Expand description
Catalog of the semantic-security capabilities the stdlib host functions
gate via check_security. This is the single source of truth behind
submilli blueprint init, the submilli blueprint capability verbs, and
the server’s GET /v1/capabilities, so an operator sees every capability
the runtime can gate.
Keep in sync with the host functions. When a host fn in stdlib::fs /
stdlib::http (or a new gated module) starts or stops gating a capability,
update the matching entry here — see AGENTS.md. The capabilities test in
the submilli CLI asserts every example_filter below parses.
Structs§
- Capability
- One gated capability and the policy
filter:surface it exposes. - Capability
Group - A group of capabilities sharing a source module, for scaffold sectioning.
- Filter
Field - One context field a capability’s
filter:expression can match on.
Enums§
- Field
Normalization - A rewrite the runtime applies to a field’s value before checking it. Call-site
derivation applies the same rewrite to a literal argument, so the filter it
writes into
requiresnames the value the policy is asked about.
Constants§
- HTTP_
OTHER_ METHOD - Every other method
http.requesttakes, gated ashttp.<method>with the method lowercased:http.request("TRACE", …)checkshttp.trace. Kept out of [CORE_CATALOG], whose consumers read a templated name asmcp.<server>and concretize it per declared server; seeuncataloged_http_method.
Functions§
- catalog
- Every capability the core packages gate, grouped by source module. An
optional package’s capabilities are listed only by
catalog_for. - catalog_
for - Every capability the packages of
stdlibgate, grouped by source module, incatalog’s order: by module name without itssubmilli:or@prefix. - find
- Look up a core capability by its exact name (templates included, by their
literal
mcp.<server>spelling). - find_
for findamong the capabilities ofstdlib.- find_
gating - The entry describing
name: its catalog entry, orHTTP_OTHER_METHODfor a name that fills it. - find_
gating_ for find_gatingamong the capabilities ofstdlib.- uncataloged_
http_ method - The method of a name that fills
HTTP_OTHER_METHOD:http.and a method token in the lowercase form the runtime checks, which the catalog has no entry for.