Expand description
Capability→tool matrix, gated capability→tool matrix, and explicit signing denylist.
The UNGATED matrix (grants_for_capability / ALL_MATRIX_ENTRIES) is
the admission path for non-signing toolset actions. Tools NOT listed here are
default-denied regardless of what capabilities a toolset declares.
The GATED matrix (GATED_MATRIX_ENTRIES) is a SEPARATE tier for
signing-adjacent capabilities. It routes SignPayment → stellar_pay_commit
ONLY through the first-invoke gate. stellar_pay_commit STAYS in
SIGNING_DENYLIST; resolve_action does NOT resolve sign-payment; the
ungated ALL_MATRIX_ENTRIES invariant tests iterate the ungated tier only.
§Security invariants
§Ungated tier
{ungated matrix grant tools} ∩ {SIGNING_DENYLIST} = ∅by literal name.- Every ungated matrix tool name EXISTS in the static
inventoryregistry. - Every SIGNING_DENYLIST name EXISTS in the static
inventoryregistry (so the denylist cannot silently rot into referencing renamed/removed tools). - Every ungated matrix tool has
destructive_hint == false(transitive-signing lock).
§Gated tier
- The gated tool (
stellar_pay_commit) IS inSIGNING_DENYLIST— this is INTENTIONAL and is the load-bearing invariant proving the ungated path is blocked. The gated tier is NOT inALL_MATRIX_ENTRIES. - The gated tool is reachable ONLY via (four-part check AND a current first-invoke grant) — the end-to-end gate is verified by the MCP server’s integration suite once that crate is added (full tool inventory required at link time).
SignPaymentgrant ∩ {sep43/sep53 bare-sign tools} = ∅.- The gated tool exists in the static
inventoryregistry. {flattened GATED_MATRIX_ENTRIES tools} ⊆ SIGNING_DENYLIST(structural proof that no gated tool is reachable via the ungated path). Asserted bygated_matrix_entries_subset_of_signing_denylist.
Inventory-based checks (invariants 2, 3, 4, 8 above) require the full MCP tool inventory at link time and therefore live in the MCP server’s integration suite once that crate is added.
Adding a new tool to the ungated matrix requires:
- Confirming it is NOT a signing/key/policy-mutation tool.
- Adding it to the appropriate capability grant array below.
- Adding a test that verifies it is NOT in
SIGNING_DENYLIST. - Verifying it has
destructive_hint == falsein the registry.
Adding a new tool to the GATED matrix requires:
- Confirming it IS a signing-adjacent tool that should remain in
SIGNING_DENYLIST. - Adding the capability →
[tool_name]entry toGATED_MATRIX_ENTRIES. - The tool MUST NOT appear in
ALL_MATRIX_ENTRIES(ungated tier). - A new
ApprovalKindarm may be required if the grant shape differs.
§Adding a signer to an ungated-matrix-listed tool
If a future implementation of an ungated matrix tool adds signing or
submission behaviour (e.g. stellar_pay gets an optional sign flag), REMOVE
that tool from its matrix grant row before merging. The precedent: signing
lives only in *_commit / sep4x_sign_* / sep53_sign_* tools, NEVER in
stellar_pay.
Constants§
- ALL_
MATRIX_ ENTRIES - All (action_name, granting_capability) pairs in the matrix.
- ALL_
MATRIX_ TOOL_ NAMES - All tool names that appear in the UNGATED matrix (deduped, in stable order).
- GATED_
MATRIX_ ENTRIES - All (capability, tool_name) pairs in the GATED matrix.
- OBSERVE_
EVENT_ GRANTS - Tools granted by
Capability::ObserveEvent. - PROPOSE_
TRANSACTION_ GRANTS - Tools granted by
Capability::ProposeTransaction. - READ_
BALANCE_ GRANTS - Tools granted by
Capability::ReadBalance. - READ_
RULES_ GRANTS - Tools granted by
Capability::ReadRules. - SIGNING_
DENYLIST - Explicit by-name denylist of signing, key-derivation, policy-mutation, and reflexive-escalation tools.
- SIGN_
PAYMENT_ GATED_ TOOLS - The single gated-tier entry for
SignPayment. - SIGN_
RULE_ CREATE_ AMOUNT_ SENTINEL - Sentinel
authoritative_amount_stroopsvalue forsign-rule-creategated calls. The amount dimension carries no independent meaning for rule creation; a fixed positive value keeps the (required-positive) bucket check satisfied and makes everysign-rule-creategrant/invoke land in the SAME[0, 1]bucket, so re-prompting is driven entirely byauthoritative_destination(the smart account), not by this value. - SIGN_
RULE_ CREATE_ ASSET_ SENTINEL - Sentinel
authoritative_assetvalue forresolve_toolset_sign_payment_gatedcalls routingsign-rule-create(Package D, GH issue #8). - SIGN_
RULE_ CREATE_ GATED_ TOOLS - The single gated-tier entry for
SignRuleCreate(Package D, GH issue #8). - SUGGEST_
DESTINATION_ GRANTS - Tools granted by
Capability::SuggestDestination.
Functions§
- gated_
grants_ for_ capability - Returns the gated grant set for a signing-adjacent capability.
- grants_
for_ capability - Returns the UNGATED grant set for a capability.
- resolve_
action - Resolves an
actionstring to a(&'static str, Capability)pair via the CLOSED matrix lookup.