Decrypt encrypted .cap bytes into the inner .cap bytes.
Decrypt an unpacked §6b envelope file map into the inner .cap bytes.
Encrypt a package into the §6b envelope: packagePath may be a package
directory (packed first, so checksums are in place) or a .cap file.
Writes the encrypted .cap to outPath.
Encrypt .cap bytes into the §6b envelope layout (as zip bytes).
Encrypt a directory or .cap into encrypted .cap bytes (§6b).
Decrypt an encrypted .cap file, writing the inner .cap to
outPath.