untrusted-render: this realm stores no string of its own. The only two a caller supplies, a module path and its subpath, are written solely by the owner through Approve and charset-validated there (p/moul/pilot assertPlain), which is what lets Render interpolate them. Package pilot is moul's realm-driven account: it holds the funds and the identity, moul's key pilots it, and its powers arrive afterwards as separate realms that this one never imports.
All behaviour is in gno.land/p/moul/pilot/v0; this realm is the instance. Demo of a power: r/moul/x/pilotdemo.