OptionalentryKind 1 — a sibling entry point of the caller's own repo (mini-app overlay).
OptionaltaskKind 2 — a task contract name (the host resolves the bound provider).
OptionalversionOptional accepted contract version for a task target (semver, e.g. ^1).
What to launch (§3) — binding-resolved, NEVER a caller-named app. Exactly one of:
entryPoint: a sibling entry point of the caller's OWN repo (the mini-app case,AGENT_AUTHORING §5) — rejectedforbiddenuntil program-identityappKeylands (R-SAL-2a);task: a task contract (open-project, …), resolved through the user- overridabletask.<name>binding to whichever app the user bound (§3 kind 2).