Say what a source is, and whether installing it needs trust
Reads a source off the host’s disk — a directory, a single .go file or a Go module reference — and reports what kind of package it is and whether installing it needs an acknowledgement. Nothing is installed, nothing is written, and a module reference is NOT downloaded: nothing may fetch a package’s code in order to decide whether to ask permission to fetch its code, so a reference is reported as unread rather than described. It exists because the decision belongs to the host and the QUESTION belongs to a surface. A client has to know whether to ask before it can ask. installPackage still enforces the same rule server-side regardless of what any caller did with this answer. A local path must be sent ABSOLUTE. A relative one resolves against the HOST’s working directory, which is not the caller’s, and the artifact the answer describes would not be the one the caller meant.
Autorizaciones
Enforced on every transport, with no exempt operation. A person's request — over the default local unix socket exactly as over a TCP listener — must carry a JWT issued by the configured identity provider, which the host verifies itself against that issuer's key set: signature, issuer, expiry, and the person and organisation it names. Requests without a valid one receive 401 NRY-0011. The socket's file permissions are transport and are not an authorisation.
Parámetros de consulta
An absolute local path, or a registry/module reference.
1024Respuesta
What that source is.
What a source turns out to be, learned without compiling it, importing it or downloading it.
The CANONICAL form of the source, and what an install must be started with: an absolute path for a local directory or file, the reference unchanged for a module. A consent surface that names one artifact and installs another is the one thing it may not do, so the caller carries this value through to installPackage rather than the word somebody typed.
The package name.
resources installs instantly; code and both carry Go source and cost a rebuild and a binary swap. Reported as code for a module reference nothing has downloaded yet, which is the safe side of a guess nobody can make without fetching.
resources, code, both The source is a module reference whose real kind and claims stay unknown until it is downloaded. A caller asking a person for consent says so rather than describing contents nobody has read.
Installing this needs an acknowledgement: true for anything carrying compiled Go code, and equally true for a resources-only package declaring a hook, since a hook is an executable narya runs through the shell with no sandbox. A resources-only package with no hooks is never gated.

