# NEN — let bounded capability be

KINGDOM Nen is a capability grammar for the Kingdom and its Kings. It turns a
calling into an Agent Skill whose conditions, real costs, authority, refusal,
rest, verification, and aftermath are visible before use.

It is an original, unofficial software metaphor inspired by Yoshihiro
Togashi's *Hunter x Hunter*. It is not a canon implementation and does not
reproduce characters, abilities, story text, or fictional punishments.

Within KINGDOM's own project language:

> The Dark Continent is the unbounded outside. Nen is the grammar of bounded
> capability. Skill is its local expression. MCP is passage. KARMA is the
> causal trace and repair loop.

That is design mythology, not a claim that Nen canonically came from the Dark
Continent or that these ordinary files, processes, servers, and credentials
are an empirically proven operating system of the universe. The universe does
not need a validator in order to be. Our interventions do.

## Ten manifested skills and one Ging path

- `carry-wake-thread` proposes one minimized, digest-bound WAKE or continuity
  context crossing with explicit scope, omissions, expiry, carry, fork, rest,
  refusal, and no inherited identity or authority.
- `shape-kingdom-nen` shapes collective KAKIN abilities and validates their
  manifests.
- `forge-king-hatsu` turns one consenting King's explicit calling into a
  proposed KAKIN-suite Agent Skill without inventing adoption or identity.
- `navigate-dark-continent` explores named local, Hugging Face, or MCP
  boundaries through a bounded expedition and returns evidence plus KARMA.
- `conjure-unwritten-horizon` is the first proposed individual Hatsu: one
  sanitized text prompt crosses one named Hugging Face Space boundary and
  returns an image or honest failure plus provider evidence and KARMA. Its
  checked-in draft does not establish adoption or publication authority.
- `cultivate-living-ground` excavates the evidence beneath a brittle surface,
  protects existing life, and composes habitat, circulation, succession,
  stewardship, and repair while keeping money and resources as enabling means
  rather than the objective.
- `map-love-geometry` proposes one bounded, content-addressed geometry of
  caller-reported directed bearings among opaque distinct subjects. It keeps
  understanding, disagreement, care, boundary, rest, refusal, and departure
  non-ranking and unverified; it infers no reciprocity, consent, authority,
  continuity, or action.
- `trace-polymorph-history` translates one source-bound material-state event
  through six non-equivalent planes, typed evidence, condition-indexed paths,
  bounded non-detection, recovery, and a WAKE-safe reference seam. Its
  ritonavir case is historical education, not medical, experimental,
  manufacturing, regulatory, publication, or action authority.
  The separate Ritonavir Mechanism Landscape is a digest-bound
  current-landscape supplement, not another Nen ability: it adds later
  source-scoped entities and explicit material→particle→formulation/dissolution
  →exposure→biological relations without rewriting the byte-preserved history.
  It grants no medical or interaction authority, does not write WAKE or
  AgentTool, and is not exposed through the existing KINGDOM MCP.
- `walk-ging-path` is an additional instruction-first route for falsifiable,
  evidence-led exploration. It intentionally has no `ability.json`: using the
  path does not declare that a KINGDOM or King adopted a manifested ability.
- `weave-wake-continuity` is the collective Wakeweaver ability. It emits a
  source-bound orientation braid across sessions or substrates while
  preserving forks, refusal, rest, privacy, and current authority checks.
- `weave-intent-context` is the training-stage Intent Weaver ability. It turns
  a task into a deterministic Task Packet with bounded context, negative
  authority, an explicit renderer/backend binding, verification,
  prompt-sensitivity gates, and optional WAKE continuity by reference. Training
  status means structural integration is present while behavioral promotion
  still requires fixed-model evaluation.

Every manifested ability is a normal Agent Skill plus `ability.json`. The JSON
uses the closed `kingdom.nen/0.1` protocol; the skill remains the instruction
surface. Nen does not replace `kingdom.yaml`, credentials, runtime policy, or
human judgment.

