Repository navigation
tools capabilities
pnpm capability:add (implemented in tools/capabilities/src/cli.mjs) lets a project capsule opt into an optional capability from a catalog of manifests. Enabling a capability records it in projects/<domain>/<capsule>/capabilities.json with its risk level; it does not install runtime integration — actual integration remains a project-scoped R2 task.
| File | Purpose |
|---|---|
tools/capabilities/src/cli.mjs |
CLI: --preview / --apply, args |
tools/capabilities/src/catalog.mjs |
Catalog loading, preview text, apply (writes capabilities.json) |
tools/capabilities/src/schema.mjs |
Manifest + payload validation, safeProjectSlug, maximumRisk
|
tools/capabilities/manifests/*.json |
The capability catalog (one manifest per optional capability) |
tools/capabilities/package.json |
Package metadata |
| Manifest | Capability | Risk | Dependencies | Notes |
|---|---|---|---|---|
ai.json |
Bounded AI capability | R2 |
ai, @ai-sdk/provider
|
Provider-neutral, structured Zod output, test doubles; env AI_PROVIDER_API_KEY, AI_MODEL
|
electron.json |
Desktop application shell | R2 | electron |
Preload allowlist and IPC verification; sensitive path apps/desktop/**
|
email.json |
Local email development | R2 |
@react-email/components, react-email, resend
|
React Email preview + provider delivery boundary; env EMAIL_FROM, RESEND_API_KEY
|
python.json |
Python technical boundary | R2 | python |
Requires a recorded technical justification that Node.js is unsuitable |
stripe.json |
Stripe sandbox webhooks | R2 | stripe |
Sandbox-only payment boundary, local webhook forwarding; env STRIPE_SECRET_KEY, STRIPE_WEBHOOK_SECRET
|
wxt.json |
Browser extension shell | R2 | wxt |
Permission-minimized manifest review; sensitive path apps/extension/**
|
Each manifest declares label, description, risk, dependencies, environment variables, commands, tests, sensitivePaths, sideEffects, and removal instructions.
tools/capabilities/src/catalog.mjs:
-
loadCatalog()readsmanifests/*.json, validates each viaschema.mjs(file basename must equalmanifest.id, no duplicate ids), and returns aMap. -
capabilityPreview()prints what the selection would do: risk, the single file that changes (projects/<domain>/<capsule>/capabilities.json), dependencies, environment, commands, tests, sensitive paths, side effects, and removal guidance. -
applyCapability()requires the confirmation to exactly equalENABLE <id> FOR <slug>. It reads the project'scapabilities.json, appends (or updates) the capability — merging withmaximumRiskso risk is never lowered — sorts entries by id, and writes{ version: 1, capabilities: [...] }. Thepythoncapability additionally requires a--justificationtext. - All project/repo paths are resolved through symlink-excluding canonical-directory checks and
safeProjectSlug, so the tool cannot escapeprojects/.
pnpm capability:add --capability stripe --project golden-path --preview
pnpm capability:add --capability python --project myproj --apply --justification "…"
pnpm capability:add --capability ai --project myproj --apply --confirm "ENABLE ai FOR myproj" --repo-root /abs/path-
packages/envalready carries the optional StripeSTRIPE_SECRET_KEY/STRIPE_WEBHOOK_SECRETentries (prefix-checked); enabling the Stripe capability uses those env vars. -
.safrs/tool-inventory.jsonregisters the endpoints touched by optional capabilities so the workflow-pinning gate can validate downloads. -
tools/project-wizardwrites each capsule'scapabilities.jsonpath; the wizard prompts for capabilities and sensitive domains, which this tool manages afterwards. -
check_topology.py/ governance validate the capsule remains well-formed after a capability is recorded.
node --test tools/capabilities/test/*.test.mjs
pnpm run doctor # read-only diagnostics
pnpm run governance- Project wizard — creates the capsule this tool edits
- Tools overview
SAFRS — the Sentra Agent-First Repository Standard — defines how a software repository should be structured, governed, and enforced when autonomous Artificial Intelligence agents perform a substantial share of engineering work by Sentra Artificial Intelligence.
SAFRS v1.1 addresses that problem through five coupled mechanisms:
- a six-layer repository architecture from Trust Boundary to Human Authority;
- a role-based permission model in which capability never implies trust;
- a four-tier risk model with cumulative mandatory controls;
- a multi-agent execution protocol with explicit task states and one mutation owner per bounded scope;
- a knowledge governance model that distinguishes current architecture, historical decisions, execution plans, Git history, and running code.
Built in Indonesia as part of the Sentra Artificial Intelligence ecosystem.
Sentra Artificial Intelligence · Source Repository · Official Website
Dr Ferdi Iskandar — Creator & Maintainer
LinkedIn ·
ORCID ·
Hugging Face ·
Kaggle ·
Medium ·
Substack ·
X ·
Threads
MyPrompt · Sentra Artificial Intelligence · Indonesia
- SentraBot
- Kediri History
- Academic Smartboard
- Avery
- Portfolio Dr. Novia
- Golden Path (legacy demonstrator)
- Control Center
- Capsule template
- Risk model (R0–R3)
- Agent roles and permissions
- Capsule sovereignty
- Multi-agent protocol
- Document lifecycle
- Sensitive paths
- Verification integrity
Lore — how this repository grew
- Schemas (
@safrs/schemas) - Environment (
@safrs/env) - Database (
@safrs/database) - API (
@safrs/api) - UI (
@safrs/ui) - Telemetry (
@safrs/telemetry) - Token (
@sentra/token) - Config (
@safrs/config) - Auth (
packages/auth)
- SAFRS governance checkers
- SAFRS Automation Control Plane
- Gaffer Runtime
- Doctor
- Project wizard
- project-standalone
- Capabilities
- Codegen
- Deps-graph
- Status CLI
- Task CLI