Should the 4th point read "route to the NAT Gateway"?
Yes, you are correct…that is a typo. Should be vpg-id. Not sure which one you’re refering to about the 4th point. From within a VPC that has an S3 endpoint, traffic will route to the S3 endpoint gateway based on its IP address in that prefix list.