Distribution
An Ability is a signed npm tarball. Two routes put it in a harness's node_modules, and both converge on the same runtime path — a plain static import of the factory, handed to registry.enable. There is no runtime "load an Ability by name" verb.
The signed channel
Deep access is the reason for the gate, and the gate is what makes deep access safe. Anything reaching a harness that does not own it flows through apps.lloyal.ai: reviewed for contract conformance, tool safety, manifest validity and signature provenance before listing. A first-party harness may also depend on an Ability it owns from a private source, as an ordinary npm dependency — not a parallel public path.
The framework points at that catalogue by default. The install command takes a name, never a URL; the catalogue URL and the Ed25519 trust roots are compile-time constants. Every harness therefore resolves Abilities through the same verified channel, and the protocol does not fragment into incompatible sub-catalogues.
Installing
npx lloyal-ai install acme/jira@^1.2.0One command, and a verified chain from publisher to process. The install verifies before anything is written: it fetches the signed catalogue and checks its Ed25519 signature against the vendored trust roots; resolves your semver range to a version the catalogue pins; fetches the manifest and cross-checks name, version and size; fetches the tarball and verifies the signature over its raw bytes; then cross-checks a sha512 integrity digest. Only then is the package vendored and installed. A failure at any step rolls back — nothing unverified is left behind.
A signed record of everything it says to your model
You can read what an Ability puts in your context window without running its code. At publish time the CLI constructs your Ability and reads back what it actually registers — every tool name, description and parameter schema, plus the skill template. That is written into the tarball as attention-surface.json, so the signature covers it.
This exists so a reviewer, and anyone installing, can read exactly what an Ability injects into a model's context without executing its code. It is derived from the code rather than declared, so it reports what the Ability really does, not what its author says it does.
What acme/jira adds to your model's context:
protocol: jira_research
use when: investigating tickets, their history and linked work
tools: jira_search, jira_fetchRelated
- Security model — why the channel is signed.
- CLI reference —
ability:new,publish,install.