Must store
Store declared protocol version, declared capabilities, extension namespace, and extension refs when accepted.
Must validate
Validate protocol version, capability support, namespace ownership, and closed-schema core field protection.
Must reject
Reject silent downgrade, unsupported required capability, invalid namespace, and extension core field override.
Host boundary
Hosts own UI, auth, storage, runtime behavior, model routing, tool execution, billing, scoring, payment, deployment, monitoring, and host workflow.