Tool descriptions tell a model what a tool does. They do not inherently say what the tool is allowed to do. The system separates read/search from action tools and enforces a consent-token gate for actions; the challenge is making that contract portable and hard to misdescribe.
Define a minimal capability schema that lets a host distinguish observe, propose, execute, export, and mutate before a model chooses a tool.
MCP makes it easy to connect new tools. It is less useful if each host has to rediscover which of those tools can create irreversible side effects.
The harness has provider-aware schema sanitization, a read/action split, and an enforced action gate. A portable versioned capability manifest is not yet a standard or product surface.
Primary source: Developer workspace and Search Console architecture
Draft a versioned capability manifest and test it against real tool schemas plus malicious near-misses. Treat each dropped security field as a test failure, not a compatibility annoyance.
The companion essay is written for a broader technical audience. The repository and developer community are the places to turn a claim into a contribution.
One is a product of Hushh Technologies Corporation (brand: 🤫 “hussh”), an independent company. One runs on third-party silicon, systems, and cloud; platform names are used solely to describe where One software runs and imply no affiliation, endorsement, or sponsorship by those platforms. Our own go-to-market and bill-of-materials partner programs are real and actively in pursuit; we name a partner only once an agreement is executed.