Buyer problem
CWL products and maintainers can benefit from curated external extensions, but a marketplace/catalog entry must never become implicit runtime authority for prompts, hooks, subagents, MCP servers, shell/process access, network access, secrets, GitHub write authority, or product data.
Anthropic/community marketplace review remains upstream discovery evidence only. Noema does not treat a mutable marketplace branch, plugin name, author prose, or sibling PR head as CWL admission/activation authority.
Current protected authority — 2026-09-10 KST
Fresh protected Noema is GitHub-verified main@b946d04236613544ceedb2160ed68b4e6d855dd8 after normal #582 integration. The original Noema admission/activation source work from this issue is now protected history through merged #560 and the subsequent external-extension lifecycle/operability chain #574, #577, #578, #579, #580, #581 and #582.
Protected source now separates source/catalog/scanner evidence from Noema Policy / Approval issuance; binds activation/invocation to exact admitted source identity, artifact/product/role/policy/time and current authority; seals replay semantics with platform SHA-256; rejects authority substitution and stale/revoked activation; persists append-only lifecycle transitions in the exact stream-scoped SQLite Durable Object; and exposes only bounded lifecycle operability metadata. ADR 0015 remains Proposed because source integration is not production activation or buyer completion.
Issue #561 is the current production-successor authority. A new active lifecycle transition remains intentionally fail-closed until Noema can re-read current Noema Policy / Approval plus immutable owner-issued AppGuardrail/quarantine/isolation/Egress evidence through a reviewed production adapter. Fresh 2026-09-10 reads show zero GitHub Releases for appguardrail, quarantine-sandbox-runtime, EgressWeave, and context-graph-contracts; mutable sibling branch/PR/package heads therefore remain ineligible authority.
Actual deployed acceptance is also still open in #561: realistic synchronous current-read/contended-append p95 ≤20 ms, exactly-one-winner CAS contention, >128-event audit/restart continuity, malformed/truncated-state rejection, exact-object SQLite storage growth, PITR/equivalent recovery rehearsal, and producer-authenticated deployment/release provenance.
Canonical ownership
Noema's Tool / Capability Boundary owns versioned external-extension descriptors, Noema Policy / Approval issuance, activation/expiry/rollback semantics, invocation receipts and lifecycle/state/checkpoint evidence. It does not absorb foreign extension functionality or the following owners:
context-graph-contracts: provider-neutral released schema/profile/conformance for shared external-capability artifacts;
appguardrail: package/manifest/hook/prompt/MCP supply-chain scanning and SARIF;
quarantine-sandbox-runtime: isolated execution/analysis of untrusted hooks, scripts, MCP binaries and package artifacts;
EgressWeave: outbound host/method/size/response policy;
contextual-orchestrator: model/provider discovery, capability routing and orchestrator/free; no extension-owned provider routing or provider credentials;
keyverse: human/service identity and secret handles; raw secrets never enter extension prompts, manifests, traces or receipts;
- product repositories: consumer-owned ACLs and declared capability demand only, never copied extension source or cross-service SQL.
A narrow local fail-closed port/test double is acceptable only where a released shared contract does not yet exist. It must never read mutable sibling source as production authority.
Adoption modes
developer_assist
An approved extension may advise in a bounded maintainer/reviewer workspace. It has no merge, release, deployment, secret, product-data or production-state authority. Installation remains disabled by default and must be scoped by repository/product, role, client and expiry.
product_runtime_adapter
A product must not embed a marketplace/Claude plugin wrapper as its production runtime. When a plugin exposes a useful MCP/API/tool, the canonical product/owner adopts the underlying released protocol/API through its own port/ACL, tests, security controls, provenance and release. Marketplace metadata remains discovery evidence.
Mandatory rejection or escalation
Reject or require explicit owner/security review when an extension requests direct provider keys/model routing outside contextual-orchestrator; broad GitHub review/merge/release/deployment/admin authority; unrestricted shell/filesystem/Docker/network/browser/credential access; runtime download or mutable refs; unsigned binaries or source/artifact mismatch; raw secrets/PII/production records/hidden reasoning; external MCP without exact released contract and bounded identity/isolation/egress; self-modifying/policy-override/exfiltration instructions; or unresolved commercial license/NOTICE/provenance.
Protected TDD invariants
Protected source covers the core hostile cases: mutable/unbound source and source/catalog drift; forged/stale/wrong-artifact/wrong-policy owner receipts; direct provider/GitHub authority; product/role/time over-broadening; expired/suspended/revoked/superseded activation; replay/idempotency and semantic-envelope binding; authority substitution; impossible chronology; public-error normalization; secret/product/hidden-reasoning retention boundaries; and exact-admission provenance.
Those tests prove Noema source invariants only. They do not prove live owner services, extension installation, production pilot value, immutable contract publication, buyer transfer rights, or production SLO/recovery.
Remaining acceptance / successor path
Do not close this issue merely because source code is protected. It can close only when its valid residual adoption/pilot/immutable-owner-contract acceptance is fully inherited and verified by #561 or another explicit successor, or when the user explicitly drops that scope.
Related: #5, #27, #29, #36, #66, #227, #531, #561, #582, #583; ContextualWisdomLab/context-graph-contracts#27; ContextualWisdomLab/appguardrail#1099.
