UpdatePackage (POST /packages/:id/update) validates semver bump, applies additive schema migration, merges settings (new keys with defaults, existing preserved), replaces assets, and re-syncs permissions/triggers. ExportPackage (GET /packages/:id/export) streams the installed package as a .pkg ZIP archive containing manifest.json and all assets. Completes the manual rollback story: export before update, re-install old .pkg if needed. Co-Authored-By: Claude Opus 4.6 (1M context) <noreply@anthropic.com>