OptionalacceptsContext slots accepted by the worker command. The host validates every supplied claim and copies its inline snapshot; this declaration grants no ambient access.
Optionalagentagent-task mode only: the agent kind spawned INTO the worker target
through agent.spawn (internal spec §10.22). Required iff
invocationMode === 'agent-task'.
Optionalhosthost-op mode only: the §7.9 host operation the capability lowers to
(internal spec §7.9). Required iff invocationMode === 'host-op'.
Namespaced ${ownerProjectId}:${capabilityName}. The host rejects a foreign
owner segment. The local name may be reused by other projects; the full
owner-qualified id is re-derived and verified before routing.
Slice: 'iframe-action', 'agent-task', and 'host-op' are parse-accepted
('runtime-job' stays out of slice).
Display only; NEVER a routing or trust key.
OptionalpreconditionsProducer-declared runtime readiness notes disclosed after exact selection.
Untrusted copy, never authorization input; a note with requiresInput is
additionally enforced pre-dispatch as an actionable not-ready signal.
OptionalpromptShort project-authored composer examples. Presentation-only and untrusted.
OptionalresourcesNamed byte inputs and a validated artifact result; never a grant.
All channels — json, files, assets, entities, edit-session,
source-patch, agent-run — are parse-accepted and host-routable.
OptionalusageBounded project-authored playbook disclosed only after exact selection. It is untrusted copy and never an authorization input.
Durable, host-indexed cross-project capability metadata (§25). NOT ambient authority — the durable counterpart of an
assistant.actionsentry.