The mesh composes every served module's words into MESH_TOOL_ENV; the runtime takes it at start and removes it from its own environment, then gives each registration's contributor and each launched child the runtime's words plus its own module's, never another's. Against an SDK without collectToolsEach it says so and serves with the runtime's words only. The test serves two imported bundles and one launched, each answering with its own words and none of the others'.
node-tools
The node's tool runtime as a module (novox/hq ADR 0175, to-be 38 WP3). Assigned to a machine, it is one process the host runs from this bundle, as the operator's account: it serves every assigned module's tools and every held seat's verbs on the bus, and answers MCP on the machine's loopback — the console (design 34). The controller composes the process (which bundles to load, where the credential is, whose machine it is); this manifest says only what the machine must have for it: the interpreter, a place for the credential, the loopback port, and leave to call every tool.
The code is the mesh-tools package in this directory; the module at the repository root,
mesh-tools, builds the images TypeScript bundles are compiled in. See the repository README.