Tool descriptions tell a model what a tool does. They do not inherently say what the tool is allowed to do. The system separates read/search from action tools and enforces a consent-token gate for actions; the challenge is making that contract portable and hard to misdescribe.
Define a minimal capability schema that lets a host distinguish observe, propose, execute, export, and mutate before a model chooses a tool.
MCP makes it easy to connect new tools. It is less useful if each host has to rediscover which of those tools can create irreversible side effects.
The harness has provider-aware schema sanitization, a read/action split, and an enforced action gate. A portable versioned capability manifest is not yet a standard or product surface.
Primary source: Developer workspace and Search Console architecture
Draft a versioned capability manifest and test it against real tool schemas plus malicious near-misses. Treat each dropped security field as a test failure, not a compatibility annoyance.
The companion essay is written for a broader technical audience. The repository and developer community are the places to turn a claim into a contribution.
🤫 One is made by Hushh Technologies Corporation, an independent company. We name the hardware and clouds One runs on to say where it runs. None of them endorse us, and we call a company a partner only once the agreement is signed.