Buyer problem
CWL products and maintainers can benefit from curated external extensions, but a marketplace/catalog entry must never become implicit runtime authority for prompts, hooks, subagents, MCP servers, shell/process access, network access, secrets, GitHub write authority, or product data.
Anthropic/community marketplace review remains upstream discovery evidence only. Noema does not treat a mutable marketplace branch, plugin name, author prose, or sibling PR head as CWL admission/activation authority.
Current protected authority — 2026-09-10 KST
Fresh protected Noema is GitHub-verified
main@b946d04236613544ceedb2160ed68b4e6d855dd8after normal #582 integration. The original Noema admission/activation source work from this issue is now protected history through merged #560 and the subsequent external-extension lifecycle/operability chain #574, #577, #578, #579, #580, #581 and #582.Protected source now separates source/catalog/scanner evidence from Noema Policy / Approval issuance; binds activation/invocation to exact admitted source identity, artifact/product/role/policy/time and current authority; seals replay semantics with platform SHA-256; rejects authority substitution and stale/revoked activation; persists append-only lifecycle transitions in the exact stream-scoped SQLite Durable Object; and exposes only bounded lifecycle operability metadata. ADR 0015 remains
Proposedbecause source integration is not production activation or buyer completion.Issue #561 is the current production-successor authority. A new
activelifecycle transition remains intentionally fail-closed until Noema can re-read current Noema Policy / Approval plus immutable owner-issued AppGuardrail/quarantine/isolation/Egress evidence through a reviewed production adapter. Fresh 2026-09-10 reads show zero GitHub Releases forappguardrail,quarantine-sandbox-runtime,EgressWeave, andcontext-graph-contracts; mutable sibling branch/PR/package heads therefore remain ineligible authority.Actual deployed acceptance is also still open in #561: realistic synchronous current-read/contended-append p95 ≤20 ms, exactly-one-winner CAS contention, >128-event audit/restart continuity, malformed/truncated-state rejection, exact-object SQLite storage growth, PITR/equivalent recovery rehearsal, and producer-authenticated deployment/release provenance.
Canonical ownership
Noema's Tool / Capability Boundary owns versioned external-extension descriptors, Noema Policy / Approval issuance, activation/expiry/rollback semantics, invocation receipts and lifecycle/state/checkpoint evidence. It does not absorb foreign extension functionality or the following owners:
context-graph-contracts: provider-neutral released schema/profile/conformance for shared external-capability artifacts;appguardrail: package/manifest/hook/prompt/MCP supply-chain scanning and SARIF;quarantine-sandbox-runtime: isolated execution/analysis of untrusted hooks, scripts, MCP binaries and package artifacts;EgressWeave: outbound host/method/size/response policy;contextual-orchestrator: model/provider discovery, capability routing andorchestrator/free; no extension-owned provider routing or provider credentials;keyverse: human/service identity and secret handles; raw secrets never enter extension prompts, manifests, traces or receipts;A narrow local fail-closed port/test double is acceptable only where a released shared contract does not yet exist. It must never read mutable sibling source as production authority.
Adoption modes
developer_assistAn approved extension may advise in a bounded maintainer/reviewer workspace. It has no merge, release, deployment, secret, product-data or production-state authority. Installation remains disabled by default and must be scoped by repository/product, role, client and expiry.
product_runtime_adapterA product must not embed a marketplace/Claude plugin wrapper as its production runtime. When a plugin exposes a useful MCP/API/tool, the canonical product/owner adopts the underlying released protocol/API through its own port/ACL, tests, security controls, provenance and release. Marketplace metadata remains discovery evidence.
Mandatory rejection or escalation
Reject or require explicit owner/security review when an extension requests direct provider keys/model routing outside contextual-orchestrator; broad GitHub review/merge/release/deployment/admin authority; unrestricted shell/filesystem/Docker/network/browser/credential access; runtime download or mutable refs; unsigned binaries or source/artifact mismatch; raw secrets/PII/production records/hidden reasoning; external MCP without exact released contract and bounded identity/isolation/egress; self-modifying/policy-override/exfiltration instructions; or unresolved commercial license/NOTICE/provenance.
Protected TDD invariants
Protected source covers the core hostile cases: mutable/unbound source and source/catalog drift; forged/stale/wrong-artifact/wrong-policy owner receipts; direct provider/GitHub authority; product/role/time over-broadening; expired/suspended/revoked/superseded activation; replay/idempotency and semantic-envelope binding; authority substitution; impossible chronology; public-error normalization; secret/product/hidden-reasoning retention boundaries; and exact-admission provenance.
Those tests prove Noema source invariants only. They do not prove live owner services, extension installation, production pilot value, immutable contract publication, buyer transfer rights, or production SLO/recovery.
Remaining acceptance / successor path
activefail-closed without immutable owner-issued evidence.context-graph-contractspublishes one; do not consume its mutable issue/branch.developer_assistpilots against no-extension baselines and retain review precision/task success/latency-cost/unauthorized-action/injection/rollback evidence before activation.Do not close this issue merely because source code is protected. It can close only when its valid residual adoption/pilot/immutable-owner-contract acceptance is fully inherited and verified by #561 or another explicit successor, or when the user explicitly drops that scope.
Related: #5, #27, #29, #36, #66, #227, #531, #561, #582, #583;
ContextualWisdomLab/context-graph-contracts#27;ContextualWisdomLab/appguardrail#1099.