Capabilities and bootstrap
Manage trusted capabilities with CapabilityRegistry and generate a project’s initial state with bootstrapProject.
Catalog and project bootstrap
import { CapabilityRegistry, bootstrapProject, createWorkspaceTools } from './packages/sdk/src/index.mjs';
const registry = new CapabilityRegistry({
tools: await createWorkspaceTools(cwd, { deniedPaths: [stateDir] }),
skills: [{
id: 'project-analysis',
path: resolve('packages/sdk/skills/project-analysis/SKILL.md'),
enabled: true,
trusted: true,
}],
});
try {
const initial = await bootstrapProject({
title: 'Database migration helper',
description: 'Verifiable, recoverable migrations for an existing system.',
catalog: await registry.catalog(),
model,
apiKey: process.env.RNA_MODEL_API_KEY,
});
if (initial.status !== 'ready') throw new Error(initial.reason);
const assigned = await registry.resolve(initial.assignments);
console.log(initial.overview, initial.focus, assigned.tools.map((tool) => tool.name));
} finally {
await registry.close();
}- Every skill, tool and MCP assignment must come from the enabled, trusted catalog, each with a reason.
- The catalog only provides skill metadata; bodies load when relevant.
bootstrapProjectruns no tools and installs no plugins; areadyresult includes a project capability package (ProjectGenome) that passed real script smoke checks.- Without a real model it returns
blocked.
Budget admission
beforeRequest({ attempt, estimatedTokens, usage, signal }) runs before each generation or repair request; throwing blocks that request. bootstrap_request_start and bootstrap_request_end events report usage per request, the end event carrying requestUsage and cumulative usage.
usage.totalTokens includes reported usage plus estimates where reports are missing; usage.estimatedTokens lists the estimated part. Estimates are not bills.
Workspace tools
createWorkspaceTools(cwd, options) provides read tools by default. With includeMutations:
- hash-checked writes with atomic publish;
- exact edits;
- cancellable command execution with timeout, output truncation and a full output log.
Commands run under a separate command guardian: cancel sends TERM, then KILL after 300 ms, and reaps descendants in the same process group. If the guardian itself is lost, the call returns cleanupUncertain instead of guessing at old PIDs. This is a POSIX process-group boundary, not a sandbox.
Dynamic capabilities
beforeRequest({ signal, snapshot }) may return { tools, contextUpdates }:
toolsis the complete new tool set, already permission-filtered by the host;contextUpdatesentries{ key, source, text }are deduplicated by content hash, persisted, and enter the session as sourced reference material.
It waits after the previous tool batch completes and before the next model request. On failure or cancel, no request is sent.
MCP
McpClient supports the request/response subset of stdio and Streamable HTTP. Each stdio server has a small guardian: after the host is killed, it notices through stdin EOF or a 250 ms parent check and sends TERM, then KILL after 500 ms, to the process group it owns. Closing the registry cancels connecting clients and waits for children to exit.