上下文
原生成员(native member)是我们围绕供应商 API 编写的封装层,同样需经过相同的安全评审:安全团队审批的具体内容包括我们调用哪些供应商 API、请求哪些权限范围。由此,审批构成工程集成启动前的一道硬性关卡。相关审批决策将录入随代码发布的注册表中:该注册表包含结构化的 URL 匹配器、供应商完整公开的工具列表、允许调用的子集,以及为每一项工具人工撰写的关于其风险与能力的注释。
原始上下文
A native member is a wrapper we wrote around the vendor's API, and it goes through the same security review: which of the vendor's APIs we call and which scopes we request are what the security team signs off on. This way, approval is a hard gate before engineering integration begins. Those decisions land in a registry that ships with the code: a structured URL matcher, the vendor's full advertised tool list, the subset that may be invoked, and a hand-written risk and capability annotation for each.