Package nativereg is the metadata a native coin does not have.
A realm-issued coin is a string and a balance. `/gno.land/r/moul/x/moultest/v0:moultest` is the entire object: no name, no symbol, no decimals, no icon, no link to whoever issues it. The bank knows the number and nothing else, so a wallet or an explorer showing you a balance has only that path to print.
This realm is where a denom says what it is. It is the mirror image of `r/nt/grc20reg`, and the two solve opposite problems: a GRC20 is an object that carries its own name and is hard to FIND, so the registry maps a key to the object; a native denom is trivial to find and carries no name, so the registry maps the denom to what it means.
Registration is proved, not claimed
A denom embeds the package path of the realm allowed to issue it, verbatim: `"/" + pkgPath + ":" + baseName` (`chain.CoinDenom`). So the issuer is readable from the denom, and Register simply requires the caller to be it. A realm registers its own coins and nobody else's, with no allowlist, no owner and no signature scheme.
A user account cannot register anything, not even a denom it holds all of: there is no package path in a user call to compare against. That is the intended shape, since the thing being described is the issuance, not the holding.
What is a hint and what is a fact
`Denom` and `Issuer` are facts: the chain enforces the relation between them. Everything else is whatever the issuing realm chose to say, and `Decimals` in particular is a DISPLAY hint with nothing behind it. The bank has no notion of divisibility; a coin wrapped out of a 6-decimal GRC20 is still counted in whole units by every balance query. Rendering 1000000 as 1.000000 is a convention between this realm and whoever reads it.
So trusting an entry means trusting the realm that wrote it, exactly as much as holding its coin already means trusting it not to call `RemoveCoin` on you.