Both candidates this file named for the missing phase-script bytecode were tested statically, from the flat-VA .pe and the extracted paks. REFUTED: the seven .embsec_ sections hold PPC CODE. Parsed from the section table (offset 592, 40 bytes apart) they total 129472 bytes, matching this file's own "~130 KB" estimate, so they are the right sections -- but six of seven begin 7d8802a6 (mflr r12) and all carry the standard prologue (stwu r1,-N(r1), std r30,-16(r1), bl). That is not bytecode for a 147-builtin VM. Also recorded: ".embsec_P" from `strings` is a false lead -- the name field is exactly ".embsec_" and the P is byte 0x50 of the following VirtualSize (0x1350 = 4944, the fifth section's size). CORRECTION: this file says grepping for MISSION_START_PRT "returns nothing". That grep was over the DISC EXTRACTION; all five MISSION_*_PRT names are present in the executable image, in an .rdata table reading "SCRIPTS" "GP_SCRIPT" "script load cancel\n" "MISSION1".."MISSION33". NARROWED: the paks are name-hash addressed, so names can be probed rather than eyeballed. 616 distinct hashes -- MISSION1..33 and the five MISSION_*_PRT under prefixes SCRIPTS\, GP_SCRIPT\, scripts\, script\, SCRIPT\ and none, with suffixes .prt/.PRT/.scr/.bin and none -- across all 35 paks: ZERO hits. Left open: the XEX's compressed/encrypted region, or a name outside those guesses. GP_SCRIPT is the strongest remaining thread -- referenced by code, absent from disc.