src, and the editor moves from a `data:` frame that
inherited the shell policy to a package document of its own.
`'self'` cannot carry these: the frames are sandboxed, and WebKit resolves
`'self'` against the frame's opaque origin, so it matches nothing there
(Chromium resolves it against the response URL and does match). The native
frame policy names the per-session package origin instead.
Claude-Session: https://claude.ai/code/session_01JNnE9qzUZMMnqpZWCqM3nb