These notes are hand-written. bytecode_reference.md is generated by cmd/codegen from the opcode registry in internal/bytecode/opcode.go. That table's capability column is the opcode field. Do not add rows to it by hand.
map_keys (MAP_KEYS) is pure. Dictionary operations such as map_get and map_keys grant nothing. OpMapKeys has an empty capability field, capability.ForConstruct("map_keys") is empty, and the operation runs under an empty grant. It returns the keys of an in-memory dictionary, sorted.
store_keys (STORE_KEYS) stays database. OpStoreKeys declares capability.Database, and capability.ForConstruct("store_keys") is database. A memory:// store needs that grant alone. A grant that omits database denies store_keys with CAPABILITY_DENIED.
A file:// store additionally requires filesystem. Opening the store and enumerating it with store_keys both demand filesystem on top of database. database alone denies file:// store_keys with CAPABILITY_DENIED. The generated table lists STORE_KEYS as database because that is the opcode field. The extra filesystem grant is enforced from the store URI (capability.StoreRequirements on open, and store.file on STORE_KEYS) and is recorded here.
#79 (runtime enforcement) and #94 (one capability table) stay Done. This note adds no capability and leaves the opcode grant matrix unchanged.