Hi @Ilaye 
First — a sincere apology for how long it took to get a proper response to this. You’ve raised it multiple times, and you deserved an answer sooner. Thank you for your patience and for the exceptionally clear write-up. 
Good news: this is done, and it ships today (Friday)! 
What’s changing
frame-src is now supported in ui.csp_overrides — exactly the way you proposed: an explicit allowlist of https:// origins, scoped the same way external_origins already works (no wildcards, no open directive, up to 8 origins).
"ui": {
"csp_overrides": {
"frame-src": ["https://www.youtube-nocookie.com"]
}
}
And a bit more you didn’t ask for (but would have hit next) 
While implementing this, we found two more walls behind the CSP one, and fixed both:
Permissions-Policy delegation — declaring frame-src now automatically delegates autoplay, encrypted-media, fullscreen, and picture-in-picture to your declared origins, through the whole chain. Without this, the player would render but fullscreen and autoplay-after-timestamp-jump (your core use case!) would silently fail. One thing you still do on your side: add the allow attribute to your own embed iframe:
<iframe
src="https://www.youtube-nocookie.com/embed/VIDEO_ID?start=42"
allow="autoplay; encrypted-media; fullscreen; picture-in-picture">
</iframe>
Referrer-Policy — YouTube embeds require a Referer to validate the embedding origin. Apps that declare frame-src now get strict-origin-when-cross-origin on bundle assets (origin only, no paths leaked). Tip: don’t add referrerpolicy="no-referrer" to your embed iframe, or the player will fail with error 153.
How to get it
Platform update rolls out today
Then update the CLI: @anna-ai/cli@0.1.56
Docs: the app-ui-manifest page has a new “Embedding third-party content (frame-src)” section
Working example: anna-app-frame-embed-demo in the examples repo — a minimal app embedding a video player with timestamp-jump buttons (your exact scenario)
One parity note: the local harness does not simulate CSP or Permissions-Policy headers, so an embed that works locally isn’t proof it will work in production. Please rely on anna-app validate and a working draft on the platform for final verification.
On the native video-playback host API
We considered it, but decided against it (for now): YouTube’s ToS requires the official iframe player anyway, so a host-mediated component would face the same embedding constraints — just moved to our page instead of yours — while locking the solution to video. Scoped frame-src solves the general case: maps, players, document previews, any explicitly-declared third-party embed. 


Really looking forward to seeing the YouTube research assistant in the store — jumping to cited timestamps in-window sounds genuinely delightful. If anything doesn’t behave as described once this lands, post here and we’ll jump on it fast. 