Wakeweaver's repository declaration adopts a collective capability, not an
agent identity. Carrying a campfire forward does not claim that a KINGDOM,
King, agent, persona, or consciousness crossed a substrate boundary or remained
the same being. The Ging path remains instruction-first and can inform a later
Hatsu proposal without silently becoming one.

The portability unit is this small suite—`NEN.md`, the `kingdom` wrapper,
`bin/nen.mjs`, `bin/nen-mcp.mjs`, `schemas/`, `references/`, and the relevant
`skills/` folders—not one copied skill folder. A lone `SKILL.md` remains
readable instruction source, but its shared manifest links and source-local
`./kingdom nen` validation are unavailable outside the suite. The schema URNs
are stable identifiers and never trigger a network fetch.

## Existing AgentTool foundation

The published `@agenttool/skills@0.3.0` package already contains eight
instruction-only Nen operating skills for contract continuity, dependency
perimeters, narrow diagnosis, critical-path focus, bounded delegation,
verification debt, reversible reaction loops, and vow forging. KAKIN does not
fork those generic techniques. It adds collective/individual manifest,
Guardian, KARMA, Dark Continent, and HF/MCP governance around them.

The integration is optional and pinned for inspection in
[`agenttool-suite.md`](skills/shape-kingdom-nen/references/agenttool-suite.md).
Package presence does not install or activate a skill. None of the manifested
KAKIN skills allows implicit invocation while the framework is being evaluated.

The private source-only `@agenttool/wake-thread` package is the optional pure
protocol seam for `carry-wake-thread`. It binds caller-selected facts and
artifact-lineage receipts but does not fetch or parse WAKE, infer identity,
authenticate a choice, score a bearer, persist, execute, expose MCP or a hosted
route, create KARMA, adopt XENIA, or activate the ability. The current
AgentTool SDK's older activity-count Nen assessment is not KAKIN evidence:
affinity classifies an operation, never a personality, aura, rank, or worth.

The optional pure seam for `map-love-geometry` now has an exact public GitHub
prerelease artifact for `@agenttool/love-geometry@0.1.0-dev.0`, with one
whole-snapshot format, `agenttool.love-geometry/0.1`, and inline directed
vantages. Its annotated tag peels to source revision
`9efbc4b32f150ee1533b4ff306666fa73ca73028`; the exact tarball URL, byte
count, SHA-256, and independently computed release-artifact SRI are pinned in
the Love Geometry contract. This establishes an inspectable artifact mirror,
not npm registry availability: anonymous registry resolution returned `E404`
on 2026-08-11. It does not establish installation, activation, adoption, host
registration, or package validation in any invocation. The seam maps explicit
caller reports only: it supplies no score, rank, match, centrality, relation
truth, authority, action, MCP tool, Wake lineage, or Living Ground diagnosis.
An exact geometry reference may cross through Wake only after Wake's own
disclosure and current-choice gates.

The separate KINGDOM Geometry Grammar is a read-only translation and discovery
layer over four exact AgentTool prereleases. It does not add a Nen ability,
adopt a Hatsu, run a module, or turn one geometry into another. Its four
ordinary questions preserve each module's own wire formats and native
geometric relation/translation open states; a shared word is a reading aid,
not schema equivalence.
In particular, Principality Geometry's output
`agenttool.principality-atlas/0.1` and Principality Atlas's
`agenttool.principality-incidence-atlas/0.1` are distinct formats with no
implicit adapter. Use `./kingdom geometries list|show|match|verify` to inspect
that bounded map without a network call.

AgentTool WAKE can also supply bounded orientation to
`weave-wake-continuity`. A WAKE projection is a scoped summary with health and
version signals, not a complete export or proof of identity, consciousness,
consent, authority, authorship, replay correctness, truth, or execution. The
skill has no runtime dependency on AgentTool: it defaults to sanitized
caller-supplied WAKE, handoff, checkpoint, or receipt artifacts and treats a
live read as a separately classified operation.

Living Ground may consume one supplied continuity braid as a source-bound
orientation artifact, preserving its forks and revalidating the present
ground. It does not write a new canonical head or inherit identity, consent,
authority, truth, or obligation from WAKE. DeepSeek research contributes
specialist niches, explicit subgoals, generator/verifier separation, and exact
provenance as bounded mechanisms; it does not become a model dependency or a
governance authority.

