The toolchain image installs from this package.json with a range; unchanged, Docker reused the cached install and the image kept SDK 0.1.3 after 0.1.5 was published. Bundles copied that copy, so a launched bundle registering its seat first served the seat's verbs as its own tools. Requiring 0.1.5 says what the runtime and its bundles need, and invalidates the cached layer.
node-tools
The node's tool runtime as a module (novox/hq ADR 0175, to-be 38 WP3). Assigned to a machine, it is one process the host runs from this bundle, as the operator's account: it serves every assigned module's tools and every held seat's verbs on the bus, and answers MCP on the machine's loopback — the console (design 34). The controller composes the process (which bundles to load, where the credential is, whose machine it is); this manifest says only what the machine must have for it: the interpreter, a place for the credential, the loopback port, and leave to call every tool.
The code is the mesh-tools package in this directory; the module at the repository root,
mesh-tools, builds the images TypeScript bundles are compiled in. See the repository README.