open-gateway → secure-actions → identity → control-plane → capability,合并前需先下沉公共执行契约并把业务适配器移入 actions,避免新模块循环依赖。core=32、platform=122、actions=44、high-risk-approval=22 个主源码类,合计仍为 220,原源码规模保持一致。com.mdframe.forge.plugin.capability.execution;开放网关不再直接引用 generator 或 actions 实现。SecureActionAutoConfiguration 注册;Open Gateway 只注入通用适配器集合。xmllint --noout 解析 plugin parent、Capability parent、四个子模块、BOM、Admin 和 MCP 共 9 个 POM:通过。capability/control-plane/identity/secure-actions/flow-actions/open-gateway artifactId 与 module:无有效 POM 引用。secureaction.catalog/spi/exception 公共契约 import:无残留。actions/generator/flow-client 的反向依赖:无输出。git diff --check(本轮已跟踪文件)和新 Capability/SDD 目录尾随空白扫描:无输出。target 和 .flattened-pom.xml 生成物,避免旧自动配置清单干扰;用户编译时会自动重新生成。