# Security Scenario Composer The composer is the executable, plan-only implementation of `canon/standards/security-scenario-composition_v0.1.md`. It validates Playbook Capability Contract v0.1 declarations, selects exact providers, applies authority-bound overrides, orders trust transitions, and emits an owner-routed JSON handoff. It never invokes an entry point and always emits `execution.permitted: false`. Compose the checked-in C0 reference: ```bash python3 tools/security-scenario-composer/security_scenario_composer.py \ --scenario examples/security-scenarios/c0-local-identity.yaml \ capabilities/playbooks/net-kingdom.local-identity.yaml ``` Compose the KeyCape C1 plus C2b reference from its authoritative sibling declarations: ```bash python3 tools/security-scenario-composer/security_scenario_composer.py \ --scenario examples/security-scenarios/c1-c2b-key-cape.yaml \ ../key-cape/capabilities/playbooks/key-cape.lightweight-sso.yaml \ ../key-cape/capabilities/playbooks/key-cape.privacyidea-token-authority.yaml ``` The scenario pins both provider ids. NetKingdom does not copy or reinterpret their execution authority; the emitted plan retains `execution.permitted: false` and routes readiness to the declaration owners. Run tests: ```bash python3 -m pytest tools/security-scenario-composer/tests ```