| Run code inside the Roblox process: no hooking, no memory patching, no injected script environment | Enforcement has to live outside the boundary it enforces, and a capability that revocation cannot revoke is a promise, not a guarantee. Absent from the surface, not disabled, so there is nothing to re-enable in a fork. | ADR-001 |
| Read or write Cordial’s memory, or use a shared-memory transport | Capabilities mean something only if holding fewer lets you do less, and an address-space boundary does not depend on Cordial being correct. A call that is too slow across the pipe needs a better shape, not a shortcut past the broker. | ADR-003 |
| Draw on top of the game, or in Cordial’s own window | A third party hooking the presentation path is what Cordial refuses to do, and shipping a supported way for someone else to do it would be the same refusal in name only. Capture works today and needs nothing from Cordial. | ADR-009 |
| Read the DataModel, the Lua state or anything else inside the engine | Those live in the engine’s address space. Cordial answers the Android platform calls the client makes, and the DataModel is never one of them. | ADR-001 |
| Touch files, network, environment or subprocesses | A Deno process with no permissions, under the capability broker. A second, independent layer. | ADR-003, ADR-018 |
| Widen the sandbox from your manifest | A Flatpak permission is app-wide and permanent while a capability is per-plugin and revocable. Open an issue instead; see capabilities. | ADR-007 |
| Write your own preference values, or read or write another plugin’s settings | There is no preferences.set, and settings.* has no field to name another plugin. Enforced by an absent parameter, not a check. | ADR-020 |
| Write into Roblox’s own files | Overlays resolve reads and never redirect a write, and nothing is copied into the APK or the extracted asset tree, so uninstalling is a complete undo. | ADR-010 |