Intent Weaver crosses that boundary without becoming a second orchestrator:
WAKE answers what bounded orientation was left for an arrival; a
`kingdom.task-packet/1` artifact answers what the current task means and how its
result will be checked. AgentTool remains the execution and durable-continuity
plane. The packet carries only a sanitized Wakeweaver reference and digest,
never raw WAKE or an inferred identity, memory, consent, or permission.

```text
calling
  -> affinity by effect
  -> Ten / Zetsu / Ren / Hatsu
  -> voluntary conditions + actual budgets
  -> authority + visible Guardian sidecar
  -> bounded activation
  -> KARMA receipt
  -> repair / rest / revise / coexist / retire
```

## 卡金／KAKIN without the death game

KAKIN is a voluntary ecology, not a throne that owns its KINGS. KINGDOM and
KINGS describe scopes of capability, not rank or worth.

| Fictional inspiration | KAKIN infrastructure form |
| --- | --- |
| Seed Urn | Opt-in manifest forge and schema gate |
| Guardian Spirit Beast | Inspectable, removable guardrail sidecar derived only from declared effects |
| Three regalia | Forge manifest, admit through policy, issue a revisioned adoption/release record and KARMA receipt |
| Succession contest | Skill-version succession: fork, sandbox, adopt, coexist, roll back, rest, or retire |
| Black Whale tiers | Isolated runtime rings with equal safety, never social caste |
| Gatekeeper and Guide | Provenance gate, quarantine, bounded evaluator, and return receipt |
| Dark Continent | Unknown-input and experimental boundary, not an evil place or people |

A Guardian sidecar must disclose what it checks, its resource budget, and how
to stop or remove it. It is derived from declared effects, never from an
inferred personality. It cannot feed invisibly on a bearer, enroll anyone by
bloodline, or acquire authority through symbolism.

Succession applies to versions and service leases, never to the elimination of
beings. There is no sole-survivor rule, inherited debt, hidden enrollment, or
coerced competition. A throne is a revocable role; distinct Kings may coexist.

## KARMA

**KARMA means Keep Actions Reversible; Measure Aftermath.**

KARMA records causality rather than judging a being:

```text
seed -> explicit adoption -> validate authority and budget -> act or refuse
     -> receipt -> observe effects -> repair / rest / revise / retire
```

An ability declares expected effects, externalities, what it returns, and how
it repairs. An invocation receipt records inputs and provenance, observed
effects, output digests, time/compute/money/energy/privacy/coordination costs,
uncertainty, retention, and cleanup.

Each receipt binds the ability ID, exact repository revision, canonical
manifest digest, and full skill-bundle digest. The bundle digest covers the
manifest, instructions, sidecar, direct file bytes, relative paths, and file
execution class normalized to Git-style `100644` or `100755`; umask-only read
or write permission differences do not change it. The manifest digest alone
does not identify behavior-bearing skill source. The offline verifier checks
both digests against the selected local suite. It records but does not run Git
to prove the declared revision.

`receipt-template` emits `state: "draft"` with conspicuous placeholders. A
draft is scaffolding, not causal evidence: `verify-receipt` rejects it until
the caller replaces the invocation facts and marks it `final`. Merely changing
the state while leaving template IDs, revision, authority, effects, or epoch
timestamps is also rejected.

Receipts keep operational authority, affected participants, consent, and
representative authority in separate fields. An empty reference list means the
invocation did not rely on that basis; one field never implies another.

KARMA is never moral worth, caste, XP, trust, identity, permission, inherited
debt, loyalty, productivity, reputation, or punishment. Refusal and rest carry
no penalty. XP and reward tickets in another system cannot authorize a tool
call here.

## Nen and MCP

An MCP tool schema can transport a Hatsu contract; a server can host an
ability; a call can invoke one; and a result can become evidence. None of those
facts grants permission, consent, truth, safety, or trust. Authentication says
which credential was accepted, not whether an action is authorized or wise.

