docs: record official plugin project scope

This commit is contained in:
brother7 committed 2026-09-05 13:25:31 +08:00
1 parent e0de7aa28c
commit f721966f3c
13 files changed
+123 -35

No files matched your search

+18 -13
View File
@@ -7,10 +7,11 @@
later consume Token Points, and system-included Data Service remains zero-charge.
- Account Library, Device Installation, project enablement, Agent assignment, runtime
authorization, and billing are separate states. No read, install, acquisition, or
assignment may silently advance another state. The sole code-owned activation-scope
exception is `makelore.project-scaffold`: Account acquisition and project enablement
remain separate, but project enablement intentionally makes its Skills available to
every parent Agent without creating or requiring assignment state.
assignment may silently advance another state. The code-owned project-wide identities
are `makelore.data-service`, `makelore.game-resource`, and
`makelore.project-scaffold`: their existing delivery/acquisition and project enablement
remain separate, but project enablement intentionally makes their Skills/tools
available to every parent Agent without creating or requiring assignment state.
- Marketplace packages become effective only after closed manifest/descriptor parsing,
canonical archive and client-compatibility checks, Ed25519 verification, immutable
Package Store selection, project enablement, Agent projection, and current server
@@ -21,11 +22,11 @@
worker or delete bytes it still owns.
- System-included Data Service ships with MakeLore and has no Library acquisition,
Admission, download, update, or device-uninstall action. Users may still enable it
per project and assign its Skill to an Agent.
per project; project enablement makes its Skill/tools available to every parent Agent.
- Code-owned Game Resource is the optional bundled hosted Plugin. Its exact schema-2
manifest, Skill, and tools ship with MakeLore, so it has no device download, update,
Beta, signature, or device-uninstall state. Account Library acquisition/removal,
project enablement, Agent assignment, current server policy, immutable Admission,
project enablement, current server policy, immutable Admission,
explicit confirmation, and Token Point billing remain distinct.
- Production Marketplace trust fails closed while the official Ed25519 public key is
absent. Test-only/integration keys and packaged unknown-key rejection are evidence,
@@ -33,8 +34,10 @@
implemented, but production package trust and real Provider activation remain closed
until the official key and separate server pricing, credential, Admission, and
acceptance gates are ready.
- A `platform_hosted` Skill or tool may enter only an installed, enabled, assigned,
trusted, compatible, policy-admitted parent Pi logical thread. Unknown, disabled, or
- A `platform_hosted` Skill or tool may enter only a delivered/installed, enabled,
trusted, compatible, policy-admitted parent Pi logical thread. Agent assignment is an
additional gate only for Plugin identities whose activation scope requires it; the
three code-owned project-wide identities bypass that gate. Unknown, disabled, or
ineligible assignments stay inert; child workers receive no hosted Plugin projection.
- A metered hosted mutation requires explicit client confirmation before resolve,
Admission, or charging. Works Square owns price, payer, Token Point policy, and receipt
@@ -67,10 +70,12 @@
Store, Release, Channel, Admission, project enablement, Agent assignment, or server
billing state.
- Code-owned official bundled Plugins may be `platform_hosted` or `skill_only`.
`makelore.project-scaffold` retains Account Library, project enablement, Release, and
Admission state while its exact Skill/templates/`.mjs` ship only in the signed client.
It is project-wide: once acquired and enabled for a project, every parent Agent receives
the Skill without partner assignment; child Agents remain empty. Downloadable
Data Service is system-included; Game Resource and `makelore.project-scaffold` retain
Account Library, project enablement, Release, and Admission state where applicable,
while their exact resources ship only in the signed client. All three are project-wide:
once their delivery/acquisition condition is satisfied and they are enabled for a
project, every parent Agent receives the full resource set without partner assignment;
child Agents remain empty. Downloadable
Marketplace artifacts remain P0
text/image-only and must reject `.mjs`; official bundled authority is not inferred
from provider metadata or an uploaded ZIP.
@@ -159,4 +164,4 @@
## Last Reviewed
2026-09-04
2026-09-05