Skip to main content

Permissions and approval

Capabilities and plugin management use explicit permission scopes. Discovery does not authorize an effect, and a descriptor’s revision does not authorize a caller.

How it works​

Bind approvals to the exact target, normalized plan, bounds, revision and idempotency identity. A plugin must enforce its own provider effects through the host-approved path. Keep secret material out of configuration schemas and diagnostic output.

Complete contract​

Read the Skulk™ 2.0 development guide for the complete parameters, constraints, examples and operational behavior.