Capability manifest
The declared list of tools a listing exposes, scopes it needs and hosts it may contact.
Every version of every listing here carries a manifest, and it is pinned: the manifest is recorded against the exact artefact that was tested, not against the product in general.
Verification compares the declaration against observed behaviour. A listing that does something it did not declare fails, and so does one that declares access it never uses.
It turns a vague question, is this safe, into a checkable one: does it do what it says.
Reading the manifest once at install and never again. A change to it on a later version is the exact shape of a tool-poisoning attack, which is why a change here is treated as a new product rather than an update.
Related terms
See Capability manifest on a real listing
Every term here shows up in the catalogue next to a real result, with the findings published and the limits stated. Free to browse, no account needed.
Open the catalogue