Skip to content

feat(tool-capability): govern external Claude community plugin admission and product-scoped activation #545

Description

@seonghobae

Buyer problem

CWL products and maintainers can benefit from curated external extensions, but a marketplace/catalog entry must never become implicit runtime authority for prompts, hooks, subagents, MCP servers, shell/process access, network access, secrets, GitHub write authority, or product data.

Anthropic/community marketplace review remains upstream discovery evidence only. Noema does not treat a mutable marketplace branch, plugin name, author prose, or sibling PR head as CWL admission/activation authority.

Current protected authority — 2026-09-10 KST

Fresh protected Noema is GitHub-verified main@b946d04236613544ceedb2160ed68b4e6d855dd8 after normal #582 integration. The original Noema admission/activation source work from this issue is now protected history through merged #560 and the subsequent external-extension lifecycle/operability chain #574, #577, #578, #579, #580, #581 and #582.

Protected source now separates source/catalog/scanner evidence from Noema Policy / Approval issuance; binds activation/invocation to exact admitted source identity, artifact/product/role/policy/time and current authority; seals replay semantics with platform SHA-256; rejects authority substitution and stale/revoked activation; persists append-only lifecycle transitions in the exact stream-scoped SQLite Durable Object; and exposes only bounded lifecycle operability metadata. ADR 0015 remains Proposed because source integration is not production activation or buyer completion.

Issue #561 is the current production-successor authority. A new active lifecycle transition remains intentionally fail-closed until Noema can re-read current Noema Policy / Approval plus immutable owner-issued AppGuardrail/quarantine/isolation/Egress evidence through a reviewed production adapter. Fresh 2026-09-10 reads show zero GitHub Releases for appguardrail, quarantine-sandbox-runtime, EgressWeave, and context-graph-contracts; mutable sibling branch/PR/package heads therefore remain ineligible authority.

Actual deployed acceptance is also still open in #561: realistic synchronous current-read/contended-append p95 ≤20 ms, exactly-one-winner CAS contention, >128-event audit/restart continuity, malformed/truncated-state rejection, exact-object SQLite storage growth, PITR/equivalent recovery rehearsal, and producer-authenticated deployment/release provenance.

Canonical ownership

Noema's Tool / Capability Boundary owns versioned external-extension descriptors, Noema Policy / Approval issuance, activation/expiry/rollback semantics, invocation receipts and lifecycle/state/checkpoint evidence. It does not absorb foreign extension functionality or the following owners:

  • context-graph-contracts: provider-neutral released schema/profile/conformance for shared external-capability artifacts;
  • appguardrail: package/manifest/hook/prompt/MCP supply-chain scanning and SARIF;
  • quarantine-sandbox-runtime: isolated execution/analysis of untrusted hooks, scripts, MCP binaries and package artifacts;
  • EgressWeave: outbound host/method/size/response policy;
  • contextual-orchestrator: model/provider discovery, capability routing and orchestrator/free; no extension-owned provider routing or provider credentials;
  • keyverse: human/service identity and secret handles; raw secrets never enter extension prompts, manifests, traces or receipts;
  • product repositories: consumer-owned ACLs and declared capability demand only, never copied extension source or cross-service SQL.

A narrow local fail-closed port/test double is acceptable only where a released shared contract does not yet exist. It must never read mutable sibling source as production authority.

Adoption modes

developer_assist

An approved extension may advise in a bounded maintainer/reviewer workspace. It has no merge, release, deployment, secret, product-data or production-state authority. Installation remains disabled by default and must be scoped by repository/product, role, client and expiry.

product_runtime_adapter

A product must not embed a marketplace/Claude plugin wrapper as its production runtime. When a plugin exposes a useful MCP/API/tool, the canonical product/owner adopts the underlying released protocol/API through its own port/ACL, tests, security controls, provenance and release. Marketplace metadata remains discovery evidence.

Mandatory rejection or escalation

Reject or require explicit owner/security review when an extension requests direct provider keys/model routing outside contextual-orchestrator; broad GitHub review/merge/release/deployment/admin authority; unrestricted shell/filesystem/Docker/network/browser/credential access; runtime download or mutable refs; unsigned binaries or source/artifact mismatch; raw secrets/PII/production records/hidden reasoning; external MCP without exact released contract and bounded identity/isolation/egress; self-modifying/policy-override/exfiltration instructions; or unresolved commercial license/NOTICE/provenance.

Protected TDD invariants

Protected source covers the core hostile cases: mutable/unbound source and source/catalog drift; forged/stale/wrong-artifact/wrong-policy owner receipts; direct provider/GitHub authority; product/role/time over-broadening; expired/suspended/revoked/superseded activation; replay/idempotency and semantic-envelope binding; authority substitution; impossible chronology; public-error normalization; secret/product/hidden-reasoning retention boundaries; and exact-admission provenance.

Those tests prove Noema source invariants only. They do not prove live owner services, extension installation, production pilot value, immutable contract publication, buyer transfer rights, or production SLO/recovery.

Remaining acceptance / successor path

Do not close this issue merely because source code is protected. It can close only when its valid residual adoption/pilot/immutable-owner-contract acceptance is fully inherited and verified by #561 or another explicit successor, or when the user explicitly drops that scope.

Related: #5, #27, #29, #36, #66, #227, #531, #561, #582, #583; ContextualWisdomLab/context-graph-contracts#27; ContextualWisdomLab/appguardrail#1099.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions