Gadgets
Extra capabilities that ride along with a target, beyond its intended purpose.
What a gadget is
A gadget is an extra capability that rides along with the target — not the purpose of the system, but a surface it exposes anyway: a GraphQL endpoint, an admin panel, a metrics endpoint, a debug console, auto-generated API docs, a feature-flag surface.
Why they matter
Gadgets are where "it also does this" turns into attack surface. They are frequently discovered while mapping something else — you are testing the API and notice the debug console — and each one seeds its own vectors and quirks. Left unrecorded, they are invisible to the engine.
How they link
Directly on the asset, or scoped inside the technology that exposes them (GraphQL endpoint inside Apollo Server). If a gadget exists only because of a specific parent component, scope it there.
Functionality vs. gadget
A functionality is what the product is for — password reset. A gadget is what came along with it — the metrics endpoint the reset service happens to expose. When in doubt: if users are supposed to use it, it is a functionality; if it is a side door, it is a gadget.
What's next
Vectors — the specific ways in.