Skip to main content

Module capabilities

Module capabilities 

Source
Expand description

Catalog of the semantic-security capabilities the stdlib host functions gate via check_security. This is the single source of truth behind submilli blueprint init, the submilli blueprint capability verbs, and the server’s GET /v1/capabilities, so an operator sees every capability the runtime can gate.

Keep in sync with the host functions. When a host fn in stdlib::fs / stdlib::http (or a new gated module) starts or stops gating a capability, update the matching entry here — see AGENTS.md. The capabilities test in the submilli CLI asserts every example_filter below parses.

Structs§

Capability
One gated capability and the policy filter: surface it exposes.
CapabilityGroup
A group of capabilities sharing a source module, for scaffold sectioning.
FilterField
One context field a capability’s filter: expression can match on.

Enums§

FieldNormalization
A rewrite the runtime applies to a field’s value before checking it. Call-site derivation applies the same rewrite to a literal argument, so the filter it writes into requires names the value the policy is asked about.

Constants§

HTTP_OTHER_METHOD
Every other method http.request takes, gated as http.<method> with the method lowercased: http.request("TRACE", …) checks http.trace. Kept out of [CORE_CATALOG], whose consumers read a templated name as mcp.<server> and concretize it per declared server; see uncataloged_http_method.

Functions§

catalog
Every capability the core packages gate, grouped by source module. An optional package’s capabilities are listed only by catalog_for.
catalog_for
Every capability the packages of stdlib gate, grouped by source module, in catalog’s order: by module name without its submilli: or @ prefix.
find
Look up a core capability by its exact name (templates included, by their literal mcp.<server> spelling).
find_for
find among the capabilities of stdlib.
find_gating
The entry describing name: its catalog entry, or HTTP_OTHER_METHOD for a name that fills it.
find_gating_for
find_gating among the capabilities of stdlib.
uncataloged_http_method
The method of a name that fills HTTP_OTHER_METHOD: http. and a method token in the lowercase form the runtime checks, which the catalog has no entry for.