code wiki / cap

topic: cap

24 modules sharing the cap name family (derived from the tree's prefix discipline).

The 'cap' topic family provides capability-based security primitives for the Nishi sovereign ecosystem, ensuring secure and measurable control over system resources. The nx_cap_census serves as the unified capability driver, emphasizing measurement-first design, while nx_cap_detect_lib offers a silent-truncation detector for consistent rule enforcement. nx_cap_grant_e2e_gate acts as the capstone, validating end-to-end MCP-grant paths offline, ensuring robustness across the ecosystem's modular architecture.

auto-narrated by the local model from this topic's module headers; links verified against the wiki index.

narrated overview -- maintained by the narration lane, module links verified against this wiki.

moduledescriptionlinesfuncs
cap.nxcapability-based security primitives. 1415
nx_cap.nxcapability-based security primitives.1475
nx_cap_census.nxTHE NISHI CAPABILITY DRIVER (unified, measurement-first). ONE engine measures how SOTA62427
nx_cap_detect_lib.nxthe SILENT-TRUNCATION CAP detector CORE, shared (DRY, rule 15) by the CLI sweep1387
nx_cap_exists.nxLIB: the Nishi builder's "does this already exist?" anti-duplicate guard (importable).13212
nx_cap_exists_gate.nx20114
nx_cap_gap_sov.nxSOVEREIGN endpoint/missing-generation finder (operator 2026-06-22: "no more tsvs ...17213
nx_cap_grant_e2e_gate.nxTHE CAPSTONE: proves the ENTIRE production MCP-grant path end-to-end, offline, with a1068
nx_cap_guard_gate.nx543
nx_cap_harvest.nxSCALE (F310b): auto-harvest a BROAD capability catalog from the live tool943
nx_cap_invoke_gate.nxproves R2: MCP tools/call over R0 is CAPABILITY-SCOPED. Drives ta_handle_pfx in-process894
nx_cap_issue_gate.nxproves the self-service DELEGATION endpoint (POST /api/cap/issue) over R0's ta_handle:1016
nx_cap_keygen.nxprovision the capability-token SIGNING SECRET on the machine that will verify it (the NAS).765
nx_cap_keygen_gate.nxproves nx_cap_keygen provisions a REAL CSPRNG signing secret that (a) is 256-bit hex,675
nx_cap_mint.nxCLI to MINT a capability token for R0's tools/call (R2 live). Reads the HMAC secret from a keyfile495
nx_cap_mint_gate.nxproves the root minter cm_mint (a) issues a capability that grants exactly the listed452
nx_cap_provision.nxFAIL-CLOSED capability-secret provisioning check (closes audit risk #1:556
nx_cap_provision_gate.nxproves the FAIL-CLOSED cap-secret check. NEGATIVE CONTROLS are load-652
nx_cap_register.nxthe LIBRARIAN registers a capability so the team (not Claude hand-editing) writes375
nx_cap_register_test.nxprove the Librarian's lint+register catches the EXACT bug Claude made by hand644
nx_cap_revoke_gate.nxproves REVOCATION over R0's ta_handle: a valid cap invokes; after POST /api/cap/revoke606
nx_cap_token.nxsovereign CAPABILITY TOKEN: the "beyond MCP" security primitive for tool invocation.14410
nx_cap_token_gate.nxproves the capability token is the BEYOND-MCP security primitive: authority-in-the-token,562
nx_cap_type_classify.nxthe census CAPABILITY-TYPE classifier (L7 of the1537