{"_id":"@continua-ai/wheelie-capability-core","name":"@continua-ai/wheelie-capability-core","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@continua-ai/wheelie-capability-core","version":"0.1.0","description":"Zero-ambient-authority Wheelie capability contracts, validators, fakes, conformance runner, and replay helpers.","type":"module","types":"./types/index.d.mts","license":"MIT","author":{"name":"Continua AI"},"repository":{"type":"git","url":"git+https://github.com/continua-ai/wheelie-capability-kit.git","directory":"packages/capability-core"},"exports":{".":{"types":"./types/index.d.mts","default":"./dist/index.mjs"},"./core":{"types":"./types/capability_core.d.mts","default":"./dist/capability_core.mjs"},"./fakes":{"types":"./types/capability_fakes.d.mts","default":"./dist/capability_fakes.mjs"},"./conformance":{"types":"./types/conformance_runner.d.mts","default":"./dist/conformance_runner.mjs"}},"scripts":{"check":"node dist/examples/check_examples.mjs --offline --json","conformance":"node dist/examples/check_examples.mjs","example:local-notifier":"node dist/examples/local_notifier_capability.mjs","example:validation-evidence":"node dist/examples/validation_evidence_stream.mjs","example:repo-agent-readiness":"node dist/examples/repo_agent_readiness_manifest.mjs","test:redaction":"node dist/examples/redaction_tests.mjs --json"},"publishConfig":{"access":"public","provenance":true},"sideEffects":false,"engines":{"node":">=20"},"keywords":["wheelie","capability","sdk","zero-ambient-authority"],"gitHead":"09fc925ec7671ba6c9eeb38698ecf0baa8b712aa","_id":"@continua-ai/wheelie-capability-core@0.1.0","bugs":{"url":"https://github.com/continua-ai/wheelie-capability-kit/issues"},"homepage":"https://github.com/continua-ai/wheelie-capability-kit#readme","_nodeVersion":"25.2.1","_npmVersion":"11.6.2","dist":{"integrity":"sha512-jiXuk37n5XEyFGeGW7LUbLgJ/kSdkDzZSWGM81S8mUc00EVPPYRKH9rRocsfvEs+T3KYbqaS508H4WeC7dPq4w==","shasum":"0cba5ac2f774f5af1806e8b2d9d984317a519eb5","tarball":"https://registry.npmjs.org/@continua-ai/wheelie-capability-core/-/wheelie-capability-core-0.1.0.tgz","fileCount":72,"unpackedSize":683107,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEYCIQDsJAQxSs/Ds1eVsqgkyrWn6AFbtpkRhSWG+T5f+FgiAAIhAJZkCNsKb3SKrJQHaeXYG9wtaXPwJGMA0HrvOn8/6RoJ"}]},"_npmUser":{"name":"dpetrou","email":"dpetrou@continua.ai"},"directories":{},"maintainers":[{"name":"dpetrou","email":"dpetrou@continua.ai"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/wheelie-capability-core_0.1.0_1780245794132_0.6914855384175111"},"_hasShrinkwrap":false}},"time":{"created":"2026-05-31T16:43:14.025Z","0.1.0":"2026-05-31T16:43:14.261Z","modified":"2026-05-31T16:43:14.429Z"},"maintainers":[{"name":"dpetrou","email":"dpetrou@continua.ai"}],"description":"Zero-ambient-authority Wheelie capability contracts, validators, fakes, conformance runner, and replay helpers.","homepage":"https://github.com/continua-ai/wheelie-capability-kit#readme","keywords":["wheelie","capability","sdk","zero-ambient-authority"],"repository":{"type":"git","url":"git+https://github.com/continua-ai/wheelie-capability-kit.git","directory":"packages/capability-core"},"author":{"name":"Continua AI"},"bugs":{"url":"https://github.com/continua-ai/wheelie-capability-kit/issues"},"license":"MIT","readme":"# `@continua-ai/wheelie-capability-core`\n\n`@continua-ai/wheelie-capability-core` is the TypeScript SDK/testkit slice for\nmaking a local tool, app, or service safely agent-callable with Wheelie\ncapability contracts before relying on hosted infrastructure.\n\nThe package is prepared for the first public npm GA release (`0.1.0`). Registry\ninstall commands should be shown only after public npm readback confirms the\n`latest` dist-tag, tarball integrity, and fresh install/import smoke.\n\n## What is included\n\n- capability descriptor, grant, session, stream event, receipt, support-state,\n  validation-environment, and failure contracts\n- descriptor, grant, session, receipt, stream sequence, SSE frame, transition,\n  and redaction validators\n- deterministic fake transports, fake receipt sink, grant/session helpers,\n  trace/replay helpers, and local fake invocation harness\n- a conformance runner for descriptor validation, grant/session admission,\n  redaction checks, stream sequencing, receipt validation, and trace validation\n- copy-pasteable local/fake examples for local notification preview, validation\n  evidence streaming, and repo agent-readiness manifests\n- package/gallery manifest, agent card, CapSearch/gallery descriptor, `llms.txt`,\n  checked local protocol conformance pack, security, support, changelog,\n  provenance, release packet, and status/support-state files\n- zero runtime dependencies and no package-manager lockfile\n\n## What is excluded\n\n- production grant minting, revocation stores, receipt stores, signing keys, or\n  provider credentials\n- hosted relay/control-plane internals, billing or metering