Pure capability-card verification primitives, shared by the CLI
(treeship verify-capability) and the WASM verifier (browser receipt
viewer) so both agree by construction. No I/O: callers supply the parsed
card, the action statements, and the trust roots.