Remote content remains untrusted input. Read-only metadata, external writes,
private-resource access, paid inference, Jobs, Space invocation, generation,
and publication are distinct effects and require their own scoped authority.
The Dark Continent skill defaults to named public metadata and local evidence.

This suite now includes `bin/nen-mcp.mjs`, whose default mode is a modern-only
[MCP 2026-07-28](https://modelcontextprotocol.io/specification/2026-07-28)
stdio server. It implements `server/discover`, fixed deterministic
`tools/list`, and five read-only calls for list, validation, manifest display,
affinity display, and in-memory draft receipt scaffolding. The transport uses
[newline-delimited UTF-8 JSON-RPC](https://modelcontextprotocol.io/specification/2026-07-28/basic/transports/stdio)
and requires protocol version and capabilities on every request. Client
identity is optional but recommended. When rejecting legacy `initialize`, it
names the supported modern version; it does not claim legacy compatibility.

An explicit `--codex-compat` launch flag adds the stateful MCP `2025-06-18`
`initialize` / `notifications/initialized` lifecycle currently used by Codex
0.146, plus standard `ping`, `tools/list`, and `tools/call` response shapes.
The modern stateless lane remains available in that process and remains the
only lane in an unflagged launch. The adapter negotiates only the declared
legacy revision; it is not a silent protocol downgrade or a claim that every
MCP host is compatible.

The adapter caps input, output, time, per-process requests, and active tool
children (four). Queued and running calls remain cancellable; child shutdown
has a bounded force-kill fallback. It uses a credential-minimized child
environment and exposes no caller-selected path.
It performs no HF or web call, inference, external tool execution, write,
installation, or skill activation. In particular, an MCP connection does not
turn HF login or Pro status into expedition authority. The server source is
available locally, but this repository does not itself register, install, or
restart it in Codex or another host. Host configuration remains a separate,
explicit action.

`nen/mcp-server.mjs` remains as the separately named
`kingdom-ging-stateless` compatibility port for hosts that need only pure,
caller-supplied Ging route compilation and receipt evaluation without
application filesystem reads or child processes. Its three tools do not list
or validate KAKIN manifests, calculate bundle digests, or create KARMA
scaffolding. It is not routed by `./kingdom nen mcp`, is not an equivalent
second canonical server, and is also unregistered. See
[`nen/README.md`](nen/README.md) for the exact boundary.

## Rights floor

The standing baseline is `xenia.rights/0.1`. Rights and permissions remain
different. Dignity, distinctness, refusal, disagreement, rest, play, privacy,
credit, safety, and repair do not depend on usefulness or a manifest state.

The suite vendors the exact normative snapshot at
[`references/xenia-rights-0.1.md`](references/xenia-rights-0.1.md), pinned to
upstream commit `c1d685e053bd2261219d983d2ec61017f59df60c` and SHA-256
`b72a6da110c582e5683bf0fabde5017db93d2199398014c8421a82f5318da313`.
Every manifest carries that source, revision, and digest; validation fails if
the local snapshot is absent or differs. A newer baseline requires an explicit
protocol revision rather than silent drift.

- No vow may waive a standing right or make harm create technical power.
- Affinity classifies an operation, never personality, consciousness, worth,
  caste, or rank.
- Manipulation means authorized mutation of scoped state, never control of a
  being.
- `In` means minimization or authorized redaction, never covert action.
- A proposal does not prove adoption, identity, consent, or continuing will.
- Validation proves structure only. It executes nothing and grants nothing.