internals, operator\n  runbooks, dashboards, and release automation\n- browser extension bridges, native app adapters, cloud-vendor SDK bindings, and\n  live transport adapters\n- generated runtime packages; generated consumers stay fixture-only until a\n  separate release workflow owns generated-code versioning and provenance\n\n## Support state\n\n| Surface | Current state | Safe action |\n| --- | --- | --- |\n| Local contracts, fakes, examples, and conformance | `native_local` | Build locally and run the npm scripts below. |\n| Package registry install | `pending_publish_readback` | Use `npm install @continua-ai/wheelie-capability-core` only after registry readback confirms `0.1.0` on `latest`. |\n| Public GitHub read/tag/archive | `public_read_verified` | Read the public source repo, release/tag, raw docs, and archives; do not infer hosted support. |\n| Wheelie Source read/evidence | `public_read_verified` | Read the public Source page, manifest, llms.txt, agent card, archive metadata, checksum, and evidence routes. |\n| Public artifact status/readback | `public_static_readback_live` | Use the status page/JSON as the current support-state boundary; npm claims need registry readback. |\n| Hosted validation | `hosted_optional_after_dry_run` | Dry-run first after local value is demonstrated. |\n| Live transports or production grants | `unsupported` | Use local fakes and conformance fixtures. |\n\n## Agent-readable files\n\nAgents and package/gallery readers should use these stable files before making\nclaims or suggesting actions:\n\n- `wheelie-package.json` — package/gallery manifest with support states,\n  distribution status, trust labels, capabilities, tools, and policy.\n- `.well-known/agent.json` — agent card for inspect, local conformance, local\n  examples, optional hosted dry-run, and unsupported operations.\n- `.well-known/capsearch.json` — CapSearch/gallery descriptor projection.\n- `llms.txt` — agent docs index and safe task cards.\n- `CONFORMANCE.md`, `SECURITY.md`, `SUPPORT.md`, `STATUS.md`, `CHANGELOG.md`,\n  and `PROVENANCE.md` — human-readable conformance, security, support,\n  availability, release, and provenance boundaries.\n- `conformance/cases.json` and `conformance/expected_report.schema.json` —\n  checked local fixture coverage and typed pass/fail receipt schema.\n- `RELEASE_CANDIDATE.md` and `release-candidate.json` — release packet with\n  package boundary, fixture parity, redaction checks, public-claim ceiling, and\n  local-only examples.\n\nReading these files is read-only. It must not contact hosted services, create\ntelemetry, upload source, spend money, or mutate team-visible state.\n\n## Build and local validation\n\nBuild the ESM `.mjs` JavaScript and `.d.mts` TypeScript declarations with the\npackage's checked TypeScript build target, then run the package-readiness test\nbefore creating an archive.\n\nThe readiness test checks package metadata, export-map artifacts, zero-dependency\nposture, package payload boundaries, checked conformance fixtures, descriptor\n`validation_environment` alias compatibility, public metadata redaction,\ngenerated-runtime exclusion, private-adapter exclusion, TypeScript compiler\noptions, included examples, local example execution, redaction tests, and a local\nfile-archive install that imports the public ESM conformance runner from outside\nthe source tree.\n\n## Run the local examples\n\nThe examples use fake providers and local receipts by default. They do not\ncontact hosted services, upload source, install extra packages, request provider\ncredentials, or emit hidden telemetry.\n\n```bash\nnpm run check\nnpm run example:local-notifier -- --fake --sink stdout \\\n  --emit-receipt out/local-notifier.receipt.json\nnpm run example:validation-evidence -- --fake \\\n  --fixture examples/validation-evidence-stream/fixtures/public-safe/tap.ndjson \\\n  --emit-receipt out/validation-evidence.receipt.json\nnpm run example:repo-agent-readiness -- --fake \\\n  --fixture examples/repo-agent-readiness-manifest/fixtures/public-safe/minimal-repo \\\n  --emit-manifest out/agent-readiness.json\nnpm run conformance -- --example local-notifier-capability --offline\nnpm run test:redaction\n```\n\nOptional Wheelie validation comes after the local path succeeds and remains a\ndry-run preview:\n\n```bash\nwheelie validation plan --dry-run --json --recipe local-notifier-capability\n```\n\n## Public release claim policy\n\nThe first GA npm package supports local contracts, fakes, examples, and\nconformance. It does not include live transports, production grants, generated\nruntime packages, source-primary authority, public Wheelie Source writes,\nmarketplace support, seller payouts, paid listings, or live-money support.\n\nOnly claim npm availability after the release receipt records unauthenticated registry metadata, `/latest`,\ntarball integrity, and fresh install/import readback.\n","readmeFilename":"README.md","_rev":"1-f46d52ad3e3ebd300b7733286dc2ff5d"}