workbooks docs

Dock capabilities

capgrantsheld by the host
vfssandboxed SQLite store
commandscall another registered command
llma model completionthe API key
browsefetch + extract a URLthe socket
netgated outbound HTTPthe socket
parallelfan work across isolated instances

A toolkit declares what it needs in #+CAPS; importing an ungranted capability fails to instantiate. See the Dock & capabilities.