Not every app will require or expect a '/messages' route, but if a user logs in with an extension then they will be spammed with decryption events unrelated to their prompt/build.
(package-lock.json changes are from verifying "npm run test")