Move Arcade 0.3.0. Vendored: @mediapipe/tasks-vision 1.1.0 (web/mp/vision_bundle.mjs is LOCALLY PATCHED, see below; vision_wasm_* unmodified), three 0.186.1 (web/mp/three.*.js, unmodified), MediaPipe pose_landmarker_lite.task (web/models/, unmodified). Build: GOOS=windows GOARCH=amd64 go build -ldflags "-H=windowsgui -s -w -X main.version=0.3.0"

LOCAL PATCH to web/mp/vision_bundle.mjs (MediaPipe tasks-vision 1.1.0): its built-in usage logger (class Mh) POSTed protobuf to https://odml.pa.googleapis.com/v1/log every 60 s. Disabled in this copy by 3 edits:
 1. constructor: `this.h=setInterval(()=>{this.flush()},6e4)` -> `this.h=void 0`   (no timer)
 2. close(){...this.flush()} -> close(){this.i=[]}; flush(t,e){ now starts with `this.i=[];t?.();return;` (discard, never send); the URL literal is replaced by "about:blank#telemetry-disabled"
 3. event enqueue `(t=t.m).error||t.i.push(e)` -> `void 0` (nothing is queued)
Original is the unmodified npm tarball @mediapipe/tasks-vision@1.1.0. In addition the local server sends a Content-Security-Policy with connect-src 'self' data: blob:, so no page script can contact any other host.