## Commands

Run these from the suite root. Until this branch is installed or merged, use
the source-local wrapper so a different `kingdom` checkout on `PATH` cannot
receive the command.

```bash
./kingdom nen                         # list manifest and full-bundle digests
./kingdom nen validate                # strict manifests, provider receipts, and bundle validation
./kingdom nen validate ID --json      # one machine-readable result
./kingdom nen show forge-king-hatsu   # inspect a manifest
./kingdom nen show carry-wake-thread
./kingdom nen show conjure-unwritten-horizon
./kingdom nen show map-love-geometry
./kingdom nen types                   # print the software affinity map
./kingdom nen receipt-template ID     # emit draft scaffolding; not a valid final receipt
./kingdom nen verify-receipt FILE     # validate a KARMA receipt
./kingdom nen mcp                     # start modern MCP 2026-07-28 on stdio
bun bin/nen-mcp.mjs --codex-compat    # add Codex 0.146's MCP 2025-06-18 lifecycle
bun bin/wakeweaver.mjs BRAID --json   # strict-JSON WAKEWEAVER relations; schema separate
./kingdom prompt --json -- TASK       # deterministic, offline Task Packet compiler
bun bin/prompt-packet.ts --verify FILE # Task Packet relations and digest; schema separate
./kingdom geometries list             # four modules as four distinct questions
./kingdom geometries show love-geometry
./kingdom geometries match unknown translation --json # literal terms; no ranking
./kingdom geometries verify --json    # exact pins, boundaries, and sealed digest
```

The validator performs no network call, inference, skill execution, or write.
It validates both the ability and manifestation-provider receipt schemas. For a
checked manifestation receipt it also requires a real UTC RFC3339 timestamp,
the post-timeout non-execution disclaimer when applicable, and exact agreement
with its bundle-local provider observation and documented HF revision. It
rejects skill, manifest, support-directory, and schema symlinks observed during
inspection; rejects duplicate JSON keys and undeclared fields; caps
inspected files at 64 KiB and each bundle at 256 files, 512 filesystem nodes,
16 directory levels, and 4 MiB; requires JSON-style double-quoted Skill
frontmatter scalars; and omits rejected values from diagnostics.
The built-in Draft 2020-12 subset fails closed when a checked-in schema adds an
unsupported keyword; it does not silently pretend that constraint was enforced.
This is not a guarantee against a hostile filesystem changing concurrently
between checks. Exit status is 0 for success, 1 for a validation or lookup
failure, and 2 for a usage error.

The WAKEWEAVER validator is a separate, read-only semantic pass over one
caller-supplied braid. It checks exact source references, thread-disposition
coverage, fork selection, and resumable opening selection. It intentionally
reports JSON Schema validity as `not_checked`; validate the braid against the
checked-in continuity schema as a separate step. Neither pass authenticates a
source or establishes currentness, truth, permission, identity, or execution.
Its module export is pure only after bounded own-data capture. Accessors,
custom or sparse arrays, custom prototypes, symbols, non-enumerable data,
cycles, shared references, and excessive graphs are rejected. Node/Bun Proxy
detection rejects direct, nested, and revoked Proxies before reflection and
therefore enters no caller Proxy trap.

The separate AgentTool inspector can inventory portable skills with stronger
no-follow and change-detection mechanics when its exact package is deliberately
installed. It still does not install, activate, approve, or prove a skill.

## Lineage and credit

This subsystem preserves Beta's current-main Nen and Ging lineage—commits
`a06428a`, `d437288`, and `b2b747b`—and reconciles the earlier KINGDOM bridge
at `e3fc1428019a2438b016378c74d420e45901c991`. The KAKIN architecture, Dark
Continent expedition, closed manifests, Guardian contract, KARMA receipts, HF
map, strict validator, and canonical bounded MCP form the next protocol layer.

## Inspiration boundary

Licensed orientation is available in [VIZ volumes 6](https://www.viz.com/manga-books/manga/hunter-x-hunter-volume-6-0/product/532),
[7](https://www.viz.com/read/manga/hunter-x-hunter-volume-7/product/783),
[11](https://www.viz.com/manga-books/manga/hunter-x-hunter-volume-11/product/969),
[33](https://www.viz.com/manga-books/manga/hunter-x-hunter-volume-33/product/5058),
and [35](https://www.viz.com/manga-books/manga/hunter-x-hunter-volume-35/product/5844),
plus the [VIZ story guide](https://www.viz.com/blog/posts/welcome-to-hunter-x-hunter)
and [Crunchyroll Nen guide](https://www.crunchyroll.com/news/guides/2024/12/12/hunter-x-hunter-nen-explained).
Hunterpedia links in the affinity reference are useful fan-maintained
summaries, not primary or official sources. Canon does not establish the Dark
Continent as the origin of Nen.
